GradeAIby Hurosoft
Back to GradeAI
Privacy policy

Data should serve the classroom, not exploit it.

This policy explains what GradeAI processes, why it is needed, which providers support the service, and how teachers can access or delete their data.

Last updated 30 July 2026

1. Scope and responsibility

GradeAI is an invite-only teacher tool operated as a Hurosoft product. Teachers and institutions decide which classroom records and student work to upload. They must have authority to use that information and should provide only what is necessary for grading.

GradeAI processes uploaded information to provide authentication, classroom management, Google sync, storage, AI-assisted draft grading, teacher review, analytics, export, support, security, and deletion functions.

2. Information we process

  • Account data: name, email, avatar, authentication identifier, organization name, role, signup time, and recent activity.
  • Classroom data: class, subject, grade, student name, roll number, email, and optional parent phone number.
  • Assessment data: assignments, rubrics, instructions, reference answers, submissions, uploaded files, grades, feedback, teacher overrides, and AI chat history.
  • Google data: connected email, selected Drive folders, spreadsheet and file identifiers, imported responses, and encrypted OAuth credentials.
  • Operational data: grading usage, audit records, security events, failed jobs, browser/device information, and privacy-filtered error reports.

3. Google user data

When a teacher connects Google, GradeAI requests read-only access to Google Drive and Sheets plus the account email. GradeAI uses this access only to show folders and spreadsheets selected for the teacher workflow, import requested Google Form or Sheet responses, retrieve teacher-authorized submission files, and identify the connected account.

GradeAI does not sell Google user data, use it for advertising, transfer it to data brokers, or use it for unrelated profiling. Access is limited to providing and securing the user-facing features the teacher requests. GradeAI's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Google access and refresh tokens are encrypted at rest when stored. Teachers can disconnect Google from GradeAI settings or revoke access from their Google Account. Invalid or revoked credentials are removed from GradeAI.

4. AI-assisted grading

GradeAI sends the rubric, teacher instructions, reference material, and relevant submission content to the configured AI provider to generate a proposed score and feedback. AI output can be incomplete, inconsistent, or wrong. The teacher remains the final decision-maker and must review every grade before using or sharing it.

GradeAI must not be the sole basis for high-stakes educational, disciplinary, admission, employment, legal, medical, credit, or insurance decisions.

5. Service providers

GradeAI uses Clerk for authentication, Neon for database hosting, Anthropic for AI grading, Cloudflare R2 for private file storage, Google APIs for teacher-requested imports, Sentry for privacy-filtered error monitoring, and Railway for application hosting. Each receives only the data needed for its function.

6. Security and retention

Controls include server-side tenant authorization, strict validation, encrypted Google tokens, private file references, short-lived file access, upload size and signature checks, security headers, rate limiting, audit records, and telemetry filtering. No internet service can guarantee absolute security.

Active classroom and assessment data remains available until the teacher deletes it or wipes the account. Supported deletion paths remove primary database records and managed submission objects. Provider backups, security records, legal requirements, or failed cleanup retries may delay complete removal for a limited period.

7. Student and children's data

Teachers and institutions must obtain any school, student, parent, or guardian authorization required for the data they submit. The beta is intended for invited educators testing non-critical workflows. Do not upload unnecessary identifiers or use GradeAI for covert monitoring.

8. Access, correction, export, deletion, and grievances

Users may request access, correction, export, deletion, withdrawal of Google access, or privacy review. GradeAI may verify identity and authority before disclosing or changing student data. Account settings provide data-wipe and Google-disconnect controls; additional requests can be sent through the contact below.

9. Changes

Material changes will be dated on this page. If a change meaningfully expands how personal data is used, GradeAI will provide additional notice or seek permission where required.

Questions or requests

Include your account email and request type. Never email passwords, API keys, OAuth tokens, or student work.

Use the support address shown on the GradeAI Google consent screen.