En enkel oversikt over hvordan Skriveøkt by Papertek beskytter personvernet til elever og lærere.
Ingen teknisk bakgrunn nødvendig – alt forklart med enkle ord og diagrammer.
Skriveøkt by Papertek er bygget på én enkel regel: samle inn så lite som mulig, og slett det så fort som mulig.
Ingen konto, ingen e-post, ingen passord. Bare en prøvekode og et kallenavn.
Teksten lagres uten kobling til ekte identitet. Kun kallenavn synlig.
Identifisert med en hashet referanse. Navnet lagres ikke på prøven.
Steg for steg – hva som lagres og hva som ikke lagres.
Koden er laget av læreren, f.eks. «HAUG-2024»
Bruk kun fornavn – aldri etternavn. Det holder at læreren kan kjenne deg igjen i klasserommet.
Teksten lagres som ren tekst. Ingen formateringsdata, ingen metadata om enheten.
Både besvarelsen og hele skrivehistorikken. Igjen står bare deltakerlisten – kallenavn og innleveringsstatus – til læreren sletter prøven, og senest til den årlige oppryddingen i juli.
Hva lagres IKKE om eleven:
Tenk på det som et bankskap – banken vet ikke hva som er inni.
Enveis-hashing betyr at:
Prøven inneholder bare den hashede referansen – aldri lærerens navn eller e-post.
Merk: en hash er ikke det samme som kryptering. Kryptert tekst kan låses opp igjen – en hash kan ikke. Det er nettopp derfor vi bruker hashing her.
Du kan bruke Skriveøkt by Papertek med bare en lærernøkkel, uten å logge inn med Google. Det gir maksimalt personvern, men innebærer en risiko.
Ingen persondata lagres overhodet. Ingen Google-konto, ingen e-post, ingenting som kan spores tilbake til deg.
Nøkkelen er din eneste kobling til prøvene. Hvis du mister nøkkelen, mister du tilgangen til alle prøvedataene dine – permanent.
Viktig: Papertek kan ikke gjenopprette tilgangen din hvis nøkkelen går tapt. Enveis-hashingen gjør det umulig å finne nøkkelen fra de lagrede dataene.
Vår anbefaling: Ta vare på nøkkelen på et trygt sted. Hvis du vil unngå risikoen for å miste tilgang, kan du logge inn med Vipps (helt anonymt) eller Google – da har du alltid en sikker kobling til prøvene dine via kontoen din. Lærernøkkelen er mest relevant for administratorer som ønsker å tildele anonyme tilgangskoder til lærere.
Vipps brukes som en sikker inngangsport – men Papertek lagrer ingen av opplysningene dine.
Vipps ser IKKE:
Skriveøkt by Papertek lagrer IKKE:
Hvordan fungerer det teknisk?
Firebase Authentication (innloggingssystemet) håndterer selve Vipps-påloggingen. Under økten vet Firebase midlertidig hvem du er – dette er nødvendig for å bekrefte at du er den du sier du er.
Men vår database (Firestore), der prøver og lærerdata faktisk lagres, mottar aldri navn, e-post eller telefonnummer. Kun en anonym identifikator («sub») lagres – en tilfeldig kode som ikke kan spores tilbake til deg.
Forskjellen fra Google-innlogging: Når du logger inn med Google, lagrer Papertek navn og e-post i databasen (for å vise i profilen din). Med Vipps lagres ingenting som kan identifisere deg. Vipps gir dermed det beste personvernet av alle innloggingsmetoder.
Tenk på det slik: Vipps er som en dørvakt som sjekker legitimasjonen din, men forteller ikke bygningen hvem du er. Bygningen (Papertek) vet bare at dørvakten slapp inn «person nr. 12345» – ikke at det var deg.
Google brukes bare som en digital dørvakt – ikke som en spion.
Google ser IKKE:
Skriveøkt by Papertek deler IKKE med Google:
Tenk på det slik: Google er som en vakt ved døren som sjekker legitimasjonen din. Vakten bekrefter at du er den du sier du er, men får ikke vite hva du gjør inne i bygningen. Vakten går hjem etter å ha sluppet deg inn.
Viktigst: Prøvedataene kobles til læreren med den hashede referansen – ikke med Google-kontoen. Selv om noen hacket Google-innloggingen din, kan de ikke se prøvene dine uten lærernøkkelen.
Google Firestore som database
Skriveøkt by Papertek bruker Google Firestore til å lagre prøvedata. Firestore er en skydatabase som kjører på Google Cloud-infrastruktur i Belgia (EU, europe-west1).
Google leverer infrastrukturen, men har ikke tilgang til innholdet i dataene på applikasjonsnivå. Tenk på det som en utleier som eier bygningen, men som ikke har lov til å åpne leilighetene.
