FERPA Support Overview
How GradeLogic™ helps institutions meet their obligations under the U.S. Family Educational Rights and Privacy Act (FERPA). GradeLogic™ is built privacy-first to support FERPA compliance — it is not a certification, and compliance is ultimately determined by your institution.
Our role
When an institution uses GradeLogic™, we act as a service provider processing data under the institution's direction. FERPA's "school official" exception lets an institution share education records with a contractor that performs an institutional function under its direct control and use limitations. We make that relationship explicit through a signed Data Processing Agreement.
How GradeLogic™ supports FERPA
- Local-first by default: rosters, student identities, original exams, and accepted results stay in the instructor's browser and are not sent to us.
- PII review & redaction: identity regions are marked and redacted (or whole pages excluded) locally, and the instructor authorizes the transfer before any cloud processing. An attestation gate blocks cloud operations until that review is confirmed.
- Data minimization: the client minimizes cloud payloads to instructor-approved, client-redacted assessment content. The server verifies the instructor-confirmed attestation and binds it to the run, but it cannot independently determine whether every unexpected identifier was detected or removed from the approved content.
- No permanent repository: approved artifacts are processed only for the operation you authorized and are deleted once the result is returned. The result itself is held for about seven days so a repeated request replays it instead of re-running and re-charging, and is then deleted. We do not retain assessment content for analytics or any other purpose.
- Provider retention: by default the AI providers we route to are barred from keeping your content, and most accounts cannot change that — only an account we can positively place outside the EEA may lift the restriction, in exchange for a wider set of models. Institutions relying on this clause should leave it in place and confirm the setting with the instructor holding the account. Two cases are worth knowing: we may place an account on a managed configuration that we determine rather than the instructor, and such a configuration can permit retention; and the restriction governs the model provider, not the US-based gateway every request passes through. See Settings › AI Configuration and our Subprocessor List.
- Use limitation: we use data only to provide the service, never for advertising.
Your responsibilities
The instructor and institution remain responsible for FERPA compliance, including: reviewing the redaction preview and catching any PII automated detection may miss (for example, a name handwritten inside an answer); verifying AI-generated grades; and executing a DPA where required by institutional policy.
What this is not
There is no official "FERPA certification" for software. This page describes how our design supports your compliance; it is not a legal guarantee. Pair it with the Data Processing Agreement, Privacy Policy, and Security Overview.
Contact
FERPA and procurement questions: privacy@gradelogic.ai.