Privacy Policy
Last updated 29 September 2026
Drill Room is a private coaching tool for students of Watkins Debate. It is not a public service and has no advertising, no analytics, and no third-party trackers. This page describes exactly what it stores and why.
Who runs this
Drill Room is operated by Nathaniel Watkins (Watkins Debate), an individual debate coach. Questions about anything on this page go to debate@nwatkins.org.
Who can use it
Anyone can create an account, either with Google or with an email address and password. Creating one adds your name and email to your coach's roster and emails your coach to let them know. You see nothing until your coach approves the account. Your coach can close an account, and can stop accepting new ones.
What is collected
Your Google account
When you press Sign in with Google, Google gives this site a signed token containing your email address, your name, and whether the address is verified. That token is how the site knows who you are. It expires about an hour after it is issued.
The site requests no other Google permissions. It cannot read your Gmail, your Drive, your contacts, or your calendar.
If you sign up with email and password
The site sends a one-time code to your address to confirm it is yours. It stores your name, your email, and a salted, one-way hash of your password. Your password itself is never stored and your coach cannot see it. After you sign in, the site keeps a random sign-in token in your browser that stops working after six hours or when you sign out.
What you submit
Drill requests and file requests you send are recorded: the text you typed, the deadline you chose, any document link you pasted, and your name and email. They go to a private Google Sheet that only your coach can open.
Your drill bank
The same private Sheet holds your credit balance — how many custom drills you have been granted, how many you have used, and when you last used one.
Stored in your browser only
Which drills you have ticked off, any drills you add for yourself, your current sign-in token, and a cached copy of your name for the greeting. These live in your browser's local storage on that device. They are never uploaded, your coach cannot see them, and clearing your browser data erases them.
Where it is stored
In a private Google Sheet owned by your coach, and in the Google Apps Script attached to it. Nobody else is given access to that Sheet. The site has no database or server of its own, and the pages themselves are static files hosted on GitHub Pages.
Who it is shared with
Nobody. Your information is not sold, rented, published, or shared with any third party. It is not used for advertising or profiling, and it is not used to train any machine-learning model.
Three Google services are involved because the site is built on them:
- Google Sign-In verifies who you are.
- Google Sheets / Apps Script stores the roster, credits, and requests.
- Google Calendar handles session booking. When you book a time, that booking and the email address you give go to Google Calendar under Google's privacy policy, exactly as any calendar invitation would.
Information may also be disclosed if the law requires it.
Cookies
This site sets no cookies of its own. Google's sign-in script may set cookies on Google's own domains as part of signing you in.
How long it is kept
Roster entries, credit balances, and past requests are kept for as long as you are coached, and for a reasonable period afterwards as a record of work done. Google sign-in tokens expire in about an hour, email sign-in tokens after six hours, and both are discarded when you sign out.
Your choices
- See what is held about you. Email your coach and ask.
- Correct it. Same — your coach edits the Sheet directly.
- Delete it. Ask and your roster row, your login, and your requests will be removed. This also ends your access.
- Revoke Google access at any time from your Google account permissions page.
- Clear local data by clearing site data for this domain in your browser. This erases your drill checkmarks.
Students under 18
Many students here are minors. No more information is collected from a student under 18 than from anyone else — a name, a school-age email address, and coursework they choose to submit. A parent or guardian may email debate@nwatkins.org to see what is held about their child or to have it deleted, and it will be removed on request.
Security
Every request to the server carries your sign-in token: a Google token, which the server checks with Google, or a random token the server issued when you signed in with your password. It answers only for the account the token belongs to, so one student cannot read another's drills, balance, or requests. Passwords are stored only as salted hashes, and repeated wrong guesses are slowed down.
Changes
If this policy changes materially, the date at the top will change and students will be told by email.