Skip to content
loam

Legal

Privacy Policy.

What we collect, what we deliberately never collect, and how students' information is protected, under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Last updated: 4 August 2026 · Version: LEGAL-2026-08-04-R1

  1. 01

    Our approach: watch the document, never the student

    Loam is a proof-of-process writing platform for schools and universities, operated by Difinity Pty Ltd (ABN 82 686 692 759). This policy covers our public website at loam.ink, the region-choice page at app.loam.ink, and the regional applications at au.app.loam.ink, eu.app.loam.ink and us.app.loam.ink (together, the Service), and explains what personal information we collect, what we deliberately never collect, and how we handle, store, protect and delete it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and this policy is our APP privacy policy. These commitments bind us regardless of whether the Privacy Act's small-business exemption would otherwise apply to us.

    Loam exists to replace AI-detector guesswork with evidence of how a document was written. That evidence is about the document, not the person. Data minimisation is the product design, not an afterthought: we collect the least information that can prove how a piece of writing came to be, and nothing else. Because our users include school students, much of this policy is about how we handle students' information, and how little of it we collect by design.

  2. 02

    What we deliberately never collect

    These are commitments built into the product, not settings we could quietly flip:

    • No camera or microphone access. We never request webcam or microphone permissions.
    • No screen or activity recording. No screenshots, no screen capture, no lockdown browser, no monitoring of other tabs, applications or devices.
    • No keystrokes outside the editor. We record edits to the assignment document only. Nothing typed anywhere else on a device is visible to us.
    • No biometrics. No keystroke-dynamics fingerprinting of a person, no typing-rhythm identity profiles, no behavioural biometrics of any kind.
    • No profiling, advertising or sale. We do not build advertising or marketing profiles of students, we never sell personal information, and we never use student writing to train artificial-intelligence models.
  3. 03

    What we collect

    Account information. For each user: name, school email address, role (student, teacher or administrator), school, and class membership. Passwords are stored only as salted one-way hashes (argon2), which we cannot read.

    Sign-in / identity provider information (if you use Google or Microsoft sign-in). If a user signs in with Google or Microsoft instead of a Loam password (for example, "Sign in with Google" or "Sign in with Microsoft", including a school's own Google Workspace or Microsoft Entra account), the provider tells us: which provider was used and its issuer; the provider's own immutable account identifier for that person (a fixed reference number, not a password); the name and email address the provider supplies at that moment; whether the provider says that email is verified; where a school or organisational account is used, the provider's own directory or organisation identifier (Google's hd workspace domain or Microsoft's tenant ID); and the date and time of each sign-in. We use this only to authenticate the person and connect them to the right Loam account and workspace. We do not send student writing, evidence records, classes or submissions to Google or Microsoft: the only traffic to the provider is the standard sign-in exchange (an authorisation request and a token exchange), never assignment content.

    Student writing and evidence records. The assignment document a student writes (text, title, and any images, links or files the student chooses to add) and its edit history: each edit as a small timestamped change, linked into a SHA-256 hash chain, plus our server's countersignatures and their timestamps. This is the product: it is what lets a teacher verify and replay how the work was written.

    AI comprehension check (opt-in). If a school administrator (or, on the Free plan, the educator) turns on the comprehension-check feature, an excerpt of the student's own in-progress draft (the last ~600 words) is sent to an AI model hosted in the same geography as the region you choose for your stored data, to generate one short question checking the student understood what they just wrote. This AI processing never leaves that geography: it stays within Australia for the Australia region, within the United States for the United States region, and — for the Germany region — within the European Union, which may include EU member states other than Germany (see section 8). The feature is off by default, the model receives only that text excerpt and a fixed instruction, never a student's name, email or other identifier, and we do not use it, or any other student writing, to train an AI model (see section 7).

    Editor events and session signals. Counts and events the editor produces (word and keystroke counts, blocked-paste events, and timing information about edits within a writing session), together with basic characteristics of the writing environment that the editor reports with each session: screen size, timezone, processor count, and whether the browser reports an automation environment. Our server analyses the timing to check a session's cadence is consistent with human typing (for example, flagging physically implausible speed or robotic regularity). These signals describe the session, not the student: we do not build typing-rhythm profiles that identify individuals, and signals are shown to teachers as indicators for their professional judgement, never as automatic verdicts.

