Privacy Policy

Effective date: June 3, 2026

Last updated: June 3, 2026

This Privacy Policy describes how RavenGrader, Inc.(“RavenGrader,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use RavenGrader — our AI-assisted grading service for educators (the “Service”).

RavenGrader is a tool for instructors, teaching assistants, and graders at colleges and universities. Our direct customers are educators and educational institutions; students do not create RavenGrader accounts. In the course of providing the Service, we process student coursework on behalf of, and at the direction of, those educators and institutions. How we handle student information is described in Section 7 (Student Data & FERPA).

Questions, or to exercise a privacy right? Contact us at williamtjandra@ravengrader.com or christopherlauw@ravengrader.com.

This document is honest about the current state of the Service, including known limitations. Where a practice is not yet automated, or a safeguard is still being built, we say so rather than overstate it.

1. Information We Collect

Information you provide to us

Account information. When you create an account, we collect:

We authenticate accounts using a password (managed by our authentication provider, Supabase, and never stored by us in plaintext) or, where you launch the Service from your institution’s Canvas learning management system (LMS), via that LMS.

Content you upload. To use the Service, you upload grading materials, which may include:

Payment information. If you purchase page credits or a subscription, our payment processor (Stripe) collects and processes your payment details directly through Stripe’s embedded checkout component. We do notreceive or store full card numbers or security codes. We retain only Stripe-issued references — a customer ID, payment-method ID, subscription ID, subscription status, period-end date, page-credit ledger entries, and (if you cancel a subscription) any cancellation reason code and free-text comment you provide in Stripe’s cancellation flow.

Communications. If you email us or submit our contact form, we receive the name, email address, and message you provide. Contact-form messages are relayed to our support inbox via Resend and are not stored in our application database.

Information we collect automatically

Diagnostic, error, and session-replay data (Sentry). We use Sentry to detect, diagnose, and fix problems and to monitor performance. This includes error messages, stack traces, the page or action involved, browser/device characteristics, performance traces, backend profiling data, forwarded application log lines, and client-side Session Replay. We configure Sentry not to attach personally identifying user fields automatically (sendDefaultPii: false). Because that setting alone does not govern on-screen or logged content, we apply the following additional controls and disclose the residual limits plainly:

Limited usage logs. We keep a limited in-app audit log of certain actions (for example, viewing the dashboard, submitting work through the Canvas integration, and administrator access). These entries record the action type, related resource identifiers, and limited contextual metadata such as a file count or Canvas user ID. They do not currently record IP address or user-agent.

Operational metrics. We record per-API-call token counts, cost, and latency linked to internal account/course/exam/submission identifiers, used to calculate page-credit consumption and to operate and monitor the Service.

IP address. Our backend reads your IP address to apply rate limits and protect the Service from abuse. We do not store your IP address in a persistent user profile or transmit it to any advertising or analytics third party.

Cookies. We use only strictly necessary, first-party cookies (a Supabase session-authentication cookie to keep you signed in). See Section 12 (Cookies and Tracking Technologies).

Information we do NOT collect

To be clear about what we don’t do:

2. How We Use Information

We use the information above to:

We do not use your content to send you marketing or promotional campaigns. The only emails we send are service- and account-related. We do not use student education records for any purpose beyond performing the grading function for the institution or instructor that uploaded them.

3. How AI Processing Works

Grading is performed using third-party AI models provided by OpenAI(primarily GPT-5.4 for all grading stages, with GPT-5.4-mini used for a narrow notation-disambiguation step). To grade a submission we transmit content to OpenAI’s API: answer-key images/text and rubric data; student submission images (sent as base64-encoded data URIs inline in the request); and the AI-generated transcription text of the student’s work. We do not include any student name, email address, or institutional identifier in the prompts sent to OpenAI.

A separate, brief LLM call (the notation disambiguator) may run on a small fraction of questions when a student’s written math contains convention-ambiguous notation; it sends the student’s expression and a truncated transcription excerpt to GPT-5.4-mini and contains no student identifiers.

