Cookie Policy
GradeLogic™ uses the minimum storage needed to run, plus optional functional preferences and diagnostics only when you allow them.
Essential cookies
The following cookies may be used. The three essential gl_* cookies listed here are set by GradeLogic™; the Cloudflare row is conditional on how Turnstile handles a particular challenge.
| Cookie | Provider / type | Purpose | Lifetime | Category |
|---|---|---|---|---|
gl_session | GradeLogic™ / first-party HTTP cookie | Keeps you signed in. | 30 days | Strictly necessary |
gl_oauth | GradeLogic™ / first-party HTTP cookie | Protects the Google sign-in exchange against cross-site request forgery. Set when sign-in starts and deleted as soon as it completes. | Up to 10 minutes | Strictly necessary |
gl_signup | GradeLogic™ / first-party HTTP cookie | Maintains your temporary signup intent after Google verification while you provide account details, accept the required legal terms, and complete payment. | Up to 24 hours | Strictly necessary |
cf_clearance (conditional) | Cloudflare / third-party HTTP cookie | May record that a Turnstile challenge was passed when Cloudflare pre-clearance is enabled. Ordinary Turnstile operation may instead use other transient, provider-controlled browser storage. | Cloudflare-configured challenge-passage duration | Strictly necessary anti-abuse control |
gl_session and gl_oauth are required to sign in and stay signed in. gl_signup is required only while completing an approved signup. Turnstile storage is required only when you use a public form protected by that anti-abuse check.
Functional cookies
Functional cookies are optional and remain disabled unless you allow the Functional category.
| Cookie | Provider / type | Purpose | Lifetime | Category |
|---|---|---|---|---|
gl_locale | GradeLogic™ / first-party JavaScript cookie | Remembers a language you explicitly select and opens translated public pages in that language on future visits. | One year | Functional / optional |
Third-party services that run in your browser
The services below can receive a connection from your browser. That means the provider receives the IP address and browser user-agent needed to deliver the connection. Turnstile is loaded only on the public forms it protects. The Sentry browser SDK is activated only after you allow optional Diagnostics.
- Cloudflare Turnstile — the anti-bot check on our waitlist and newsletter forms. The widget loads from
challenges.cloudflare.com, and Turnstile may set its own strictly-necessary cookies or storage entries to operate the challenge or remember that it was passed. The cookie table identifies the documented pre-clearance cookie; the exact deployed behavior must be verified whenever the Turnstile configuration changes. - Sentry browser SDK — optional browser error and performance diagnostics. When enabled, it can receive error messages and stack traces, the current page route, browser and device metadata, normalized workflow phase and outcome, request timing, instructor-attended time, and performance measurements. A random internal account ID is attached so repeated failures can be correlated without sending your name or email address. GradeLogic configures the SDK not to collect exam or task identifiers, cookies, form interactions, request or response bodies, request or response headers beyond the browser user-agent described above, or URL query parameters. It does not set a browser cookie in the current configuration and does not intentionally attach exam files, roster records, answer images, prompts, or model output. Sentry is disabled until you allow Diagnostics and is closed when you withdraw that choice.
GradeLogic also uses Sentry on its backend to identify API failures. Backend monitoring runs on the server, does not set a browser cookie, and is not controlled by the cookie dialog; it uses random internal user and billing-account IDs for correlation, and is configured to exclude names, email addresses, exam identifiers, cookies, headers, bodies, query parameters, browser storage, and assessment payloads.
Everything else GradeLogic™ runs in your browser is served from our own domain. The text-recognition engine that reads printed text on your exam pages — used by page splitting, PII detection and zone detection — runs on your device and is delivered by us, not by a third-party CDN. That matters: it reads your exam pages before any redaction is applied, so it is deliberately kept off other companies' infrastructure.
Local storage, IndexedDB & Cache Storage
| Storage | Purpose | Duration |
|---|---|---|
gl-cookie-consent in local storage | Records your necessary-storage, optional-functional, and optional-diagnostics choices, the notice version, and when you decided. | Until you clear site data |
| GradeLogic™ IndexedDB | Stores exams, source files, rosters, zones, settings, grading records, and notifications locally. | Until you delete it, or you remove the site's data |
| IndexedDB / Cache Storage model assets | Caches on-device OCR software and model files so they do not need to be downloaded for every use. | Until browser eviction or site-data removal |
| Small interface preferences in local or session storage | Remembers display state or a short-lived navigation continuation. | Until cleared, or until the browser session ends for session storage |
Browser storage is not a server-side repository. Clearing site data removes it, and so does the in-app "Delete browser data" action. That is deliberately separate from deleting your account: your exams, rosters and results are your own working records, and closing an account does not destroy them. If you want both gone, clear the browser data first — once the account is closed you can no longer reach the button. See our Privacy Policy for how local-first storage works.
No advertising or cross-site tracking
We do not use third-party advertising, cross-site tracking cookies, audience measurement, or behavioural profiling. Sentry receives sanitized backend error events to identify API failures and, if you allow Diagnostics, technical browser error and performance events to investigate browser reliability. GradeLogic does not use that data to build advertising profiles or analyze assessment content.
Managing cookies
You can clear cookies and site data via your browser settings; doing so will sign you out and may remove locally-stored exam data. You can also revisit the cookie notice anytime via "Cookie preferences" in the footer, or "Cookie preferences" in the account menu. Withdrawing Functional deletes the language cookie, and withdrawing Diagnostics stops future Sentry events from the browser. It does not disable server-side backend error monitoring, which does not use browser cookies.