    Technical and security information. Standard technical logs when the Service is used: IP address, browser type and version, and timestamps. We use these for security, troubleshooting and abuse prevention. A session cookie keeps users signed in (see section 10).

    Institution and billing contacts. For institution staff who deal with us: business contact details, correspondence, and billing information. Payment cards for School-plan subscriptions are collected and processed by Stripe, our payment provider; we do not store full card numbers. Students are never billed and we hold no payment information about students. The Free plan for individual educators involves no billing at all: no card, no payment provider, no billing records.

    Website enquiries. If you email us or request a pilot, we keep the correspondence and contact details you provide.

    We do not knowingly collect sensitive information (such as health information or biometric data) and the Service is not designed to receive it. Students should not be asked to include sensitive information in assignments; where an institution's assignment requires personal reflection, that content remains under the institution's control as described in section 5.

  4. 04

    How we collect it

    • From the institution, when it provisions accounts, enrols classes, or imports a roster (name, school email, class).
    • From Google or Microsoft, if you choose that sign-in method. We receive the sign-in information listed in section 3 from the provider you choose.
    • From the user directly, when they write in the editor, update their account, or contact us.
    • Generated by the Service, as evidence records, countersignatures, signals and logs are produced.

    We collect personal information only by lawful and fair means, from you, your institution, an identity provider you choose, or through your use of the Service.

  5. 05

    Working for your school: our role

    For student information, Loam acts as a service provider to the institution. The institution decides which students use Loam, which assignments are written in it, who can see the evidence, and how long records are kept. We handle student personal information on the institution's instructions and for no independent purpose of our own.

    The institution remains responsible for its own obligations under the privacy laws that apply to it. For public schools these are typically State and Territory regimes, such as the Privacy and Personal Information Protection Act 1998 (NSW) for NSW government schools. We support institutions in meeting those obligations, including through data-processing agreements (available on institution plans), security documentation, and this policy's commitments. Institutions are responsible for providing any notices to, and obtaining any consents from, students, parents and guardians that their policies or laws require; we assist with plain-language material on request.

    Where a teacher uses Loam through a personal (Free plan) workspace, the same principle applies with the teacher in the directing seat: the teacher decides which assignments are written in Loam, and warrants in our Terms of Service that their use is permitted under their school's policies and that any required notices and consents have been handled. Student work and evidence records in a personal workspace remain academic records of the student and their school; they are not the teacher's personal property, and they are not ours. Our short-form Data Terms bind us to the same no-sale, no-advertising, no-AI-training commitments for personal workspaces, and if a verified school tells us that records in a personal workspace relate to its students, the school's instruction prevails (see the Terms of Service, clause 5).

  6. 06

    Why we collect and use personal information

    We use personal information only to:

    • Provide the Service: operate the sealed editor, build and verify evidence chains, and let authorised teachers replay and verify submissions;
    • Run classes: manage accounts, enrolments, assignments and submissions;
    • Keep the Service secure: authenticate users, detect abuse and tampering, and maintain audit integrity;
    • Support and communicate: respond to support requests and send service communications (we do not send marketing to students);
    • Bill institutions: invoice and administer subscriptions;
    • Improve the Service: using aggregated, de-identified usage statistics that do not identify any individual, institution or document content; and
    • Meet legal obligations: including record-keeping and responding to lawful requests (see section 7).

    We do not use personal information for advertising. We do not use student writing or evidence records to train AI models. We do not disclose personal information for any purpose unrelated to the Service.

  7. 07

    Who can see it, and who we share it with

    Within the school. A student's teachers and their institution's administrators can see the student's work, evidence records and signals for that institution's classes. Students see their own work. Access is isolated per institution. One school can never see another school's data.

    Loam support. To resolve a support request, our support staff can see operational information about the account holder's own use (such as their recent action names, their account status, and workspace-level counts). To see more (the full details of the account holder's own activity, and the configuration of the classes and assignments they created, such as join codes, status and counts, not the names or titles), our staff must first ask that account holder and receive their permission in the product. This permission is time-limited, logged, and can be withdrawn at any time. In no case, with or without permission, can support staff see any student's writing, replays or evidence records, or any other user's personal information.