De-identified and aggregated data. We may create de-identified or aggregated information from data processed through the Service — including from student submissions, transcriptions, and grading results — and use it to develop, evaluate, and improve our grading models, rubric generation, and other features. Before any such use, we remove direct identifiers (such as names, email addresses, and Canvas user IDs) and any indirect identifiers that could reasonably be used to identify an individual, so the data cannot reasonably be linked back to a student, instructor, or institution; we commit not to attempt to re-identify it; and we require any recipient to do the same. We do not sell de-identified data, and we never use identifiable student coursework, transcriptions, or grades to train AI models.

In this Policy, de-identified data means data from which we have removed or obscured all direct identifiers and any indirect identifiers that could reasonably be used to identify an individual, such that the data cannot reasonably be linked back to a student, instructor, or institution, and which we do not attempt to re-identify.

4. How We Share Information

We do not sell your information and do not share it for cross-context behavioral advertising. We share it only with the service providers (“subprocessors”) below, who process it on our behalf under contractual confidentiality and data-protection obligations, and as described under “Other disclosures.”

Subprocessors

Provider (legal entity)LocationPurposeInformation involved
Supabase, Inc. (hosted on AWS, US-East-1, N. Virginia)United StatesDatabase, authentication, and private file storageAll personal and student data at rest: account data, uploaded answer keys and student submissions, transcriptions, scores, and billing references
OpenAI, L.L.C.United StatesAI grading pipeline (answer-key analysis, transcription, scoring), including the Batch APIAnswer-key images/text and rubric; student submission images (base64) and transcription text; internal submission UUID in batch metadata and custom_id. No student names or emails are placed in prompts.
Stripe, Inc.United StatesPayment processing, subscriptions, and customer portalInstructor email, internal user ID, Stripe billing identifiers, and checkout metadata (purchase type). No raw card data; Stripe’s embedded component handles card entry.
Functional Software, Inc. d/b/a SentryUnited StatesError monitoring, performance tracing, backend profiling, and client-side Session ReplayError/diagnostic data, forwarded application logs (which can include student names and instructor email), and session replays (which can incidentally capture on-screen student names, scores, and transcriptions)
Resend, Inc.United StatesTransactional email deliveryInstructor email, exam name, course name, and student count (grading-completion notices); contact-form name, email, and message (relayed to our support inbox). No student names or submission content.
Instructure, Inc. (Canvas LMS)Operated by your institutionLTI 1.3 integrationInbound: student name, Canvas user ID, role, and course/assignment identifiers received at launch. Outbound: the approved, curve-adjusted score and Canvas user ID written back to your gradebook.
Railway CorporationUnited StatesBackend application hostingAll backend HTTP traffic in transit, including student files and grading data
Vercel, Inc.United StatesFrontend application hostingAll browser traffic to the web application from instructors, TAs, graders, and Canvas-embedded student sessions

Google Fonts (Google LLC).Our public marketing landing page loads a webfont directly from Google’s font CDN (fonts.googleapis.com), which causes your browser to send your IP address and user-agent to Google when you visit that page. This does not occur on the authenticated application, where fonts are self-hosted. We disclose this so it cannot be read as covering authenticated, student-data pages.

Other disclosures

Learning management systems. When you or your institution connect RavenGrader to Canvas via LTI 1.3, we exchange data with Canvas as described above only while the integration is enabled.

Legal and safety. We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of RavenGrader, our users, or others. For legal demands seeking student education records we hold on behalf of an institution, see Section 7.

Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify affected users of any resulting change in ownership or use of their information.

5. Data Retention

We retain information for as long as your account is active or as needed to provide the Service, and we are transparent about the current limits of our deletion tooling.

Account deletion. When you delete your account, it enters a 30-day grace period during which it can be reactivated and no new charges or credit spend are permitted. Once that period elapses, the account is permanently destroyed by an automatic daily process: database rows are deleted (except the de-identified billing records described above), and the associated uploaded files are removed from our storage service.

Known deletion limitations (disclosed). As of the date of this Policy:

We are actively building automated export tooling and will update this section as those capabilities ship. Institutions may request manual deletion or return of their student records at any time (see Sections 7 and 8).

6. How We Protect Information

We use reasonable technical and organizational safeguards, and we describe both what we do and where we are still hardening.

Encryption in transit. Traffic between your browser and the Service is served over HTTPS/TLS by our hosting providers (Vercel for the frontend, Railway for the backend). Non-localhost CORS origins are restricted to https:// endpoints.

