Checkleaf
Privacy Policy
Checkleaf has no account, no server of its own and nothing that reports on a student. Everything the app knows is one database on this device, and this page says what can leave it: in plain words first, then table by table for anyone who wants to check.
This is the policy Checkleaf shows under Settings › Privacy Policy, word for word. Where it says "this page" or "this device," it means the app and the phone it runs on.
What Checkleaf saves
Checkleaf saves an image of each scanned sheet, and what it read from it: the bubbles, the name and ID at the top, every answer and the score. It also keeps your tests and answer keys, your classes and rosters, the corrections you made, and the name and school you typed in Settings. A test you delete waits thirty days in case you want it back, then goes for good.
What can leave this device
Three things, and nothing else.
Your device’s own backup. iCloud or Google backs this app up with the rest of your phone, scanned images included. That is your phone copying itself, not Checkleaf sending anything, and it is switched off in your phone’s settings.
Files you send. A test, a stack of papers, a printed page or a spreadsheet leaves only when you hand it to the share sheet yourself. No file Checkleaf writes carries an image of a sheet.
Reports about the app. Each time the app starts, Google’s Firebase service is told that this install exists. If you turn reports on, it is also told how the app is used and when it crashed. A report never carries a student’s name, ID, score, answers or a picture of a page, and Google keeps each one for fourteen months.
What you control
Backups are yours to switch off, in your device’s settings. Files go only where you send them. The Share Reports switch, in Settings and at the end of this page, turns the reports off at once; turning them off also deletes the random identifier they were filed under, so nothing sent later can be joined to what was sent before.
How to delete it
Delete All Data, at the foot of Settings, destroys the database: every class, test, key, roster, paper, score and image, and the name and school you typed. Removing the app deletes everything it wrote here. Three things neither can reach: a copy you already sent somewhere else, a device backup already taken, and a report Google already received.
In detail
The same page, table by table: what the camera keeps, each of the database’s twenty tables, the two messages that go to Firebase, and the five libraries the app is built from. Nothing below says anything the summary does not; it says it exactly.
The Camera
The camera does one job: reading the sheet in front of it. Frames arrive as gray pixels, the reader finds the four corner markers and measures every bubble, and each frame is dropped as the next one arrives — every frame but the one that reads the paper. That one Checkleaf keeps, as a picture of the whole page the way it was scanned: the bubbles, the name and ID block at the top, and anything written in the margins. It is there so you can look at the page a grade came from when somebody asks you about it a term later. Checkleaf keeps a closer picture too, for each row the reader will not call — that row of bubbles on its own, so you can see what the camera saw when you decide the mark.
There is no photo capture on either platform, so the only picture this app can make is one cut out of a frame it was already reading: nothing of the room, and nothing with the scan screen closed. Both kinds are kept on this device, they are in no file Checkleaf writes, and Delete All Data destroys them. What it writes down beside them is what the reader found: which bubbles were filled, how dark each one was, and the score that follows.
The screen itself is more public than any this app has drawn before. Propped up to take a stack in, it is facing a room: while a paper is being read it shows that student their own name and nothing else about them, the name goes as the sheet leaves, and no score is ever shown there. Checkleaf asks for one other permission, and only when you start a Paper Drop: on Android, notifications, so the count on the lock screen keeps up while you are away from the phone. On Android it may also stay open for up to three minutes when you leave it with papers still saving, showing a ‘Saving papers…’ notice until they are written; that asks you for nothing.
What stays on this device
One database, in this app’s own storage, with twenty tables. Your tests: the title, the subject, the layout, the answer key, the roster you typed or imported, the passing score, the day you gave the test, and which of your classes it belongs to. A test you delete is kept for thirty days so you can put it back, out of every list, every total and every file in the meantime; then Checkleaf destroys it, and Delete Now destroys it sooner.
Your classes: the name you call each one, the roster it holds now, the passing score its tests start from, the color it wears in your lists, and the day a new term put it away if you have started one. That roster is a list of children, kept the way a test’s own is — a test file or a papers file you send carries no class at all, and the only file a class travels in is a backup you make yourself. Starting a new term deletes nothing: the class comes off your list with its roster and its passing score, and they stay on this device until you delete the class yourself.
The classes you deleted: Checkleaf writes a class down from the subject you give a test, so deleting one leaves a note saying not to write it down again. Each note is the subject in lower case and the tests it was about — no roster, no names, and nothing a note by itself could tell anyone about a child. It travels in a backup you make yourself, so a phone you restore does not put back the classes you got rid of.
Your students: one row for each child on your rosters, holding the name you read, the student ID your school issued if they have one, and whether Checkleaf wrote the row down from a roster or you added the student yourself. Checkleaf writes these down from the rosters you already keep, and a student you add yourself is kept here and nowhere else. There is nothing else in the row — no note, no photograph and no attendance mark — and it is here so one child’s papers across several tests are one child. It travels in a backup you make yourself, and in no other file.