    Our service providers. We use a small number of infrastructure providers to run the Service, currently: Amazon Web Services (AWS) for cloud hosting, storage and encrypted backups; Amazon SES for transactional email (invitations, password resets, notifications); AWS Bedrock, which processes an excerpt of a student's own in-progress draft only when a school or Free-plan educator turns on the opt-in AI comprehension check, and only for that purpose (see section 3); Stripe for subscription billing for School-plan institutions: institution billing contacts and payment-transaction data only, never student data, student accounts or evidence records (see section 8); and PostHog for optional analytics and masked session replay on the public marketing website only, hosted in PostHog Cloud EU. PostHog replay is disabled on the public local-verifier route. A selected PDF is processed locally and no PDF content, identity, evidence, file metadata or verifier result is sent to PostHog or another processor. PostHog is not used for analytics or replay in the signed-in application (see section 10 and our Cookie and Website Analytics Notice). Service providers are bound by contractual obligations, act only on our instructions, and never gain rights to use personal information for their own purposes. Our current subprocessor list is published on our subprocessors page, and institutions on a DPA are notified of changes in advance.

    Identity providers (Google and Microsoft single sign-on). If someone signs in with Google or Microsoft, that company authenticates the person and returns the identity information described in section 3. Google and Microsoft are not included in DPA Schedule 3; their role is limited to sign-in initiated by the user or Institution. We list the relationship here and on our subprocessors page for transparency. We do not send student writing, evidence records, classes or submissions to them.

    Legal requirements. We may disclose personal information where required or authorised by law, for example in response to a court order. Where lawful, we will notify the institution before disclosing student information and will challenge requests that are overbroad.

    Business changes. If Loam is involved in a merger, acquisition or asset sale, we will ensure the recipient is bound by commitments at least as protective as this policy, and institutions will be notified.

    We never sell personal information, and we never share it with data brokers, advertisers or AI-training pipelines.

  8. 08

    Where your information is stored

    The Service is hosted with Amazon Web Services in the region you choose when you sign up: Sydney (Australia), Frankfurt (Europe) or N. Virginia (United States). Your stored work, evidence records, account data and encrypted backups stay in that region. Data location commitments are confirmed in each institution's agreement.

    Overseas recipients. The table below lists the third parties that receive personal information overseas, the country or region involved, the data disclosed, and the purpose.

    • Amazon Web Services hosting: the institution's selected region: Australia, Germany or the United States. Data: service data stored for that institution. Purpose: hosting, storage and delivery of Loam.
    • Amazon Simple Email Service: the same selected region as the institution: Australia, Germany or the United States. Data: recipient name and email address, message type and delivery details. Purpose: transactional email.
    • Amazon Bedrock: The geography of the institution's selected region: within Australia for the Australia region; within the United States for the United States region; and within the European Union, which may include EU member states other than Germany, for the Germany region. Data: the last approximately 600 words of writing, without account identifiers. Purpose: optional comprehension-question generation after an educator turns the feature on.
    • Stripe: United States and other locations used by Stripe. Data: institution billing contact, transaction and payment details; no Student Work. Purpose: institution billing and payment processing.
    • PostHog: European Union, hosted in Germany. Data: consented public-site analytics and masked replay data on eligible routes; on /security/, only a static page view and coarse sample-download, sample/non-sample selection, and successful sample/author-export verification classifications. No selected PDF, filename, author, account name, content, proof identifier, evidence, replay, disclosure level, failure result or explicit verification duration. Purpose: public-site analytics and product improvement.
    • Google: countries in Google's global service infrastructure; exact processing locations are not fixed by Loam and must be confirmed from the applicable agreement. Data: sign-in request and the name, email, subject identifier and profile image returned by Google; no Student Work. Purpose: sign-in chosen by the user.
    • Microsoft: countries in Microsoft's global service infrastructure; exact processing locations are not fixed by Loam and must be confirmed from the applicable agreement. Data: sign-in request and the name, email, subject identifier and profile image returned by Microsoft; no Student Work. Purpose: sign-in chosen by the user.

    Difinity's Australian operations personnel are part of Difinity, not a separate overseas recipient for APP 8 purposes. Their limited access is described below. Foreign service providers remain subject to the overseas-disclosure assessment.