Encryption at rest.Data stored in our database and file-storage buckets is encrypted at rest using AES-256, implemented at the infrastructure layer by Supabase (on AWS US-East-1) under its SOC 2 Type II–certified controls. We do not add a separate application-level encryption layer on top of this infrastructure encryption, and our database connection relies on Supabase’s server-side TLS requirement rather than an application-enforced ssl=require parameter.

Access controls.Database tables holding account, course, submission, grading, audit, and billing data are protected by Postgres row-level security so authenticated users can access only their own data and courses they belong to. Storage buckets are private and accessed only through short-lived, pre-signed URLs. Account authentication uses Supabase ES256 JWTs verified against Supabase’s published JWKS endpoint. Administrative access is restricted to a named email allowlist. Critical grading endpoints are rate-limited. Stripe webhook payloads are signature-verified.

Known security gaps (disclosed).In the spirit of transparency with institutional customers: our Canvas LTI integration tables do not yet have row-level security applied; LTI launch token signatures are not yet verified against Canvas’s JWKS; some LTI student-view endpoints accept a Canvas user ID as a query parameter without session authentication; certain authenticated submission endpoints do not yet enforce course-membership ownership checks; administrative access uses an email allowlist without enforced multi-factor authentication; and a development LTI private key was identified in version control and is being rotated. We have not obtained SOC 2 Type II certification of our own program (our core subprocessors independently hold SOC 2 Type II reports). We are remediating these items and will update this section as controls are strengthened.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential.

7. Student Data & FERPA

RavenGrader is designed for educational use, and most student data we process constitutes “education records” under the Family Educational Rights and Privacy Act (FERPA).

7.1 RavenGrader as a “school official”

When a FERPA-covered educational institution uses RavenGrader to grade student coursework, RavenGrader, Inc. acts as a “school official” with a “legitimate educational interest” within the meaning of FERPA, 34 CFR § 99.31(a)(1)(i)(B). Grading — evaluating student work, producing scores, generating feedback, and returning results to the instructor or gradebook — is a function the institution would otherwise perform using its own faculty, teaching assistants, or graders. RavenGrader performs that same institutional function under the direction of, and on behalf of, the institution.

As a school official, RavenGrader:

Improvement and de-identified data. We improve our grading models using de-identified and aggregated data only. Under 34 CFR § 99.31(b)(1), information from which all personally identifiable information has been removed — where a reasonable determination has been made that a student’s identity is not personally identifiable — is not subject to FERPA’s consent, use, and re-disclosure restrictions. We do not use identifiable student education records to develop, evaluate, or train our models. See Section 3.

The institution remains the controller. The educational institution — not RavenGrader — is the controller of student education records. Institutions and instructors are responsible for ensuring their disclosure of student records to RavenGrader falls within an applicable FERPA exception (including the school-official exception at 34 CFR § 99.31(a)(1)(i)(B)) and for providing required notices to students or parents.

7.2 Education records and personally identifiable information

When RavenGrader is used by or on behalf of an institution, the following categories of student data we receive and process may constitute “education records” and “personally identifiable information” under FERPA, 34 CFR §§ 99.3 and 99.32:

We do not extract or store student email addresses, and we do not pull Canvas rosters (NRPS is not implemented).

Grades are not directory information. Scores, feedback, transcriptions, and other grading data are not“directory information” under 34 CFR § 99.3. We do not designate, publish, or disclose them as directory information, and we do not treat the absence of an opt-out as permission to share them. Grade data is disclosed only to the submitting institution or instructor, or written back to the institution’s own gradebook at the instructor’s direction.

7.3 Use limitation

Student education records are: used only to provide the grading Service; never used for behavioral or targeted advertising; never mined for commercial student profiling; never used in identifiable form to train or fine-tune any AI/ML model that RavenGrader operates or controls; and never sold, rented, licensed, or transferred for commercial gain. Once data has been de-identified and aggregated so that it can no longer reasonably be linked to a student (Section 3), it is no longer an education record, and we may use it to evaluate and improve the Service; we do not attempt to re-identify it.

