Legal
Privacy Policy
Last updated: July 2026
Overview
DraftGrade helps teachers grade handwritten student work using AI. This policy explains what information passes through the product, how it's used, and what is and isn't stored. It applies to the current pilot version of DraftGrade and will be updated as the product changes.
What we ask teachers to do first
Before uploading any student work, teachers are reminded to cover or redact student names on the page itself. This is the first and most reliable layer of protection, and it happens before anything reaches our systems.
What DraftGrade processes
- Photographs or scans of student work, uploaded by the teacher
- Rubrics, uploaded as a file (PDF, DOCX, or TXT) or pasted as text
- The resulting scores and feedback generated for review
This content is sent to our AI provider for processing at the time of grading. It is not retained on our servers after a session ends. The underlying model is also instructed to avoid including personally identifying information in anything it returns.
What we don't do
- We don't build student profiles or track individual students over time
- We don't sell or share student work with third parties for advertising or any other purpose
- We don't require students to create accounts or log in
Analytics
We use standard, privacy-conscious analytics to understand how the product is used at an aggregate level, such as which features are used and how often. This data isn't tied to individual student work.
FERPA and the school official exception
There is no official government certification for FERPA compliance. FERPA is a law a school and its vendors comply with together, not a badge a company is independently awarded. Under FERPA's "school official" exception (34 CFR § 99.31(a)(1)(i)(B)), a vendor can be treated as a school official with legitimate access to education records once a school designates it as one. That designation rests on three conditions, and here is how DraftGrade is built to meet each one:
- Performs a service the school would otherwise use its own employees for. Grading and generating feedback on student work is exactly this kind of institutional function.
- Is under the direct control of the school with respect to the use and maintenance of education records. DraftGrade doesn't retain student work after a grading session ends, so there is no ongoing record for a school to control the use of. Institutions that want this formalized in writing can request a signed Data Processing Agreement.
- Is subject to FERPA's requirements on the use and redisclosure of personally identifiable information. Student work is used only to generate the requested grade and feedback. It is sent to our AI processing partner for that single purpose, under terms that prohibit using submitted content to train their models, and is not shared, sold, or repurposed for anything else.
We won't claim a certification that does not exist. What we can offer is an honest account of the practices above, and a signed DPA for any school that wants the arrangement formalized.
On your device
To make re-grading the same papers instant instead of calling the AI again, DraftGrade saves recently graded results in your browser's local storage on the device you're using. This is separate from the server-side handling described above: it lives only on that device, in that browser, and is never sent to us. These saved results include the scores, feedback, and short excerpts quoted from the student's writing that the grading result contains. You can clear them at any time from the Preferences page, and they age out automatically once a device has accumulated more than a class set's worth of results.
Data retention
Uploaded images and rubrics exist only for the duration of a grading session and are not stored afterward. Teachers are responsible for saving or exporting results they want to keep, using the copy and download options provided in the product.
One exception: when a teacher manually overrides a suggested score, DraftGrade keeps a short accountability log of that change, so a school can review how grades were adjusted. Each entry holds the rubric's title, a generic label like "Paper 1" (never a filename or a student's name), and the before/after score, not the student's actual work or the AI's written feedback. These entries are kept for 90 days and are visible only to the teacher who made the change.
Changes to this policy
As DraftGrade moves from pilot to general availability, this policy will be updated to reflect any changes in how data is handled, including the introduction of formal agreements for institutional customers. Material changes will be noted here with an updated date.
Contact
Questions about this policy or how a specific school's data is handled can be directed to our team through the contact options on the About page.