The students you removed: Checkleaf writes a student down from your rosters, so removing one leaves a note saying not to write them down again. Each note is a student number in the app’s own short form and the roster lines it was about — the class, the number on the line and the name your roster spells there, in lower case. The name is in the note for one reason: if your school gives that number to a new child, Checkleaf has to see a new child rather than the student you removed. It travels in a backup you make yourself, so a phone you restore does not put back a student you removed.
Your papers: one row each, holding the paper number, the student ID and name it was matched to, the period and form it came from, when you scanned or typed it in, every answer as the reader saw it, and a record of every correction you made. A paper that arrived in a colleague’s papers file keeps two things more: the day it arrived, and the name that file gave for whoever sent it, which is the name they had typed under Name and School on their own phone and the file carried across. It is a note about one file rather than a person this app knows — nothing joins two of them, no printed page and no spreadsheet or papers file you send has a place for it, and your own backup is the only file it travels in.
What you have handed off: one line each time a file was made or a page went to a printer, holding an app-made id for that handover, what kind it was, which test, period and form it covered, the day, and how many papers each test had issued by then, which is how the Share screen can say what has arrived since. Nothing this app sends carries that log, and the Delete All Data button destroys it with the rest.
The rows the camera could not read: for each mark still waiting on you, one strip of the page it came from, kept as the gray pixels the camera saw. A row of bubbles wide and no more — no name, no ID, nothing else off the sheet — and at most twelve to a paper. They are here so you can check the app against the paper in your hand, and they go when the paper does.
The page each paper was read from: for every paper the camera reads, one picture of the whole sheet as it was scanned — the bubbles, the name and ID at the top, and anything written in the margins. It is here so you can look at the page a grade came from long after the paper itself has gone home, and each paper keeps one and no more. It stays on this device, no file Checkleaf writes carries it, and it goes when the paper does.
A media-reference row holds a test’s id, a paper and question number, the picture’s size, its byte count, a fingerprint of its bytes and an app-made file name. It holds no person’s name.
A picture-revision row holds a test’s id, a paper number and an app-made id that changes each time a rescan replaces that paper’s pictures of the rows the camera could not read. It holds no person’s name.
A maintenance row holds only whether storage cleanup is pending or done.
A filing receipt records one filed paper: a test’s id, an app-made id for that filing, an app-made id for the sheet when it came from a scan, a paper number and whether it added, replaced or rescored the paper. It holds no person’s name.
Collecting a test: one line each time you take a stack in as students hand it to you — which test, which of your classes, when the collection began, when its timer ran out and when you ended it, and how many papers the roster expected that day. That count is the one that stood on the day, so a roster you change in October leaves what September said alone. No child is named in that line.
Who handed in, and when: inside each collection, one row for every paper that went in — the paper’s number, its place in the order, the minute it arrived, the ID on the roster it filed under, and whether it came in with marks still waiting on you. It is here so a stack you took in is a record of a period rather than a pile in a different order by the time you get to it. It stays on this device, no file Checkleaf writes carries it, and it goes when the test does.
And your preferences, which is where the name and school you type in Settings are kept — those two print on the class report and the student reports, so a page that leaves says whose class it is. Nothing else is kept: no email address, no location, no contacts, and no identifier of Checkleaf’s own for you or for this device — the random identifier the reports use is the Firebase library’s, described below.
Getting ready for cloud backup
Checkleaf is building an optional backup you could switch on, and it keeps a line for each thing such a backup would cover — one test, your classes, or the list of what the backup holds. A line holds a scrambled name that stands in for the thing, Checkleaf’s own name for it, a fingerprint of the copy last sent, the version number that copy was given, whether you have deleted it here since, and a little bookkeeping about the last copy sent, so a backup that was cut off can finish on its own. Checkleaf’s own name is kept so a test you delete here can still be recognized in a backup you have not deleted — without it, the copy would be one nothing could ever open again. No title, no roster, no name and no score is in any of it: what Checkleaf calls a test is the random id it made when you created it. It stays on this device, and neither the scrambled name nor the fingerprint can be read back into what it was made from.
The backup being sent: before Checkleaf sends the list of what a backup holds, it saves two kinds of note, so a dropped connection can be finished rather than guessed at. One is an exact copy of that list, with a random id for the attempt, when it was made and how it stands; the other is a line for each thing the list covers, with the same scrambled name, Checkleaf’s own name for it, and the fingerprint and version number of the copy sent and of the one it replaces.
The account a backup would belong to: one line, for the same feature, naming the account such a backup is kept under, whether its first backup has finished, and the last change number the backup reported. The part of Checkleaf that writes all of this is built now, and it writes a line each time it sends something — but it runs only for an account, and this build has nothing to sign in to, so it never runs. There is no account to name yet, so all of this is empty on every device today, and no file Checkleaf writes carries any of it. When that changes, this page changes with it.