Google behandler data i henhold til EUs personvernforordning (GDPR) og Paperteks databehandleravtale med Google.
For skoler er Feide den primære innloggingen: når skolen har inngått en databehandleravtale (DBA) med Papertek, logger både lærere og elever inn med sin Feide-skolekonto i stedet for bare prøvekode og kallenavn. Da behandles identifiserbare personopplysninger under DBA-en, og avsnittene over om anonym bruk gjelder ikke fullt ut.
Hva innebærer en DBA? Skolen er behandlingsansvarlig og bestemmer formålet med databehandlingen. Papertek er databehandler og følger skolens instrukser. All databehandling er regulert av avtalen, og elevens tekst og skrivehistorikk slettes fortsatt automatisk etter 30 dager. Navnet fra skolekontoen blir stående i deltakerlisten til læreren sletter prøven, og senest til den årlige oppryddingen i juli.
Google-innlogging krever databehandleravtale på lik linje med Feide.
Både elever og lærere kan også logge inn med en Google-konto. Da lagres navn og e-postadresse på nøyaktig samme måte som ved Feide – og da gjelder de samme kravene. Avtaleplikten følger personopplysningene, ikke innloggingsleverandøren.
Forskjellen er praktisk, ikke juridisk: Feide er skoleadministrert, slik at skolen kontrollerer hvem som har konto og når tilgangen opphører. En Google-konto er som regel brukerens egen, utenfor skolens kontroll. Derfor bør en skole bruke Feide – men bruker den Google, trengs det like fullt en databehandleravtale.
Helt uten innlogging gjelder standardmodellen: ingen konto for elever, bare prøvekode og fornavn som kallenavn. Da behandler Papertek ingen personopplysninger om elevene.
Dette beskriver anonym bruk (prøvekode og kallenavn, uten innlogging). Ved Feide- eller Google-innlogging er elev- og lærerdata identifiserbare, og et innbrudd vil kunne knytte elevtekst til en navngitt person – boksene under gjelder da ikke. Ved anonym bruk er konsekvensene minimale selv i verste fall.
All data har en utløpsdato. Ingenting lagres for alltid.
Google Cloud, Belgia (europe-west1)
All data lagres innenfor EU. Kryptert både under overføring (HTTPS) og når den ligger i ro. Ingen data sendes utenfor Europa. Krypteringen er ikke ende-til-ende: læreren leser teksten, og Papertek har teknisk tilgang for å drifte tjenesten.
Ved anonym bruk trenger barnet ditt ingen konto – ingen e-post, passord eller personlig informasjon samles inn. Bruker skolen Feide (eller barnet logger inn med Google), lagres navn og e-postadresse fra kontoen.
Barnet bruker kun en prøvekode og fornavn som kallenavn – aldri etternavn. Bare nok til at læreren kjenner dem igjen i klasserommet.
Teksten barnet skriver slettes automatisk etter 30 dager.
Ved anonym bruk kan ingen koble teksten til barnet ditt, selv om de bryter seg inn i databasen. Ved Feide- eller Google-innlogging er teksten knyttet til navnet; vernet er da tilgangsstyring og kort lagringstid.
All data lagres innenfor EU (Google Firestore i Belgia (europe-west1)) og er kryptert under overføring og lagring. Det er ikke ende-til-ende-kryptering – læreren leser teksten, og Papertek har teknisk tilgang for å drifte tjenesten.
Hvis skolen har en databehandleravtale med Papertek, kan barnet logge inn med skolekontoen. Da gjelder avtalen mellom skolen og Papertek for all databehandling.
A simple overview of how Skriveøkt by Papertek protects the privacy of students and teachers.
No technical background needed – everything explained in plain language with diagrams.
Skriveøkt by Papertek is built on one simple rule: collect as little as possible, and delete it as soon as possible.
No account, no email, no password. Just a test code and a nickname.
Text is stored without any link to a real identity. Only the nickname is visible.
Identified by a hashed reference. Their name is never stored on the test.
Step by step – what is stored and what is not.
The code is created by the teacher, e.g. “HAUG-2024”
Use only your given name – never your family name. Just enough for the teacher to identify you in the classroom.
The text is stored as plain text. No formatting data, no device metadata.
Both the answer and the full writing history. All that remains is the participant list – nickname and submission status – until the teacher deletes the test, and at the latest until the annual cleanup in July.
What is NOT stored about the student:
Think of it like a safe deposit box – the bank doesn’t know what’s inside.
One-way hashing means that:
The test only contains the hashed reference – never the teacher’s name or email.
Note: a hash is not the same as encryption. Encrypted text can be unlocked again – a hash cannot. That is precisely why we use hashing here.
You can use Skriveøkt by Papertek with just a teacher key, without logging in with Google. This gives you maximum privacy, but comes with a risk.
