1. Purpose of OWL ECR
OWL ECR is an E-Class Record companion for authorized teachers. It does not replace the official DepEd E-Class Record and is not an official DepEd system. It provides a simpler interface for connecting a teacher- or school-controlled Google Sheets copy, displaying mapped learner rows, encoding classroom records, and syncing selected entries back to that Sheet.
The service may be used to create and manage teacher accounts, control account or subscription access, configure classes and linked spreadsheets, import learner rosters from the connected ECR, encode scores or attendance-related entries, create grade requests, write submitted grades to a linked Grade Sheet, and maintain limited operational and security logs.
2. Teacher and account information
OWL ECR collects or generates the minimum account information reasonably needed to provide and secure the service. Depending on the enabled features, this may include:
- Google account identifier, verified email address, display name, and profile image;
- school, position, registration date, last login date, account role, activation, trial, or subscription status;
- class names, grade and section labels, subjects, advisory designation, Google Spreadsheet links or IDs, Sheet tab names, mapped rows, and synchronization timestamps;
- payment reference, amount, status, provider checkout identifiers, and payment timestamps when paid subscriptions are enabled; and
- session, request, security, error, and synchronization metadata needed to operate and protect the service.
OWL ECR uses Google authorization. Teachers enter their Google or DepEd password only on Google’s sign-in page. OWL ECR does not receive or store that password.
3. Learner information handled by the service
When a teacher synchronizes a class, OWL ECR reads learner names from the mapped INPUT DATA ranges of the linked ECR. A working roster containing learner name, gender grouping, row mapping, and an app-generated roster identifier is retained in that teacher’s isolated OWL ECR workspace so the Record and Grade Request screens can operate.
OWL ECR is designed not to permanently store the following in its MySQL database or local application files:
- Learner Reference Numbers, parent or guardian records, or full copies of ECR workbooks;
- individual quiz, assessment, examination, attendance, or grade values;
- grade submissions or grade-request content; or
- formula results, descriptors, computed grades, or other full ECR contents.
Scores, attendance marks, grade submissions, request logs, and grade-request rosters are written to and read from the teacher’s linked Google Sheets. They are not copied into the OWL ECR application database.
4. Google Sheets access and authorization
Teachers provide the link or identifier of an ECR or Grade Sheet that their signed-in Google account owns or can edit. OWL ECR uses Google OAuth authorization to read the required ranges and write teacher-selected records to mapped cells.
The Google Sheets permission requested by OWL ECR technically allows the service to view, edit, create, and delete spreadsheets accessible to the authorized account. OWL ECR’s application workflow is designed to call only the spreadsheet IDs that the teacher links to the service or that a valid grade-request link identifies. OWL ECR does not make those files public and does not use them for advertising.
Google access and refresh tokens are encrypted at rest using the server’s private application key. They are retained while the Google connection is active and are removed locally when the teacher disconnects the account. Teachers may also revoke access through their Google Account security settings.
Do not enable “Anyone with the link” access for files containing learner records. Keep each Sheet private and share it only with authorized school personnel.
5. Grade request links
An adviser may generate a signed, time-limited grade request link for an authorized subject teacher. The link contains protected request claims such as the target Sheet, subject, term, request identifier, and expiration. Request metadata, the request roster, status, and submitted grades remain in reserved tabs or assigned cells of the adviser’s linked Grade Sheet.
A person holding a valid request link may see the learner names and grade-entry fields needed for that request without receiving access to the full ECR. Current links act as bearer credentials; recipients must not forward or publish them. Links expire after the period selected by the adviser, normally 7, 14, or 30 days.
6. Where information is stored and who may receive it
Teacher account and subscription records may be stored in OWL ECR’s hosting database. Per-teacher profile, class configuration, imported roster, encrypted Google token, and synchronization summary files are stored in an account-isolated server workspace. Learner scores, attendance, grades, and grade-request records are stored in the linked Google Sheets.
Information may be processed by the following parties only as needed for the stated purposes:
- Google: authentication, Google Drive/Sheets hosting, and Sheets API operations under the teacher’s Google account;
- PayMongo: secure checkout, payment status, and email receipts when paid subscriptions are enabled;
- hosting and technical service providers: infrastructure, backup, security, and limited troubleshooting support under appropriate safeguards; and
- authorized authorities or parties: when disclosure is required by law, necessary to protect rights or safety, or validly directed by the school or data controller.
OWL ECR does not sell teacher or learner information and does not disclose learner records to advertisers or public users.
7. Security measures
Security measures include Google OAuth sign-in, encrypted Google tokens, isolated teacher workspaces, administrator-controlled account activation, server-side permission checks, CSRF protection, signed and expiring grade-request tokens, HTTPS requirements for production, secure session cookies, mapped Sheet ranges, and formula-cell protection within the templates.
No online service can guarantee absolute security. Teachers must protect their Google account, review sharing permissions, sign out from shared devices, and immediately report suspected unauthorized access.
8. Retention and deletion
- The remembered-login cookie is valid for up to 30 days unless the teacher signs out or clears it sooner.
- Class configuration and imported roster information remain until the class or teacher workspace is deleted, or until the roster is replaced through synchronization.
- Google tokens remain until disconnection, revocation, account deletion, or another event makes them invalid.
- Account, subscription, payment, and security records are kept only as long as reasonably necessary for service delivery, support, fraud prevention, accounting, dispute handling, or legal compliance.
- Records in Google Sheets remain subject to the teacher’s or school’s own retention and deletion rules.
Disconnecting a Sheet stops future synchronization but does not delete information already present in that Google Sheet. Account deletion requests may be subject to identity verification and legitimate legal, billing, security, or backup-retention requirements.
9. Teacher and school responsibilities
Teachers and schools must have an appropriate authority and lawful basis before processing real learner information through OWL ECR. They are responsible for deciding which records are entered, who receives grade-request links, how long school records are retained, and who may access the connected Google files.
Users should use an official school or DepEd Google account when required, avoid public links, regularly review Drive permissions, share request links only with authorized personnel, and follow DepEd, school, division, records-management, and data-privacy policies.
10. Privacy rights
Subject to the Data Privacy Act of 2012 and applicable exceptions, data subjects may request information about processing and exercise rights of access, correction, objection, erasure or blocking, data portability, complaint, and damages. Requests concerning records inside a school-controlled Google Sheet should normally be directed first to the school, teacher, or designated Data Protection Officer that controls that record.
Requests concerning an OWL ECR teacher account, service record, or deletion may be sent to the contact below. OWL ECR may request reasonable proof of identity and authority before acting on a request involving another person or a learner.
11. Contact
Schools may provide their own Data Protection Officer contact and local retention rules in addition to this notice.
12. Updates to this notice
This notice may be updated when OWL ECR features, providers, legal requirements, or security practices change. Material changes will be posted on this page with a revised update date and, when appropriate, communicated through the service.