Backups the platform takes
Both platforms back up the apps on a device, and this database is inside what they take. That includes the pages: a copy of every sheet you have scanned rides your own device backup along with the grades. On iOS it sits in the app’s Documents folder, which iCloud device backup includes. On Android Checkleaf asks for that backup deliberately, and Google’s servers hold it under one condition the app attaches: no cloud copy at all on a device that cannot encrypt it end to end with the screen lock. That is the platform copying your device rather than Checkleaf sending anything — but a policy that said nothing ever leaves would be wrong without it. Either backup is switched off in the device’s own settings, not in this app.
What leaves, and only when you send it
No file leaves this device until you choose where to send it. When you do, Checkleaf writes a real file and hands it to the system’s share sheet; where it goes next is whatever you pick there. The files are the printed pages as PDFs, the spreadsheets as CSVs, and three formats only Checkleaf reads: a test, a stack of papers, and a backup of everything on this device. None of the three carries a picture of a page, so a backup you restore puts your grades back without them: the papers come back with their scores, and the marks that were waiting show the reader’s measurements instead. Printing works the same way, through the system’s own print dialog.
There is no automatic export, no upload on a schedule and no sync in the background — every file that has ever left this app was a tap you made. The two exceptions have their own parts below: the note at every start, and the reports you can turn on.
What leaves at every start
Each time the app starts, Google’s Firebase library registers this install with Google, whether the reports below are on or off. It sends a random identifier for this install and which app and version this is, and it checks in with Google’s analytics service, which carries no report while the reports are off. Nothing you typed and nothing from a page goes with it.
The identifier is there so the reports can be told apart. Turning them off deletes it, and the next start makes a new one. On Android, this registration and the reports are the only reason the app can use the network at all.
Reports about the app, off until you turn them on
Checkleaf can send two kinds of report to Google’s Firebase service. Both stay off until you turn them on, and grading works either way. The Share Reports switch, in Settings and at the end of this page, turns them off at once; turned on, they start the next time you open the app.
The first is how the app is used: which screens open, which tools get used, and rough counts as a range, like 6 to 20 sheets in a scan, never the number itself. The second is a crash report: what the app was doing when it stopped, with the phone model and system version.
Neither can carry a student’s name, ID, score, answers or a picture of a page: the app has no way to put one in, and it is tested for that before every release. Each report carries the install identifier described above and travels over your phone’s connection. Google works out an approximate location from the internet address a report or the start-up note arrives from, as any website can; the app itself never reads your location. Google keeps each report for fourteen months, then deletes it. The Google setting that would join reports to a Google account, for advertising, is off.
Turn the reports off and they stop; the identifier is deleted with them, so nothing sent later can be joined to what was sent before. Delete All Data deletes the identifier the same way and turns the reports off, as on a fresh install.
Delete All Data
The Delete All Data button, at the foot of Settings, destroys the database: every class, test, key, roster, paper and score, every page the camera read and every strip of one it kept, and the name and school you typed. It deletes the install identifier and turns the reports off, as on a fresh install.
It also sweeps what the file features leave behind — the copy an export wrote for the share sheet, the copy iOS makes in this app’s Inbox when you tap a file into Checkleaf, and the test named under the app’s icon. If any of that will not go, the screen says which part rather than claiming a clean sweep.
Three things it cannot reach: a copy you already sent somewhere else, a device backup already taken, and a report Google already received — though with the identifier gone, nothing sent later can be joined to it. Removing the app deletes everything it wrote here.
Changes
This describes Checkleaf as it is today, and the app is tested against these words: a camera that captured a photograph, a twenty-first table in the database, a new library, or a permission that reaches anything of yours would each be caught before release, and this page rewritten first.
Checkleaf is built out of Android’s own libraries and JetBrains’, and five others. Koin puts the app’s parts together as it starts. Kermit writes Checkleaf’s own diagnostic lines into the log this device already keeps for every app on it. ZXing draws the square code a Key Pass shows and reads one off another phone’s screen. None of those three asks for a permission of any kind, and none holds code that opens a connection; each was checked for that before it was let in.
The fourth is Google’s Firebase, which carries the reports and the start-up note described above: it is the one library here that can open a connection, and the reason the app asks for the network at all. The fifth is CrashKiOS, on iPhone only, which makes a crash inside Checkleaf’s own code readable in that report rather than a list of numbers; it opens no connection itself and hands what it finds to Firebase.
No other library ships in Checkleaf, including one carried inside another, until this page names it.
Usage and Crash Reports
In the app, this page ends with the Share Reports switch. Open Checkleaf, go to Settings › Privacy Policy, and the switch is at the bottom. It is also in Settings itself.
Contact
Questions about this policy go to privacy@rayalabs.co. Checkleaf is made by Raya Ventures LLC, a Washington limited liability company doing business as Raya Labs.