7.4 Institutional direct control, return, and deletion

The institution (or an instructor acting under institutional authority) retains direct control over the use and maintenance of student education records. Authorized institutional personnel may, at any time, access submission files and grading results through the Service, and may request correction, export, or deletion of student records by emailing williamtjandra@ravengrader.com or christopherlauw@ravengrader.com; we will fulfill such requests, currently through a manual process. RavenGrader will not unilaterally delete or repurpose institution-controlled student records except as required by law or as directed by the institution. Important limitations (disclosed):we do not yet offer a self-service export interface, and export requests are fulfilled manually; deletion of student records is automatic but not immediate (stored files and rows are destroyed after the recovery window described in Section 5, and destruction ahead of that window is fulfilled manually on request); and, because submission content sent to OpenAI remains subject to OpenAI’s limited abuse-monitoring retention pending a zero-data-retention arrangement, we cannot compel OpenAI to delete a specific record on instruction (see Section 3).

7.5 Re-disclosure restriction and subprocessor obligations (34 CFR § 99.33)

RavenGrader will not re-disclose personally identifiable information from education records except (a) as directed by the controlling institution or educator, or (b) as otherwise authorized under FERPA (for example, in response to a lawful subpoena or court order after any required notice). Each subprocessor that receives education records (OpenAI, Supabase, Sentry, Railway, Vercel, and Canvas as the institution’s own system) is engaged under terms that limit use to performing the contracted function, prohibit further re-disclosure except as required by law, and require reasonable security. We disclose in Section 3 the remaining OpenAI abuse-monitoring retention window.

7.6 Student/eligible-student rights — contact your institution

Because the institution controls these records, FERPA rights flow through the institution, not directly through RavenGrader.

7.7 Solo and individual-instructor accounts

FERPA applies to educational agencies and institutions. Many RavenGrader accounts are created by individual instructors, TAs, or graders acting independently, without a formal agreement between their institution and RavenGrader. When you use RavenGrader on your own — not under an institutional contract and not as an authorized agent of a FERPA-covered institution for this purpose — the school-official exception does not, by itself, extend to RavenGrader through your individual use. In that case, our handling of the student data you upload is governed by our contractual commitments to you in this Policy and by applicable state law. In either context our substantive commitments are identical (we use student data only to provide the Service; we do not sell it, use it for advertising, or train models on it); the distinction affects the legal mechanism, not the safeguards. If you are an individual instructor, you are responsible for determining whether you have authority to upload student work and whether your institution requires use of only institutionally contracted tools or any student consent. We do not verify institutional affiliation at signup.

7.8 Institutional agreements and data return/destruction

Institutions may execute a separate Data Processing Agreement / FERPA Addendum (DPA)with us governing use, re-disclosure, security, deletion, and (where applicable) data return or destruction upon termination. Upon termination and on written request, we will make available an export of the institution’s education records and, on request, delete them and the corresponding stored files — currently through a manual process given the deletion limitations disclosed above. To establish institutional terms, contact williamtjandra@ravengrader.com or christopherlauw@ravengrader.com.

7.9 No waiver of FERPA rights

RavenGrader does not require, and has never required, students or parents to waive any FERPA right as a condition of having coursework processed through the Service. Students are not parties to these terms and do not create accounts; our authority to process their records derives from the school-official relationship (or, for solo instructors, from our agreement with the instructor and applicable law), not from any student consent or waiver.

8. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to opt out of certain processing. We extend the core choices below to all account holders. State- and region-specific rights are in Sections 9 (California), 10 (other U.S. states), and 11 (EU/UK).

Account-holder data (you). As the controller of your own account data (email, display name, billing references, your courses/exams and grading history), you may request: access/portability (a copy of your personal account data); correction; deletion of your account; and withdrawal of consent. When we delete your account, most associated database records — your profile, courses, exams, submissions, grading results and runs, audit entries, credit balance, and credit ledger — are deleted via cascading deletion. Uploaded files in our storage service are not deleted by this process and require a separate manual deletion (see Section 5).

How to submit a request — two methods. You may (1) email williamtjandra@ravengrader.com or christopherlauw@ravengrader.com from the address associated with your account, including the right you wish to exercise; or (2) submit a request through the contact form at ravengrader.com, noting your request in the message. We may verify your identity before acting. We currently fulfill all rights requests manually and aim to respond within 45 days; if we need more time we will tell you within that period.