    Difinity's operations personnel are in Australia. In the Australian operations system they can see only opaque Loam identifiers for the student, teacher, school and support request, together with the name, work email address and support messages of a teacher or school administrator who contacts us. They cannot see or receive a student's name, email address, date of birth, writing, replay, evidence record or other directly identifying student details or student content. Student content and direct student identifiers remain in the institution's selected region.

    Australian operations personnel are part of Difinity, so their internal access is not treated here as disclosure to a separate overseas recipient. APP 8 still applies to relevant foreign service providers, and Difinity must take reasonable steps before disclosure and may remain accountable for their handling.

    Sign-in exchange with Google and Microsoft. When someone signs in with Google or Microsoft, the sign-in exchange itself (the authorisation request and token exchange) is made to that provider's own global infrastructure, which may sit outside Australia; the identity information described in section 3 that the provider then gives us is stored in the region you (or your school) chose at signup, the same as your other account data (see above). This provider-side exchange may occur outside the selected region; the identity information returned to Loam is stored in the selected region.

    Your physical location and your chosen region are different things. The Free plan is available globally, so wherever you are, your information and your students' information is stored in the region you (or your school) chose at signup (see above), and handled under this policy. If your chosen region is not where you are, this may be an international transfer from your country's perspective; see section 16 for what that means for users in the EU and UK.

  9. 09

    How we protect it

    • Encryption: end-to-end TLS for data in transit across all regions, and encryption at rest.
    • Tamper-evident records. Evidence chains are hash-linked (SHA-256) and countersigned by our servers, so alteration of records is detectable, including by us.
    • Password protection. Passwords are hashed with argon2; sessions use secure, httpOnly cookies.
    • Workspace isolation. Each institution's data is partitioned in its own workspace, with tenant-scoped access controls.
    • Production access. Production access is logged. Further work to narrow deploy and operational access is scheduled. Support access to an account holder's own activity remains subject to the controls described in section 7.
    • Encrypted backups. Nightly backups are retained for 30 days and monthly backups are retained for 1 year in each region.

    No system is perfectly secure, and we do not promise the impossible. But we notify promptly when something goes wrong (section 12) and we minimise what there is to lose (section 2).

  10. 10

    Cookies

    The application uses an essential session cookie to keep users signed in. It is secure, httpOnly, and not used for tracking. The signed-in application uses no PostHog analytics or replay and no advertising cookies.

    The public marketing site uses an essential first-party cookie to remember the visitor's analytics choice. Only after explicit consent, it loads PostHog Cloud EU for anonymous website analytics and masked session replay and stores first-party analytics cookies or similar browser values. Before consent, after rejection, or while Global Privacy Control is active, no visitor analytics or replay request is sent. Query strings are stripped and every input and form value is masked on routes where replay is enabled. Replay is disabled entirely on /security/, where consented analytics are limited to one static page view and coarse counts for sample download, sample/non-sample selection, and successful sample/author-export verification. Selected PDF data and verifier results are not sent. These events carry a random anonymous browser identifier and timestamp for unique counts, which can make elapsed time inferable; Loam adds no duration, named profile, or time-to-verify report. Replays are retained for no more than 30 days. Analytics events and associated metadata are retained for up to 7 years under our current PostHog Cloud plan. Visitors can withdraw consent through Cookie settings in the site footer. Our Cookie and Website Analytics Notice gives the complete list of data, storage and controls.

  11. 11

    How long we keep it

    On institution (School) plans:

    • During the subscription, student work and evidence records are retained as the institution directs, with a default retention period of 7 years from submission, configurable by the institution to its own records policy. Evidence often needs to remain available for the institution's marking, review and appeal periods.
    • After termination, the institution has a 30-day export window; we then delete its live account profiles, class memberships, student work and evidence within 90 days. Product-database audit, acceptance and agreement records are kept for the separate period stated in the table below. Deleted data may remain in encrypted, whole-database backup copies until those age out on our rolling backup schedule. In all regions, nightly backups are retained for 30 days and monthly backups are retained for 1 year, unless the law requires otherwise.
    • Account deletion requests for individual students are actioned on the institution's instruction (see section 5), since the institution controls its academic records.