No personal data is stored at all. No Google account, no email, nothing that can be traced back to you.
The key is your only link to your tests. If you lose the key, you lose access to all your test data – permanently.
Important: Papertek cannot restore your access if the key is lost. The one-way hashing makes it impossible to find the key from the stored data.
Our recommendation: Keep your key in a safe place. If you want to avoid the risk of losing access, you can log in with Vipps (fully anonymous) or Google – that way you always have a secure link to your tests through your account. The teacher key is most relevant for administrators who want to assign anonymous access codes to teachers.
Vipps is used as a secure gateway – but Papertek stores none of your personal information.
Vipps does NOT see:
Skriveøkt by Papertek does NOT store:
How does it work technically?
Firebase Authentication (the login system) handles the actual Vipps login. During the session, Firebase temporarily knows who you are – this is necessary to verify your identity.
But our database (Firestore), where tests and teacher data are actually stored, never receives name, email, or phone number. Only an anonymous identifier (“sub”) is stored – a random code that cannot be traced back to you.
The difference from Google login: When you log in with Google, Papertek stores your name and email in the database (to display in your profile). With Vipps, nothing that can identify you is stored. Vipps therefore provides the best privacy of all login methods.
Think of it this way: Vipps is like a doorman who checks your ID, but does not tell the building who you are. The building (Papertek) only knows that the doorman let in “person no. 12345” – not that it was you.
Google is used only as a digital doorman – not as a spy.
Google does NOT see:
Skriveøkt by Papertek does NOT share with Google:
Think of it this way: Google is like a security guard at the door who checks your ID. The guard confirms you are who you say you are, but never finds out what you do inside the building. The guard goes home after letting you in.
Most importantly: Test data is linked to the teacher using the hashed reference – not the Google account. Even if someone hacked your Google login, they cannot see your tests without the teacher key.
Google Firestore as database
Skriveøkt by Papertek uses Google Firestore to store test data. Firestore is a cloud database running on Google Cloud infrastructure in Belgium (EU, europe-west1).
Google provides the infrastructure but does not have access to the data content at the application level. Think of it like a landlord who owns the building but is not allowed to open the apartments.
Google processes data in accordance with the EU General Data Protection Regulation (GDPR) and Papertek’s data processing agreement with Google.
For schools, Feide is the primary login: once the school has signed a data processing agreement (DPA) with Papertek, both teachers and students log in with their Feide school account instead of just a test code and nickname. Identifiable personal data is then processed under the DPA, and the anonymous-mode sections above do not fully apply.
What does a DPA mean? The school is the data controller and determines the purpose of data processing. Papertek is the data processor and follows the school’s instructions. All data processing is regulated by the agreement, and the student’s text and writing history are still automatically deleted after 30 days. The name from the school account remains in the participant list until the teacher deletes the test, and at the latest until the annual cleanup in July.
Google login requires a data processing agreement exactly as Feide does.
Students and teachers can also sign in with a Google account. The name and email address are then stored in exactly the same way as with Feide – and the same requirements apply. The obligation follows the personal data, not the login provider.
The difference is practical, not legal: Feide is school-administered, so the school controls who has an account and when access ends. A Google account is usually the user’s own, outside the school’s control. A school should therefore use Feide – but if it uses Google, a data processing agreement is still required.
With no login at all, the default model applies: no account for students, just a test code and given name as nickname. In this case, Papertek does not process any personal data about the students.
This describes anonymous use (test code and nickname, no login). With Feide or Google login, student and teacher data are identifiable, and a breach could link student text to a named person – the boxes below do not apply then. In anonymous use the consequences are minimal even in the worst case.
All data has an expiration date. Nothing is stored forever.
Google Cloud, Belgia (europe-west1)
All data is stored within the EU. Encrypted both in transit (HTTPS) and at rest. No data leaves Europe. The encryption is not end-to-end: the teacher reads the text, and Papertek has technical access in order to operate the service.
In anonymous use your child needs no account – no email, password, or personal information is collected. If the school uses Feide (or the child signs in with Google), the name and email address from the account are stored.
Your child only uses a test code and their given name as nickname – never their family name. Just enough for the teacher to identify them in the classroom.
The text your child writes is automatically deleted after 30 days.
In anonymous use, nobody can link the text to your child, even if they break into the database. With Feide or Google login the text is tied to the name; the protection is then access control and short retention.
All data is stored within the EU (Google Firestore in Belgium (europe-west1)) and is encrypted in transit and at rest. This is not end-to-end encryption – the teacher reads the text, and Papertek has technical access in order to operate the service.
If the school has a data processing agreement with Papertek, your child can log in with their school account. In that case, the agreement between the school and Papertek governs all data processing.