Who we are
SuperGrader is an AI-assisted grading tool for teachers. You photograph or upload student work, we help you grade it, and you keep the results in your account. This policy explains exactly what we collect, where it goes, who else touches it, and how long we keep it.
It is written for the teacher who holds the account — the person we have a direct relationship with.
What we collect
Account information
- Your name and email address, from the account you create or from Google if you sign in that way.
- Your profile picture, if your Google account has one.
- Your settings and preferences, such as language and default maximum score.
Student work you upload
- Images of student papers, answer keys and rubrics that you photograph or upload.
- Student names. These are read from the paper by an AI model and stored alongside the grade, so results are labelled with the right student. They are stored as text in our database, not only as pixels in an image.
- Grading results: scores, per-question marks, feedback text and confidence values.
- Timing data used to show you how much time grading saved.
Billing and usage
- A count of papers you have graded this month, used to apply the free allowance.
- Subscription status. Card details are handled entirely by Stripe and never reach our servers.
- An activity log of actions taken in your account, used for support and troubleshooting.
We do not use advertising trackers, and we do not sell any data to anyone.
Who else processes your data
Running this service means sending data to a small number of providers. Each is listed here with what it receives:
- AI grading providers. Images of student work, your answer key and your rubric are sent to a third-party AI gateway (kie.ai) and the models it routes to, in order to read and grade the paper. This is the core of how the product works — student work leaves our servers to be processed.
- Cloudflare R2. Stores uploaded images. The storage bucket is private; images are served only through short-lived links generated for the signed-in owner.
- Neon. Hosts our PostgreSQL database, which holds accounts, grades, student names and settings.
- WorkOS. Handles sign-in, passwords and Google authentication.
- Stripe. Processes subscription payments.
- Resend. Sends account emails such as password resets.
- Sentry. Receives error reports when something breaks, which can include technical context about the request that failed.
How long we keep it
Nothing is deleted on a timer. Your assessments, grades, student names and uploaded images stay in your account until you delete them or delete your account. We would rather state this plainly than promise an automatic expiry we do not perform.
- Delete a single grade, assessment or folder from the app, and its database rows are removed.
- Delete your account from Settings, and we remove all of your stored images from object storage and every row we hold for you — assessments, blueprints, grades, photos, folders, activity logs, subscription records and referral records — and then delete the login identity itself.
Deletion is immediate and is not reversible. Backups and provider-side logs may persist for a short period afterwards as part of normal operation.
One thing survives an account deletion, and we would rather name it than let you discover it: we keep a minimal record that the deletion happened — your account identifier, the action, and the time. It contains no student data, no images and no grades. We keep it because an account deletion that erased all evidence of itself would leave us unable to demonstrate that we honoured your request, or to investigate if someone else triggered it.
We also keep a security log of significant actions on an account — sign-ins, failed sign-in attempts, deletions and administrative changes — recorded with the time and the originating IP address. It is used for security investigation and to meet obligations to schools, not for analytics or marketing.
Who can see uploaded papers
Uploaded images are private to the account that uploaded them. The storage bucket allows no public access; every image is served through a signed link that expires shortly after it is issued and is only generated for the signed-in owner. There is no public URL for a student paper.
Student records and FERPA
Student work is sensitive, and the honest position is this: SuperGrader is a tool you direct. When you upload student work, you are disclosing student information to us and to the AI providers listed above. Under FERPA, a school may designate a vendor as a school official with a legitimate educational interest, but that determination is your school’s or district’s to make, not ours to assert.
Accounts here are individual: you sign up as a teacher, not on behalf of your school, and we hold no agreement with your district. Creating an account is not your school’s approval of this service. Many districts require software handling student work to be reviewed and approved first, and some prohibit sending it to third-party AI services at all. Please check your own district’s policy before uploading student work — we have no way to check it for you.
If your institution requires a data processing agreement, a vendor review, or restrictions on sending student work to third-party AI models, please complete that process before uploading student work. We are glad to help with the paperwork.
We do not knowingly collect information directly from children. Accounts are for educators. Student information reaches us only through work that a teacher uploads.
AI model training
We do not use your student work to train our own models — we do not train models. Student work is sent to third-party AI providers for the sole purpose of grading it for you, and their handling of that data is governed by their own terms. If your institution needs contractual assurance that submitted content is excluded from provider-side training, ask us and we will tell you exactly what our current provider agreements say.
Security
- All traffic between your browser and our servers is encrypted with HTTPS.
- Data is encrypted at rest by our database and storage providers.
- Every API request is authenticated, and records are scoped to the account that owns them.
- Sign-in sessions use short-lived tokens with a refresh token held in an HTTP-only cookie that JavaScript cannot read.
- Payment card details never touch our servers.
No system is perfectly secure. If you believe your account has been accessed without your permission, contact us immediately.
Your rights
You can, at any time and without asking us:
- See everything stored in your account, through the app.
- Correct a grade, a student name or an answer key.
- Delete individual grades, assessments or folders.
- Delete your entire account and all associated data from Settings.
Depending on where you live, you may have additional rights over your personal data, including the right to a portable copy. Write to us and we will help.
Changes
If we change how we handle data in a way that materially affects you, we will update the date at the top of this page and notify account holders by email. Continuing to use SuperGrader after a change means you accept the updated policy.
Contact
Questions about this policy, or requests relating to your data:
See also our Terms and Conditions.