Skip to main content
ecree logo

ecree

GDPR evidence

ecree.comEducationLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

ecree and GDPR

CertReports found no public GDPR evidence for ecree as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Scope
For student users, we collect the following (rationale in parenthesis): 1) Student essays (Collected so the student can submit their essay to the assignment and the professor can read the essay). 2) Student drafts of essays. A draft of an essay contains many "snapshots" of the current text of the essay. The student creates a draft of an essay in our system and when they create it, they see feedback for each snapshot as they edit (collected so a student can create a draft and improve it and get feedback on the draft while they write it, until they submit the draft as a full essay above, the student can also see the feedback from our algorithm and improve the draft before submitting. So the professor can read the draft and see the student’s current status and see the feedback and grade of the draft). 3) Class names and assignments (collected so students can write an essay for a particular assignment). 4) Teachers can add custom videos (collected to allow extra customized feedback from professors/institiutions). 5) Teachers can add comments to students (collected so students can receive additional feedback from teachers). 6) Administrators at ecree have access to all of the above. Only select employees at ecree have administrative access (This access is granted so administrators can view all essays, essay drafts, grades, feedback, and essay grading and plagiarism logs. The grading and plagiarism logs tell us why the algorithm gave the essay the grade and feedback that it was, and the plagiarism log tells us why the algorithm gave the essay a plagiarism result of authentic or suspicious. 7) For all users, we store email, first name, last name, institution (if there is one), password (hashed), sign up date, last sign in date, location details (ip and general location) of sign up (this information is collected to roster students, allow troubleshooting, and monitor for violations of our terms and conditions). 8) We store login attempts and log in IP addresses (this information is collected to roster students, allow troubleshooting, and monitor for violations of our terms and conditions). 9) We store Payment details (amount, Stripe transaction ID, product purchased) for individiual professors and students who want to buy the service (collected so individual users can access our service). 10) LTI is a method by which we receive students from outside web sites like Blackboard and we create an account using SSO (single sign on) then we allow them access to the system. This is both for professors and students. Currently, these SSO users do NOT see the terms of service and privacy policy. Both docs are on our page ecree.com/signup. 11) We allow users to use our system by Google Sign In. If they do this, they dont go through our sign up page and they don't see our terms of service and privacy policy. 12) We store all page request logs some of which contain personal information such as when doing LTI/SSO we have encrypted (by SSL) first and last name and email address. Logs contain all POST data (collected to help diagnose problems later in our algorithm). 13) We want to store data of how students type later. Right now when students create an essay in our Interactive Editor product, they create an essay draft which has many "snapshots". These are taken at intervals, and take all current text. Instead, we want to capture all key presses, time between current and last key press, all mouse clicks, every event to create the essay, such that we can play through all events that created the essay (collected to have all history of the essay, but also to be able to do analysis of who is who using the fingerprint).
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026ecree: Inactive
Live pagesha256 eedd200fe2
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is ecree GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Education category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No Education vendor has GDPR evidence in the index yet.