Privacy Policy
This policy explains what GradeLogic™ processes and why. GradeLogic™ is local-first: original exam files, rosters, identity mappings, and accepted results are stored in your browser. Cloud AI receives only the assessment content you approve after local PII review, subject to the limitations described below.
What we process
Account data (your Google profile basics), subscription and billing data (via Stripe), and — only when you explicitly authorize cloud processing — the redacted exam artifacts needed for an AI operation. The required payload is sent for synchronous processing and the result is returned in the same request. Sentry receives sanitized backend error events so we can operate and secure the API. Those events can include an error message and stack trace, redacted API route, request method, request ID, a random internal account ID, and runtime metadata, but are configured to exclude names, email addresses, cookies, request or response headers and bodies, query parameters, browser storage, and assessment payloads. This backend monitoring is always active and is not controlled by browser cookie preferences. If you separately allow optional Diagnostics, Sentry also receives a random internal account ID together with technical browser errors, normalized page routes, workflow phase and outcome, request timing, instructor-attended time, and performance measurements. The browser SDK is configured not to collect names, email addresses, exam or task identifiers, cookies, form interactions, request or response bodies, request or response headers beyond the browser user-agent received at the network layer, or URL query parameters.
Local-first architecture
Student identities, rosters, original exam files, identity mappings, and accepted grading records remain in your browser's storage (IndexedDB). Before any cloud processing you review a local preview of redacted or excluded regions and explicitly authorize the transfer. The server verifies that the request is bound to the instructor-confirmed redaction manifest and records a fingerprint of the submitted payload, but it cannot independently determine whether every identity or other item of PII was found and removed. Unexpected PII can therefore be transmitted if it remains in an approved answer area. We do not maintain a permanent repository of assessment content.
See our FERPA Support Overview and Privacy & security page for how this supports your education-privacy obligations.
How we use data
To authenticate you, run the AI operations you request, meter Grading Credits, provide support, investigate backend service errors and API performance, and — only after optional Diagnostics consent — measure workflow reliability, operation duration and instructor-attended time. We do not use assessment content for advertising or indefinite analytics, and we do not sell personal data. See our Responsible AI Policy for how AI is applied.
Processors we use
We rely on a small set of subprocessors, each processing data only to provide its function. The current list is maintained on our Subprocessor List.
Retention
GradeLogic does not create a persistent server-side copy of assessment payloads. Redacted payloads are processed only to complete the requested operation and return its result. The result of an operation is retained for approximately seven days so that a repeated request replays the stored result instead of re-running and re-charging it, and is then deleted. A record is not kept indefinitely merely because it appears in a ledger or audit table. Where applicable law requires retention, we keep only the qualifying record for the required period, restrict it from ordinary use, and delete or anonymize it when that period ends.
Your account itself is kept for as long as you have one, and for 36 months after your last sign-in if you stop using it. After that we erase it the same way we would if you had asked us to, keeping only the records described below that a law requires us to keep. We email you about 30 days before that happens, and signing in at any point starts the 36 months again — that is all it takes to keep the account. This is the storage limit Art. 5(1)(e) GDPR requires us to set and Art. 13(2)(a) requires us to tell you about.
Cancelling your subscription is not the same as deleting your account and does not start that clock over: your account remains, and you can subscribe again. Deleting your account is a separate action you can take at any time from Settings, and it is immediate.
Sanitized backend error events and optional browser diagnostic events are retained for the period configured in GradeLogic's Sentry projects and then deleted. Those deployed retention settings must be verified and stated here before this draft policy takes effect.