    On the Free plan (personal workspaces):

    • The replayable evidence record for each submission is retained for 12 months from the date of submission (for a draft that is never submitted, 12 months from its last activity). The 12-month clock cannot start before 19 July 2026 for records created before that date. After that, the detailed edit history and its replay are deleted. The final document, its verification outcome, and the server timestamps that anchor the evidence chain are kept while the personal workspace remains active, and are deleted after the workspace's 30-day deletion-recovery period, so a past verification remains attested even after the detailed record expires.
    • Notice before anything is deleted. We give staged notices (in the product and by email) at 60 days, 30 days and 7 days before a submission's evidence passes out of retention, with a one-click export as the primary action in every notice. Export is free and works up to and on the expiry date.
    • Dispute and legal hold. If a submission is involved in an academic-integrity process, an appeal, or a legal matter, the educator can place it on hold; held records are exempt from the retention schedule until the hold is lifted. Holds are free and logged.
    • The schedule is prospective. It applies to evidence created after it took effect; it is never applied retrospectively to evidence collected before then, and the first deletion under any new or changed schedule happens no less than 90 days after account holders are notified of it.
    • Retention duties stay with the teacher and school. The Free plan is not a records-management system. Educators and schools remain responsible for their own records-retention obligations; where a school requires records kept longer than the Free plan's schedule, export them or use an institution plan, where retention follows the school's records policy.

    Every other category of record we hold, with the exact period, is set out below. No category is kept for an open-ended or unstated period.

    • Free-plan working content and evidence. Working content, replay events and detailed evidence are deleted after 12 months. The 12-month clock cannot start before 19 July 2026 for records created before that date.
    • Free-plan final record. The final document, verification result, server timestamps and compact integrity anchors remain while the personal workspace remains active. They are deleted when the personal workspace is deleted, after a 30-day recovery period. If an institution takes control, its contract and retention setting apply.
    • Account profile and class membership. Retain while the account and workspace are active. Deactivation alone does not delete the record. A personal-workspace deletion removes the account after the 30-day recovery period. An institution termination gives a 30-day export window and deletes the account profiles and class memberships from live systems within 90 days, unless a legal hold applies. Product-database audit, acceptance and agreement records are separate records and are kept for the period in the row below.
    • Linked Google or Microsoft identity. Retain while the link and account remain active. Delete on unlinking, personal-workspace deletion, or institution offboarding when the linked account is deleted. Deactivation alone does not delete it.
    • Temporary sign-in flow. Google and Microsoft sign-in-flow records expire after 10 minutes and are removed by the existing daily retention run.
    • Signed-in session. The sign-in credential stops working 30 days after it is created. The database record is deleted 90 days after expiry. Logout, a security reset, account deletion or workspace deletion may remove it earlier.
    • Routine operational and infrastructure logs. This includes logs that record access to or changes in our cloud systems. Retain for 30 days, then delete or de-identify. These infrastructure logs are not covered by the 7-year row below.
    • Product-database security, acceptance and agreement records. This means in-app audit rows, policy-acceptance records and executed-agreement records held in the product database. It does not include operational or infrastructure logs. Retain for 7 years after the event, or while a related institution agreement remains in force, whichever is longer.
    • Support correspondence. Retain for 2 years after the ticket closes, then delete, unless the request has been reopened or a legal hold applies.
    • Billing and tax records. Retain for 7 years after the end of the financial year in which the transaction occurred, then delete unless a legal hold applies.
    • Backups after live deletion. Deleted live data may remain in nightly backups retained for 30 days and monthly backups retained for 1 year. It is isolated from normal use and removed when the backup expires.
  12. 12

    Data breaches

    We maintain a data-breach response plan. We will notify affected institutions of any data breach affecting their data without undue delay. Where a breach is likely to result in serious harm, we will also comply with the Notifiable Data Breaches scheme under the Privacy Act, including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals where required. For student data we coordinate notification with the institution so families hear it from the school, accurately and quickly.

  13. 13

    Access, correction and deletion

    You may request access to, or correction of, the personal information we hold about you.

    • Students and parents/guardians: the fastest path is through your school, which controls its academic records, and we act on its instructions. You may also contact us directly; we will respond, coordinating with your institution where the information forms part of its records.
    • Institution staff and website contacts: contact us directly.

