Privacy Policy
Effective date: 2 June 2026 · Last updated: 2 June 2026 · Jurisdiction: Quebec, Canada
1. Who we are
GradeAid is an AI-assisted grading tool for teachers. A teacher creates an account, provides a rubric (answer key or scoring guide), and submits student work (typed answers, PDFs, or photos of handwriting). GradeAid transcribes and grades that work with the help of an AI model and lets the teacher review and override every result.
For any privacy question or request (access, correction, or deletion of data), contact our privacy contact: aidenbenzur12@gmail.com. This is also the contact for the person responsible for the protection of personal information under Quebec's Act respecting the protection of personal information in the private sector(the “Private Sector Act,” as modernized by Law 25).
2. The information we handle
(a) Teacher account information. When you register and use GradeAid, we collect and store your name, email address, school (optional), and a hashed password (a bcrypt hash — never your plaintext password).
(b) Student data entered or uploaded by teachers. To grade work, teachers enter or upload information about their students, which may include:
- student names and any identifier the teacher chooses to enter;
- submitted work — typed answers, uploaded PDFs, and photos of handwritten work;
- grades, scores, criterion-level breakdowns, and feedback generated for that work, including any teacher overrides and comments.
This data may include the personal information of minors. It is provided to GradeAid by the teacher or school, not collected by us directly from students. See sections 5 and 7.
(c) Payment information. Paid access is billed through Stripe. Stripe collects and processes your payment details (such as card number) directly. GradeAid does not receive or store your full card details. We store only a Stripe customer/subscription reference and your access status.
(d) Operational data. Our hosting providers process limited technical data needed to run and secure the service (for example, IP addresses and request logs used for rate limiting, abuse prevention, and debugging).
3. How we use the information
We use the information only to provide and operate the grading service, specifically to:
- authenticate you and maintain your account;
- transcribe handwritten or uploaded work into text for grading;
- grade student work against your rubric and generate scores and feedback;
- save your classes, students, grades, and overrides so you can review them;
- process your subscription and manage access;
- secure the service (rate limiting, abuse prevention) and fix problems.
We do not sell personal information, and we do not use student work for advertising.
4. How we store and protect it
- In transit: all traffic is encrypted over HTTPS/TLS.
- At rest: data is stored in a managed PostgreSQL database hosted in Canada (Supabase,
ca-central-1region). - Access control: the database enforces row-level security (RLS), and the application restricts each teacher to their own data. Passwords are stored only as bcrypt hashes.
- Payment data: card details are held by Stripe (a PCI-DSS compliant processor), not by us.
No system is perfectly secure, and this draft does not promise absolute security. We take reasonable measures appropriate to the sensitivity of the data.
5. Our roles: teacher/school is the controller, GradeAid is the processor
For the student data described in section 2(b):
- the teacher and/or their school is the controller — they decide what student information to enter and why;
- GradeAid acts as a processor (service provider), handling that data on the teacher's/school's behalf and instructions to deliver grading;
- the teacher is responsible for having the authority and lawful basis to enter student data into GradeAid — including any consent, school authorization, or notice required by their institution and by law.
For the teacher account data in section 2(a) and payment data in section 2(c), GradeAid is the controller.
6. Third-party processors
We use the following sub-processors to run GradeAid. Each receives only the data needed for its function. Some operate outside Canada (notably in the United States), which means student work and other data may be processed outside Canada.
| Processor | Role | What it receives | Location |
|---|---|---|---|
| Google (Gemini API) | AI transcription & grading | Student work (typed text, PDF/image content) and rubric text; the model's generated scores/feedback | Outside Canada (US / global) |
| Stripe | Payment processing | Your name, email, and payment/card details entered at checkout | Outside Canada (US / global) |
| Supabase | Managed database hosting | All stored account, student, grade, and feedback data | Canada (ca-central-1) |
| Railway | Backend application hosting | Data in transit while it is being graded (receives uploads, calls the AI) | Outside Canada (US) |
| Vercel | Frontend hosting / delivery | Serves the web app and routes requests; processes request/technical data | Outside Canada (US / global edge) |
AI processing by Google (important)
When you grade work, the student's submitted work is sent to Google's Gemini API to be transcribed and/or scored. Whether Google may use that content to improve its own models depends on the Gemini API billing tier in use:
- On the paid tier (billing enabled), Google states it does not use prompts or responses to train or improve its models, and processes them as a data processor under its Data Processing Addendum; it retains limited logs only for abuse prevention and legal compliance.
- On the free / unpaid tier, Google states it uses submitted content to improve its products and that human reviewers may read it — and explicitly warns not to submit confidential or personal information.
7. Children's / minors' information
GradeAid is a tool for teachers, not for children. We do not knowingly collect personal information directly from children, and children do not interact with GradeAid. Where a teacher enters work or information about students who are minors, the teacher and their school are responsible for the lawful basisfor doing so — including any required consent, authorization, or notice. If you believe a child's information has been entered without proper authority, contact us at aidenbenzur12@gmail.com and we will work with the responsible teacher/school to address it.
8. How long we keep data (retention)
- Teacher accounts and the student data linked to them are kept for as long as the account is active, so teachers can review past grades.
- When you (or your school) ask us to delete an account or specific student data, we delete it from the active database within a reasonable period, subject to short-lived backups that age out.
- Payment records held by Stripe are retained per Stripe's policies and applicable financial-record requirements.
- We do not retain student work longer than needed to provide the service and meet legal obligations.
(Specific retention periods are to be finalized with legal review.)
9. Your rights and how to exercise them
Under Quebec's Law 25 (Private Sector Act) and Canada's PIPEDA, you have the right to:
- access the personal information we hold about you;
- request correction of inaccurate information;
- request deletion of your account and associated data;
- ask questions about how your information is handled, and raise a complaint.
To exercise any of these, email aidenbenzur12@gmail.com. We will respond within the timeframes required by applicable law. Because the teacher/school is the controller of student data (section 5), requests about a specific student's information should generally be directed to, or made through, the responsible teacher/school; we will assist the controller in responding.
You may also contact the Commission d'accès à l'information du Québec (CAI) or the Office of the Privacy Commissioner of Canada (OPC) if you have a complaint.
10. Changes to this policy
This policy is a draft and may change— both as the product evolves and following legal review. When we make material changes we will update the “Last updated” date above and, where appropriate, notify account holders.
11. Contact
Privacy contact: aidenbenzur12@gmail.com
GradeAid · Quebec, Canada