| Record | Kept for | Why |
|---|---|---|
| Your account, once unused | 36 months | Measured from your last sign-in, so signing in resets it. We email you about 30 days before the account is erased. |
| Result of an AI operation | About 7 days | So a repeated request replays the stored result instead of re-running and re-charging it. |
| Anti-abuse and rate-limit counters | 30 days | Hashed values only. Long enough to investigate a burst of activity after the fact. |
| Operation metering and redaction attestations | 4 years | The period in which an ordinary civil claim can still be brought (§§ 195, 199 BGB), which is what these records would answer. |
| Invoices and payment records | 8 years | § 14b UStG and § 147 Abs. 3 AO. Our payment provider is the record-holder. |
| Accounting ledger | 10 years | § 147 Abs. 1 AO and § 257 Abs. 1 HGB. |
There are two different things you may want, and they are separate. To stop paying, cancel the subscription — in the billing portal our payment provider hosts, or from the cancellation button in our footer, which does not require you to sign in. That ends the subscription at the end of the period you have paid for and leaves your account and your data alone. What follows describes the other one: deleting the account.
Deleting your account cancels the subscription, revokes remaining credits, ends every session, and erases the identity behind the account: your name, email address, profile picture, the identifier your Google sign-in used, and the contact and registered-address details given when the contract was formed. The sign-in, rate-limit, order-confirmation, waiting-list and cached result records are deleted outright. Where a record must survive — the accounting and payment history above, and the evidence of how the contract was concluded — it is kept without the personal details it does not need, is excluded from ordinary use (Art. 18 GDPR, § 35 BDSG), and is deleted when its period ends. The country you contracted from is deliberately kept, because it is what determines where your assessment content may be processed.
One thing deletion does not remove: if you subscribed to our email updates, that is a separate relationship on a separate legal basis, and deleting the account unsubscribes it rather than erasing it. The address stays on our suppression list, which is what stops us mailing it again — including where it previously bounced or was reported as spam. Use the unsubscribe link, or write to privacy@gradelogic.ai, if you want that record removed as well.
Two things deletion deliberately does not do. It does not remove the exams, rosters and results held in your browser — those are your own working records, and they are cleared separately from Settings, which you should do before closing the account if you want them gone. And it does not remove a limited record where a specific law requires us to keep it, for example a qualifying invoice or accounting document.
Your rights
Subject to applicable law, you may request access, correction, portability, or deletion of your account data. Two of those you can exercise yourself, without asking us: Settings › Your data downloads everything we hold about you, from both our servers and this browser, and Settings › Danger Zone closes and erases the account. What deletion covers, and the narrow set of records a specific law requires us to keep, are described under Retention above; that exception does not justify keeping unrelated profile or service data. For anything else, write to us at the address below — we answer within one month (Art. 12(3) GDPR). See our GDPR Support Overview for details.
Security & transfers
Transport is encrypted (HTTPS).
Where your assessment content may be processed is an account setting, under Settings › AI Configuration. It has two parts: whether processing is restricted to providers in the European Economic Area, and whether those providers may retain what they are sent. The default for every account is the strict combination — EEA-restricted, no retention.
Not every account may change it, and the rule is stricter than "EEA accounts cannot". You are held to the strict setting if you contracted from, or are billed in, an EEA country; or if we cannot establish which country your account belongs to at all, which is the case until a contract records one; or if we have placed your account on a managed configuration. Only an account we can positively place outside the EEA may widen the setting. Where the setting is fixed, the page says which of these applies.
A managed configuration is one we set rather than you. We use it to hold an account to a particular processing arrangement; depending on the arrangement it can be stricter or less strict than the default, including allowing a provider to retain content. If your account is on one, the page says so, and you can ask us what it is and why.
The setting is enforced on our servers, not in your browser: each option is served by a separate processing credential whose limits are configured with our AI gateway, and a request that cannot be served within those limits fails rather than falling back to a credential with weaker ones.
One limit of the EEA option is worth stating plainly, because it is easy to read as more than it is. It restricts the model provider that processes your content. Every request still passes through our AI gateway, which operates from the United States, so choosing the EEA option does not mean your content never leaves the EEA — it means the provider that processes it is one we route to under that restriction. The categories of recipient, and the transfer position, are set out on our Subprocessor List; we name the individual providers to institutional customers under our Data Processing Agreement. For more, see our Security Overview.
Contact
Email: privacy@gradelogic.ai
Subject line: Privacy Policy inquiry