Student data. If your data was uploaded by an institution or instructor (for example, your coursework as a student), those records are controlled by the institution or instructor. Direct access, correction, and deletion requests to them; we will cooperate in fulfilling such requests. We do not honor student-submitted deletion requests for education records directly, because doing so without institutional authorization could itself violate FERPA.

Transactional emails. We do not send marketing email, so there is no marketing list to unsubscribe from. Service and account emails (such as grading-complete notices) are necessary to operate the Service.

9. California Privacy Rights (CCPA/CPRA)

This section applies to California residents.

9.1 Categories of personal information collected (last 12 months)

Within the meaning of Cal. Civ. Code § 1798.140, in the past 12 months we have collected:

Sensitive personal information (SPI). The only SPI we collect from account holders is account log-in credentials(email and a Supabase-managed, hashed password we never see in plaintext). Student education records may reveal academic performance. We use SPI only to provide the requested Service and for no secondary purpose, so the Right to Limit does not apply to our current practices, and we do not post a “Limit the Use of My Sensitive Personal Information” link. We do not collect SSNs, precise geolocation, racial/ethnic origin, religion, biometric identifiers for identification, health, or sexual-orientation data.

9.2 Sources, business purposes, and recipients

We collect this information directly from you, from your institution’s Canvas LMS via LTI (student name and Canvas user ID), automatically through your use of the Service (diagnostic/usage data), and from Stripe (billing references). We use it for the business purposes in Section 2. We disclose it only to the service providers in Section 4 (Supabase, OpenAI, Stripe, Sentry, Resend, Canvas, Railway, Vercel) to operate the Service. We do not sell personal information and do not share it for cross-context behavioral advertising.

9.3 Your California rights

You have the right to know (categories and specific pieces), delete, correct, opt out of sale/sharing (we do not sell or share, so there is nothing to opt out of, but you may submit a request to confirm), limit use of SPI (not applicable as explained above), and non-discrimination — we will not deny service, charge different prices, or provide a different level of service because you exercised a right.

Submitting and timing. Use either method in Section 8. We will acknowledge within 10 business days and respond within 45 calendar days, extendable once by up to 45 additional days with notice.

Authorized agents. You may use an authorized agent who provides either (a) your signed written permission or (b) a valid power of attorney under Cal. Probate Code §§ 4000–4465. For signed-permission requests we will verify the agent and confirm your authorization; for a valid power of attorney we will process upon verification. Send agent requests to williamtjandra@ravengrader.com or christopherlauw@ravengrader.com.

Notice at collection / Do Not Sell.This Section, together with Section 1, serves as our notice at collection. Because we do not sell or share personal information for cross-context behavioral advertising, we are not required to post a “Do Not Sell or Share My Personal Information” link; if our practices change, we will add the required mechanism before any such activity begins.

9.4 Automated decision-making (AI grading)

We use AI to assist grading; this section addresses California’s automated decision-making technology (ADMT) framework.

What we do.A multi-stage AI pipeline (OpenAI GPT-5.4) generates a rubric from the instructor’s answer key, transcribes student submissions, and scores them against the rubric, producing per-question scores, confidence flags, and feedback. Where Canvas is integrated, an approved score can be written to the gradebook, which can affect a student’s academic record.

Human review.No AI-generated grade is final without human involvement. Before grading begins, the instructor must approve the AI-generated rubric. After grading, each submission enters a “needs review” state; the instructor can view the per-question breakdown, confidence flags, and evidence, and edit any score before approving. Grades are released to students and written to the Canvas gradebook only when the instructor takes an explicit “Release Grades” action (which requires an instructor Canvas role). For transparency: at that release step, the system publishes all graded submissions for the assignment — including any the instructor has individually approved andany still in “needs review” status — so instructors should review before releasing. The instructor has full authority to edit any score before or after release.

Pre-use notice, opt-out, and appeals.Your instructor or institution is responsible for notifying you before your work is processed. Because we act at the institution’s direction, students who wish to opt out of AI-assisted grading, or to appeal a grade, should contact their instructor or institution (which can grade manually and can edit any score); we will honor opt-out and correction requests communicated to us by the instructor or institution, and you may also write to williamtjandra@ravengrader.com or christopherlauw@ravengrader.com and we will coordinate with the relevant party. We do not currently provide a student-facing in-app opt-out or appeal mechanism.