    We respond within 30 days. If we refuse a request (for example, where records must be preserved for a pending academic process), we will explain why in writing and tell you how to complain. There is no charge for making a request.

    Note that evidence records are deliberately tamper-evident: "correcting" the content of an evidence chain is not possible without invalidating it. Where information in an evidence record is disputed, we can attach a statement of disagreement and the institution can act on the dispute under its own processes.

  14. 14

    Complaints

    If you have a privacy concern or complaint, contact our Privacy Officer at hello@loam.ink. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.

    If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, phone 1300 363 992, or GPO Box 5288, Sydney NSW 2001. Students at public schools may also have complaint rights under their State or Territory's privacy scheme (for example, via the Information and Privacy Commission NSW for NSW government schools' own conduct).

  15. 15

    Changes to this policy

    We may update this policy from time to time. Material changes will be notified by email, at least 30 days before they take effect, to institution administrators and to individual account holders on the Free plan, and the "last updated" date above will change. Changes are prospective. We will never weaken the commitments in section 2 ("what we deliberately never collect") without the clear, advance, opt-in agreement of affected institutions and account holders.

  16. 16

    Users in the EU and UK: GDPR basics

    The Free plan is available globally, so some educators use Loam from places where the EU General Data Protection Regulation or the UK GDPR applies. In plain terms:

    • Where the data goes. If you or your school chooses the Europe region at signup, your stored data is held in Frankfurt, Germany, and there is no storage transfer to Australia. If you choose the Australia or United States region instead, your stored data is transferred to and held in that region. In every region, Difinity's operations personnel in Australia have the limited access described in section 8; for data stored in Europe, this access is an international transfer to Australia, and Australia does not hold an EU or UK adequacy decision. The access control sharply limits the information available in Australia, but it does not by itself end the EU or UK transfer analysis. An opaque identifier can remain personal data if Difinity can link it back to a person, and teacher or school-administrator support information remains personal data. We therefore treat the Australian operations path as requiring a documented transfer assessment unless qualified counsel concludes otherwise.
    • Roles. For student information, the school (or the educator, where they use a personal workspace) acts as the controller; Loam processes on documented instructions, as described in section 5 and in our Data Terms (personal workspaces) or DPA (institution plans).
    • Transfer mechanism. Loam's published Data Terms and standard DPA template do not themselves incorporate the EU Standard Contractual Clauses or the UK International Data Transfer Addendum. If your use requires either instrument, contact hello@loam.ink before using the Service so the applicable terms can be agreed in writing.
    • Your rights. Access, rectification, erasure and portability requests are handled through the channels in section 13; evidence bundles are the portable export format.
    • No automated decision-making. Loam's signals are indicators presented for a teacher's professional judgement (section 3); the Service makes no automated decision producing legal or similarly significant effects about a student.
  17. 17

    Age, and school authorisation outside Australia

    • Students under 13. Loam holds students' names and school email addresses, so we treat age seriously rather than looking away. On the Free plan, educators attest when adding students that their students are 13 or older (or over the digital-consent age where they live, which is up to 16 in some EU countries), or that their school has authorised the use and the required notices and consents have been handled. Students under 13 without school authorisation are not supported on the Free plan. We say this plainly because a teacher's personal signup cannot supply the parental-consent machinery that regimes like COPPA (US) require.
    • United States (FERPA). The Free plan is not offered as a FERPA arrangement. An individual teacher's signup cannot make Loam a "school official" under FERPA; US educators attest that their school has authorised their use. Formal agreements are an institution-plan matter, and institution plans are not yet offered in the US.
    • Canada. Provincial public-sector privacy and data-residency rules (for example for public-school boards) are not something an individual teacher can satisfy by signing up. As with FERPA, we disclose plainly: Loam stores your data in the region you choose at signup (section 8), and Canadian educators attest that their use is authorised under the policies that apply to them. We make no compliance claim we cannot support.
  18. 18

    Contact

    Privacy Officer: Loam, Difinity Pty Ltd (ABN 82 686 692 759), New South Wales, Australia. Email: hello@loam.ink.

Optional website analytics

With your permission, Loam uses PostHog EU to understand which public pages help visitors and where they leave. Session replay masks every input and is disabled entirely on the document-verifier page. We do not run PostHog analytics inside the signed-in app.

Read the cookie and analytics notice