1. Scope and responsibility
GradeAI is an invite-only teacher tool operated as a Hurosoft product. Teachers and institutions decide which classroom records and student work to upload. They must have authority to use that information and should provide only what is necessary for grading.
GradeAI processes uploaded information to provide authentication, classroom management, Google sync, storage, AI-assisted draft grading, teacher review, analytics, export, support, security, and deletion functions.
2. Information we process
- Account data: name, email, avatar, authentication identifier, organization name, role, signup time, and recent activity.
- Classroom data: class, subject, grade, student name, roll number, email, and optional parent phone number.
- Assessment data: assignments, rubrics, instructions, reference answers, submissions, uploaded files, grades, feedback, teacher overrides, and AI chat history.
- Google data: connected email, selected Drive folders, spreadsheet and file identifiers, imported responses, and encrypted OAuth credentials.
- Operational data: grading usage, audit records, security events, failed jobs, browser/device information, and privacy-filtered error reports.
3. Google user data
When a teacher connects Google, GradeAI requests read-only access to Google Drive and Sheets plus the account email. GradeAI uses this access only to show folders and spreadsheets selected for the teacher workflow, import requested Google Form or Sheet responses, retrieve teacher-authorized submission files, and identify the connected account.
GradeAI does not sell Google user data, use it for advertising, transfer it to data brokers, or use it for unrelated profiling. Access is limited to providing and securing the user-facing features the teacher requests. GradeAI's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Google access and refresh tokens are encrypted at rest when stored. Teachers can disconnect Google from GradeAI settings or revoke access from their Google Account. Invalid or revoked credentials are removed from GradeAI.
4. AI-assisted grading
GradeAI sends the rubric, teacher instructions, reference material, and relevant submission content to the configured AI provider to generate a proposed score and feedback. AI output can be incomplete, inconsistent, or wrong. The teacher remains the final decision-maker and must review every grade before using or sharing it.
GradeAI must not be the sole basis for high-stakes educational, disciplinary, admission, employment, legal, medical, credit, or insurance decisions.
5. Service providers
GradeAI uses Clerk for authentication, Neon for database hosting, Anthropic for AI grading, Cloudflare R2 for private file storage, Google APIs for teacher-requested imports, Sentry for privacy-filtered error monitoring, and Railway for application hosting. Each receives only the data needed for its function.
6. Security and retention
Controls include server-side tenant authorization, strict validation, encrypted Google tokens, private file references, short-lived file access, upload size and signature checks, security headers, rate limiting, audit records, and telemetry filtering. No internet service can guarantee absolute security.
Active classroom and assessment data remains available until the teacher deletes it or wipes the account. Supported deletion paths remove primary database records and managed submission objects. Provider backups, security records, legal requirements, or failed cleanup retries may delay complete removal for a limited period.
7. Student and children's data
Teachers and institutions must obtain any school, student, parent, or guardian authorization required for the data they submit. The beta is intended for invited educators testing non-critical workflows. Do not upload unnecessary identifiers or use GradeAI for covert monitoring.
8. Access, correction, export, deletion, and grievances
Users may request access, correction, export, deletion, withdrawal of Google access, or privacy review. GradeAI may verify identity and authority before disclosing or changing student data. Account settings provide data-wipe and Google-disconnect controls; additional requests can be sent through the contact below.
9. Changes
Material changes will be dated on this page. If a change meaningfully expands how personal data is used, GradeAI will provide additional notice or seek permission where required.