Confidentiality that depends on everyone remembering to be careful fails on a bad week. So the separation here is structural: fields a specialist cannot see, messages that can only be relayed, access that expires and is logged.
Every field we hold against every role that touches an order. Where a cell says “no”, there is no view that would show it.
| Data we hold | Academic manager | Subject specialist | Second reader | Quality auditor | Billing and engineering |
|---|---|---|---|---|---|
| Your name | yes | no | no | no | billing only |
| Your email address | yes | no | no | no | billing only |
| Your institution | only if you say it | no | no | no | no |
| The brief and instructions | yes | yes, redacted | yes, redacted | yes, redacted | no |
| Files you upload | yes | yes, metadata stripped | yes, metadata stripped | yes, metadata stripped | no |
| Messages with the desk | yes | relayed only | no | no | only the ticket you raised |
| Payment details | last 4 digits only | no | no | no | processor reference only |
| The delivered work | yes | their own draft | yes | yes | no |
One manager owns your order end to end: reading the brief, quoting it, routing questions and releasing the files. This is the role confidentiality is built around, because someone has to be able to talk to you about your own order.
The specialist receives the brief, the rubric and the deadline — nothing that identifies you. Questions travel through the desk in both directions, and uploads are stripped of document metadata before they are passed on.
The second read is blind in both directions — the reader does not know who wrote the draft or who commissioned it. That is what makes the verdict worth having.
Auditors score work against the published scorecard without knowing the writer, the reviewer, the manager or you. An auditor who recognises a piece declares it and it is reassigned.
Finance sees what it needs to issue a receipt or process a refund. Engineering has no routine access at all — a support ticket you raise can grant it temporarily, with the reason recorded and the access expiring.
Each control is stated with how it fails — because a control whose failure mode nobody has thought about is a hope.
Your brief is separated from your contact record the moment it arrives, and linked only by an internal reference. There is no view that joins them for a specialist.
a mis-set permission shows nothing rather than everything
Author names, comment history, tracked changes and file properties are removed before a file reaches anyone writing or reviewing.
a file that cannot be cleaned is not forwarded
There is no channel between you and the specialist. Questions pass through the desk, which is also why nobody can be talked into an exception.
no route exists to leak through, even willingly
Every view of a client record is recorded with who, when and why. The log is reviewed monthly and unexplained access is treated as an incident.
access without a reason is visible after the fact
Valid legal compulsion is the only route, and it is bounded in writing.
The order below is deliberate: records are frozen before anyone establishes whether a concern is real.
Not through our systems — there is no view that joins your identity to your brief for that role, and messages are relayed rather than direct. The one thing we cannot control is what you put in the brief itself: if you write your name, student number or module code into the instructions, a specialist will see it. Managers redact what they spot, but leaving those details out is the reliable route.
They get a reply refusing to confirm or deny that any record exists, and nothing else. We do not treat an institutional letterhead as authority, and we do not quietly comply while telling you we would not.
Yes, for twelve months by default, so you can download it again and so we can answer a question about it. Ask us to delete it sooner and it goes within thirty days. Anonymised order records are kept longer where accounting rules require it — the retention table in the privacy policy states each period.
No. Card details go directly to the payment processor; we hold a token, the last four digits and the amount. Nobody here, at any level, can see a full card number.
Yes. We need a working email address and a payment method; a name you use consistently is enough for everything else. We do not verify identity, and we do not want documents that would let us.
Send it to the address in the legal hub and it is handled by the managing editor within thirty days. You get a copy of what we hold, per category, or confirmation of deletion — and asking does not affect an order in progress.
Which is why we ask for as little as the work requires, and delete what we no longer need on a schedule rather than on request.