Compliance before data moves.
We sequence privacy and security review before any student data is processed in the cloud — not after.
We built GridGrade so that the cautious choice is the default one. Here's exactly how student data is treated.
This is a plain-language stance page, not a legal contract. A formal Privacy Policy / DPA is available to institutional customers.
We sequence privacy and security review before any student data is processed in the cloud — not after.
For the Fall 2026 pilot, grading runs locally on the instructor's own machine. No student data touches any cloud platform.
The deterministic core does the grading and is the authority. Third-party AI assists only on judgment calls, on minimal anonymized snippets — and an instructor or institution can disable third-party AI entirely.
We never log student names, IDs, or cell contents. Student work never enters our code repository or issue tracker; feedback we collect is scrubbed of personal information before any human sees it.
Extracted artifacts and stored results are deletable on request; the system is built around single-prefix erasure so a deletion is complete, not partial.
During Fall 2026, processing student submissions locally is functionally equivalent to opening them in Excel for grading — no vendor cloud involved.
Before any real student data enters the cloud, the customer institution's security and data-sharing review must clear, and student consent is captured where required. We provide a privacy packet: a data-flow one-pager, PII-minimization design, a configurable retention/deletion lifecycle, and a standard DPA template.
When workbooks are de-identified, it's a real pipeline — author/company metadata, comment authors, headers/footers, and roster-name matches are all addressed — not just a renamed file. We don't treat "hashed the filename" as de-identification.
Your name, email, institution, role, course/enrollment context, your selected interest, and your message. We store this to respond to you and to plan the launch. We don't sell it or share it. We keep it only as long as needed to follow up.
We capture your approximate request metadata (a coarse rate-limit signal and timestamp) to stop abuse. We do not run third-party advertising trackers.
The marketing site has no login; the graded product (with its own privacy controls) is separate.
In the product, retention is course-configurable (a sweep set per term by the instructor's institution), and a deletion request is honored completely. Grading evidence is never silently lost — it's either retained per the course's setting or fully erased on request. For this website's contact data, email hello@gridgrade.app to have your inquiry deleted.
Security and privacy are first-class — sequenced before any student data moves.
Email hello@gridgrade.app.
Launching Fall 2026 — early access & pilot inquiries open now. One human reads every message.
One human reads every message. We aim to reply within two business days.
No commitment. We never share your information. Replies typically within two business days.