Privacy Policy
Last updated: 13 July 2026
Rubrica (operated by Quickers Italia) is built for European digital sovereignty. Personal data is processed inside the EU, on European infrastructure and European AI. This policy explains what we process, why, and your rights.
1. Roles under the GDPR
- For account and institutional data, Quickers Italia is the controller.
- For student personal data processed through Rubrica Professor on your behalf, your institution is the controller and Quickers Italia is the processor (governed by our DPA).
- For Rubrica Student (individual learner accounts), Quickers Italia is the controller for running the service; you keep ownership of the notes and material you upload.
2. Data we process
- Account data: name, email, institution, authentication.
- Course content you create or upload: syllabi, slides, PDFs, images, URLs.
- Student data: roster emails and names, quiz attempts and scores, attendance, peer/jury ratings (aggregated), feedback.
- Usage and technical logs needed to run and secure the service.
3. Purposes & legal bases
- Providing the service (performance of a contract).
- Security, abuse prevention and service improvement (legitimate interests).
- Student self-enrolment and check-in (consent captured at the point of entry).
4. European data residency
Accounts, course content, quizzes, attempts, documents and reports are stored on European servers (self-hosted Postgres, authentication and file storage). Nothing is replicated to a non-EU region. There are no US cloud providers in the data path.
5. Sub-processors
We use a minimal set of European sub-processors:
- Mistral AI (Paris, France) - AI generation (quizzes, decks, answers) via its paid API. Per Mistral's terms, paid-API inputs/outputs are not used to train its models; processing is EU-prioritised (with GDPR safeguards for any exceptional transfer); API data is retained only ~30 days for abuse monitoring, or zero-retention where enabled. Sub-processors: trust.mistral.ai/subprocessors.
- Hostinger - European hosting for our self-managed servers.
- Stripe - payment processing for Rubrica Student subscriptions only. Stripe receives the billing data needed to take payment; it does not receive your uploads or study notes. Any transfer is covered by Standard Contractual Clauses.
Text-embedding models (Ollama) run locally on our own EU servers - not a third-party service. For AI generation we use Mistral (EU); we do not use OpenAI, Anthropic, or US hyperscalers for your learning content.
6. AI processing
To generate content, the relevant prompt and grounding text are sent to Mistral's EU API and the result returned to you. This data is not used to train AI models. AI outputs may be inaccurate and must be reviewed by the educator before use.
7. Retention
We keep personal data for as long as your account is active or as needed to provide the service, then delete or anonymise it. Under the DPA, we delete or return student data on the institution's instruction or on termination.
8. Security
Access controls and database-level Row-Level Security isolate each institution's data. Peer and jury ratings are structurally anonymous - individual votes are never exposed, only aggregates. Data is encrypted in transit (TLS).
9. International transfers
By default, personal data stays within the EU. Where any exceptional transfer occurs at the sub-processor level, it is covered by GDPR safeguards such as Standard Contractual Clauses.
10. Your rights
You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to lodge a complaint with your supervisory authority. For student data, requests are directed to the controlling institution. Contact us at hola@rubrica.pro.
11. Rubrica Student - your uploads & model improvement
- What we process: the photos, PDFs, text and notes you upload, the study notes generated from them, your email, and minimal usage/billing metadata.
- Free plan. In exchange for free use, your content may be used in anonymised/pseudonymised form to improve Rubrica (quality, features, and - with safeguards - model grounding). We strip direct identifiers before any such use.
- Pro plan. Your content is private and never used to train or improve our models. You can also opt out of improvement at any time from your account.
- Deletion: you can delete any noteset or upload at any time, and delete your account to remove your personal data, subject to lawful retention (e.g. billing records).
12. Changes & contact
We will notify material changes to this policy. Questions or data requests: hola@rubrica.pro. See also our Terms of Service and European sovereignty page.