9.5 Narrow scope of the FERPA exemption

CCPA exempts FERPA-covered education records from most of its requirements, but that exemption is narrow. Your instructor/TA/grader account data, billing data, platform usage and diagnostic data, and contact-form communications are fully subject to CCPA/CPRA and may be the subject of the requests above. The FERPA exemption reaches only the student education records we process as a service provider on behalf of an institution.

10. Other U.S. State Privacy Rights

Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Delaware, and other states with comprehensive privacy laws (VCDPA, CPA, CTDPA, TDPSA, OCPA, DPDPA, and similar) have rights to confirm/access, correct, delete, and obtain a portable copy of personal data, and to opt out of the sale of personal data, targeted advertising, and profiling that produces legal or similarly significant effects. We do not sell personal data, conduct targeted advertising, or perform such profiling, so those opt-outs are already satisfied. The categories of data we collect, the recipients we disclose to, and the request methods are described in Sections 1, 4, and 8.

For student data we process as a processor/service provider on behalf of an institution or instructor, direct rights requests to that institution or instructor; we will assist them.

Sensitive data.We do not process the categories of “sensitive data” defined under these laws (precise geolocation; racial/ethnic origin; health; genetic or biometric data for identification; religious beliefs; sexual orientation; immigration status), so no separate opt-in consent is required.

Response and appeal. We respond to verifiable requests within 45 days (extendable once by 45 days). If we decline a request, we will explain why; you may appeal by emailing williamtjandra@ravengrader.com or christopherlauw@ravengrader.comwith “Privacy Rights Appeal” in the subject line, and we will respond within 60 days. If your appeal is denied, you may contact your state attorney general’s consumer-protection office.

Oregon residents may additionally request a list of the specific third parties to which we have disclosed personal data; based on the flows in this Policy these are the recipients named in Section 4.

11. EU/UK Data Protection (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies (for example, a contracting institution established in the EU/UK, or a student located in the EU/UK), the following applies. Our infrastructure and subprocessors are in the United States, so such processing involves an international transfer.

Our role. For student education records processed on behalf of an institution or instructor, RavenGrader is a processor(GDPR Art. 4(8)) acting on the controller’s documented instructions; the institution or instructor is the controller. For instructor/TA/grader account data, RavenGrader is an independent controller.

Article 28 DPA. Institutions and instructors may request a DPA compliant with GDPR Article 28; contact williamtjandra@ravengrader.com or christopherlauw@ravengrader.com.

Lawful basis (where we are controller of account data). Contract performance (Art. 6(1)(b)) for account and billing; legitimate interests (Art. 6(1)(f)) for security, fraud prevention, and error monitoring/diagnostics (including Sentry telemetry and Session Replay, which we have assessed against your interests and disclose as a known residual-risk channel in Section 1); and legal obligation (Art. 6(1)(c)) for financial-record retention.

International transfers.All subprocessors are US-based. We rely on the EU-US Data Privacy Framework (and UK Extension) where a subprocessor is certified, and otherwise on the European Commission’s Standard Contractual Clauses and, for the UK, the IDTA/UK Addendum. Transfer documentation is available on request. We have not yet appointed an Article 27 EU/UK representative; this is being addressed before we serve EU/UK users as a controller.

Data-subject rights. Where we are the controller of your account data, you have rights of access, rectification, erasure, portability, restriction, and objection; email williamtjandra@ravengrader.com or christopherlauw@ravengrader.com. We aim to respond within 30 days (extendable for complex requests). Where we are a processor, direct requests to the controlling institution/instructor; we will assist. You may lodge a complaint with your local supervisory authority (in the UK, the ICO).

12. Cookies and Tracking Technologies

We use a small number of first-party and limited third-party technologies. We do not use advertising cookies, cross-site behavioral-tracking cookies, or third-party analytics pixels.

Because the authenticated Service uses only strictly necessary first-party cookies plus the diagnostic technologies above, we do not currently display a general cookie-consent banner. Note that the Session Replay technology is non-essential; users with concerns may contact us to request that replay be disabled for their account, or may block the Sentry domain in their browser.

13. Do Not Track and Global Privacy Control

Do Not Track (DNT). Because there is no consistent industry standard for DNT signals, we do not respond to them. We do not perform cross-site tracking or behavioral advertising in any case.

