Skip to main content
Grade Orbit

Privacy Policy

Last updated: June 2026

1. Our Commitment to Privacy

At Grade Orbit, we take data privacy seriously. This Privacy Policy explains how we handle your data. We operate two distinct tiers with different postures:

  • Solo / individual teacher tier: we do not handle student personal data. Student work is redacted in your browser before upload; we are a “Service Provider” under a PII-Free Zone architecture.
  • School tier: under our Article 28 Data Processing Agreement, which forms part of our Terms, we act as a Processor for the school. The school remains the Controller. We process real student names, uploaded student work, and the outputs of marking and AI-detection checks under the DPA, with strict tenant isolation and explicit retention controls. Where a school chooses to give pupils their own logins, we also process pupil email addresses so those pupils can sign in to view their own marked work. Uploaded work is retained so teachers can return to a student’s results, then deleted automatically once a run’s retention window passes or when the school account is closed. See our Transparency Pack for the full school-tier breakdown.

2. Student Data & PII Protection

The “PII-Free Zone”

On the Solo and Team tiers, our servers are a strictly designated “PII-Free Zone” — we do not ingest, store, or process unredacted student PII.

This applies to the Solo / individual teacher tier described above. The School tier works differently: under our Data Processing Agreement, which forms part of our Terms, schools upload un-redacted student work and we store it (and real student names) as a Processor, governed by the DPA and the retention controls set out in this policy and our Transparency Pack.

For the Solo / individual teacher tier, to ensure compliance with GDPR and UK GDPR:

  • Client-Side Redaction: All redaction of student names, IDs, and signatures happens entirely within your browser. The unredacted image never leaves your device.
  • Anonymous Data Transfer: Only anonymous, redacted data is sent to our servers and AI providers (Google Gemini). Students are identified only by generic placeholders (e.g., “Student 1”) or your own local reference systems that we cannot decrypt.

3. Data We Collect

We collect only the minimum data necessary to provide our service to you (the teacher/school):

  • Account Information: Your email address and encrypted password.
  • Usage Data: Anonymous statistics about feature usage to help us improve the platform (handled via our Cookie Policy).
  • Content: The grading criteria, exam board specifications, and reference texts you upload to configure the AI.
  • Lesson planning content: Schemes of work, lesson ideas, and generated lesson PowerPoints are your own teaching material, not student data. We store them with your account so you can return to them; they are deleted when your account is deleted (for schools: when the school’s account closes). Please don’t include student personal information in them — lesson planning sits outside the redaction flow.
  • Redacted Student Work (Solo / Team): The anonymous image data and text transcriptions generated after you have performed redaction in your browser.
  • School Student Work & Results (School tier): For schools on a Data Processing Agreement, the un-redacted student work uploaded for marking or AI-detection, the real student names (and optional nicknames) it is matched to, and everything we generate from it — the transcription of the work, AI and teacher feedback, grades, on-page annotations, and AI-detection results. This is stored as a Processor for the active life of the assessment run and then for the school’s chosen retention window, and is deleted automatically once that window passes or when the school account is closed.
  • School Pupil Logins & Email (School tier): Where a school chooses to give pupils access to their own marked work, we collect each pupil’s email address (supplied by the school — typed in or imported from a spreadsheet) and create a login for them. The pupil sets their own password, which is stored only as a securely hashed value — we never see or keep the password itself. We send a pupil two kinds of message: a one-time “set your password” email and a “your result is ready” notification when a teacher shares feedback. Grades and feedback are never included in these emails — they are shown only after the pupil signs in, and a pupil can only ever see their own approved results, never another pupil’s. Pupils are never sent marketing of any kind.
  • Operational Logs: To maintain and improve service quality, GradeOrbit temporarily stores the mark schemes you provide and the AI-generated outputs (grades, feedback, and transcriptions) for each marking session. This data is retained for up to 30 days and is used solely for debugging and service improvement. No student images are stored in these logs. This data is accessible only to GradeOrbit staff.
  • Team Membership & Usage (Teams only): Where you join a Team, the Team Owner can see the email address of every member of their team and per-member credit usage statistics (credits consumed, marking and AI-detection counts, and a recent transaction history). Team Owners cannot see the content of any student work or AI outputs — only aggregate usage figures. Each team’s data is isolated from other teams via database row-level security.

3a. Marketing Emails

Marketing emails — product updates, tips, and activity-based reminders — are sent only to users who have explicitly opted in. You can choose to opt in at signup, and you can change your choice at any time from Account → Email Preferences. Not opting in does not affect transactional emails such as welcome messages, password resets, or billing notifications — we still need to send those to operate the service.

4. Your Roles & Responsibilities

In every tier, you (the teacher or the school) are the Data Controller and are responsible for having a lawful basis to process student work. Our role depends on your tier:

Solo / Team: Grade Orbit acts as a Service Provider. Because student work is redacted in your browser before it reaches us, we provide the tools to process data but do not see or hold the underlying student personal data.

School: Under our Data Processing Agreement, which forms part of our Terms, Grade Orbit acts as your Data Processor. The school remains the Controller; we process real student names, student work, pupil email addresses, and the results strictly on the school’s documented instructions and only for the purposes set out in the DPA.

If you have questions about our privacy practices, please contact us at george@gradeorbit.co.uk