Legal
Student work is the most sensitive thing you will ever hand a piece of software. Here is exactly what happens to it.
Last updated September 8, 2026
This policy explains what GradeBud, Inc. (“GradeBud”, “we”, “us”) does with personal data on gradebud.com and in the grading app. It covers two groups of people, and the difference matters.
Your name, email, school and role, and your password (hashed) or your Google sign-in. Plan, credit balance and credit history. A Paddle customer reference so payments can be matched to your account.
Class names, student names and — if you add them — student emails, plus your rubrics and assignment instructions. We ask for the minimum that makes grading work; there is no field for a student ID, birth date, address, grade history or anything about a student’s background.
The pages you upload, as images. PDFs are converted to page images in your browser before anything leaves your device. Alongside them we store what grading produced: rubric scores, margin comments, the overall grade, and an AI-writing likelihood.
Standard server logs (IP address, browser, timestamps, errors) for security and debugging, and per-grading token counts and model cost so we can meter credits and keep the service solvent. We run no advertising trackers and no third-party analytics.
Where the GDPR applies, our bases are performance of a contract (running the service), legitimate interests (security, fraud prevention, improving the product with aggregate figures), consent (optional cookies and marketing), and legal obligation.
We do not sell personal data, share it for cross-context behavioural advertising, or use it for automated decisions with legal effects — a teacher approves every grade.
Grading sends the page images of one submission, along with your rubric and assignment instructions, to Anthropic’s API, where a Claude model reads and scores them. That call carries no student name, no email, no class and no account identifier — just the pages and the rubric.
Anthropic does not train models on data submitted through its API, and neither do we. We do not use your papers, rubrics or grades to train, fine-tune or evaluate any model, and we do not let anyone else do so. If a model declines a paper, the request may be retried on a substitute model within the same API call under the same terms.
Output is a draft for you to review. What that means for grading decisions and academic-integrity findings is set out in the Terms.
Student work and grades are education records. When you use GradeBud we act as a school official with a legitimate educational interest under FERPA’s outsourcing exception — we perform a function the school would otherwise use its own staff for, we are under the school’s direct control as to the use and maintenance of the records, and we do not redisclose them without authorisation.
Districts that need a signed data privacy agreement, a data protection addendum or a state-specific student-privacy contract can reach us at privacy@gradebud.com.
GradeBud is for educators, not students: children cannot create accounts, log in, or interact with the service. Where the work you upload belongs to a child under 13, we process it only on your school’s instructions, and the school is responsible for the notice and consent COPPA requires — schools may give that consent on a parent’s behalf for educational services like this one. We ask for no more information about a student than a name, and even that is optional.
We keep the list short on purpose. Each of these is bound by contract to process data only on our instructions and to protect it:
We will post changes to this list here before a new sub-processor starts handling student data. Institutions on a signed agreement get notice by email.
Your content stays until you remove it, because a graded paper is worth keeping for the term it belongs to. You can delete classes, students and rubrics yourself in the app; deleting a class removes the assignments, submissions and grades under it.
To have uploaded page images and grading records erased — for a term you have finished, or altogether — write to privacy@gradebud.com and we will delete them within 30 days. Closing your account deletes your profile and everything hanging off it on the same timetable.
Two things outlive that: backups, which roll off within 30 days, and billing and tax records, which we keep for as long as the law requires them — those hold transactions, not student work.
Depending on where you live you can ask us for a copy of your personal data, correct it, delete it, get it in a portable format, object to or restrict certain processing, or withdraw consent. Write to privacy@gradebud.com and we will answer within 30 days. We will not treat you differently for asking.
Requests about a student’s records go to the school rather than to us — the school controls those records and we act on its instructions. If you are in the EEA or UK you may also complain to your data protection authority.
GradeBud is operated from the United States and our providers process data there. If you use the service from outside the US, your data is transferred there. For transfers from the EEA, UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses with our providers. Institutions with a data-residency requirement should talk to us before signing up.
We will post any update here with a new “last updated” date. If a change materially affects how we handle student work or your personal data, we will email account holders at least 30 days before it takes effect.
GradeBud, Inc. — privacy questions, data requests and district paperwork go to privacy@gradebud.com. Suspected security issues go to security@gradebud.com.
The contract you are on is the Terms of Service.