Global Privacy Control (GPC). We acknowledge GPC signals. Because we do not sell personal information or share it for cross-context behavioral advertising or targeted advertising, there is no processing activity for a GPC signal to limit, and honoring it requires no change to how we handle your data. If we ever begin selling or sharing personal information, we will implement GPC detection and honoring within the time required by applicable law before doing so.

14. Children’s Privacy and COPPA

RavenGrader accounts are intended for educators (instructors, TAs, and graders), who are adults; we do not knowingly allow individuals to create accounts directly, and we do not knowingly collect personal information directly from children under 13 through registration or any direct interaction. Students do not create accounts and submit work through their institution’s tools.

Some coursework processed through the Service may belong to minors, including, in dual-enrollment contexts, students under 13. We process that data solely on behalf of, and at the direction of, the educator or institution under Section 7 — not for our own purposes, not for advertising, and not to build profiles of students or to train AI models. Where the Children’s Online Privacy Protection Act (COPPA) applies, we rely on the school’s authorization under COPPA’s school-consent mechanism (16 CFR § 312.5(b)(1)): the institution, not RavenGrader, is responsible for obtaining any required parental consent. Educators and institutions are responsible for any consents and notices required under FERPA, COPPA, and applicable state law before uploading student data. For minors aged 13–17 enrolled in post-secondary courses, FERPA rights vest in the enrolled “eligible student,” and applicable state student-privacy laws (such as SOPIPA) prohibiting commercial use, advertising, and student profiling apply regardless of age — commitments we already make for all student data. If you are a parent who believes a child’s information was collected without proper consent, contact williamtjandra@ravengrader.com or christopherlauw@ravengrader.com and we will review and, where required, delete it.

15. No Sale of Data; No Targeted or Behavioral Advertising

RavenGrader does not sell personal information — student education records, instructor account data, or anything else — and does not share personal information for cross-context behavioral advertising, as those terms are defined under CCPA/CPRA and other state laws. We do not use advertising trackers, analytics pixels, or marketing tags; we do not share IP or device identifiers with advertising networks or data brokers; and we do not use any data to build advertising profiles of students or instructors. We do not send product recommendations, marketing campaigns, or surveys to students, and we do not use student data to develop or market any product — consistent with FERPA, SOPIPA, and PPRA (20 U.S.C. § 1232h). Our only outbound emails are transactional grading-completion notices to instructors and relays of voluntary contact-form messages.

For higher-education institutions handling student financial-aid data subject to the GLBA Safeguards Rule (16 CFR Part 314), RavenGrader operates as a downstream service provider, maintains the safeguards described in Section 6 (subject to the disclosed gaps), and will, on request and under a written agreement, provide additional information to support the institution’s vendor-oversight obligations.

16. Security Incidents and Breach Notification

Despite the safeguards in Section 6, no system is perfectly secure. If we confirm a security breach affecting your personal information, or student education records we hold on behalf of an institution, we will:

RavenGrader acts as a service provider; the institution or instructor is responsible for notices owed directly to students or parents, and we will cooperate. To report a suspected security issue, contact williamtjandra@ravengrader.com or christopherlauw@ravengrader.com.

17. International Users and Data Location

RavenGrader is operated from, and stores data in, the United States. Our primary storage is on Supabase (AWS US-East-1); AI processing is performed by OpenAI’s US API; and our application is hosted on Railway (backend) and Vercel (frontend), both US-based. If you access the Service from outside the United States, your information will be processed in the United States, where data-protection laws may differ from those in your jurisdiction. We do not currently offer a non-US data-residency option; institutions with residency requirements should contact us before deploying.

18. Changes to This Policy

Every published version carries an effective date and a last updated date (shown at the top). Prior versions are available on request.

19. Who We Are and How to Contact Us

RavenGrader, Inc. is responsible for this Policy and the Service. For account data we act as an independent controller; for student education records we act as a processor / service provider / FERPA school official, processing solely on behalf of and at the direction of the institution or instructor (see Section 7). We have not designated a formal Data Protection Officer; privacy inquiries, rights requests, and institutional DPA requests should be directed to:

RavenGrader, Inc.
Email: williamtjandra@ravengrader.com or christopherlauw@ravengrader.com