Last Updated: October 5, 2026
Thank you for visiting Classwise AI. This Privacy Policy explains how Classwise AI, Inc. ("Classwise AI," "we," "us," or "our") collects, uses, and shares information when you visit classwise.ai or use our services as an educator, school official, or student ("Services").
This Privacy Policy applies to website visitors, educators, and students who interact with the Services.
This policy covers "Student Data," including student identifiers, assignments, submitted work, feedback, scores, grades, and Student Tutor messages and generated responses. Where Classwise AI and a school or district have executed a Data Processing Agreement (DPA), that agreement additionally governs Student Data. The DPA is available at Classwise AI Data Processing Agreement (DPA).
Where the DPA gives greater protection than this policy, the DPA controls. Nothing in the DPA reduces any commitment we make here.
We process Student Data to provide grading, feedback, and Student Tutor.
Where a school relies on FERPA’s school-official exception, processing must remain under its control and within its authorized educational purposes. Student Tutor collects information directly from students. Use involving children under 13 requires an appropriate school-authorization or parental-consent basis under COPPA.
Institutional DPAs define permitted use, access, retention, and deletion requirements. This Privacy Policy also covers Student Data processed through accounts without an institutional DPA.
Educators may use all Services features, including Student Data uploads, LMS integrations, and Student Tutor. A DPA applies where Classwise AI and a school or district have executed one.
You and your school or district own all data you provide to, or generate through, the Services. This includes your account information, the rubrics and comments you write, the feedback saved to your account, and all Student Data. Classwise AI claims no ownership of it and acquires no title or interest in it.
You grant us a limited, non-exclusive, revocable licence to host, process, transmit, and display that data for one purpose only: to provide the Services to you. The licence ends when the data is deleted. We claim no right to use it for anything else.
We do not use your data, your school's data, or Student Data to train, fine-tune, evaluate, or improve any artificial intelligence or machine learning model, whether ours or a third party's. Provider data-use and retention terms are addressed in Section 5 and Appendix A.
We collect information that you directly provide to us when you:
Create an Account:
Complete Your Profile (Optional):
Communicate With Us:
Make a Payment:
When payments are enabled, we will use Stripe as our third-party payment processor. We do not collect or store your full credit card information. Stripe processes your payment information on our behalf.
We also collect Student Data provided through the features described in Section 2D.
Third-Party Login: If you create or log into your account using Google or Microsoft ("Third-Party Services"), we receive the following information from them, and no other information: your Name, Email Address, and Profile Picture, as permitted by your settings on those services.
LMS Integration: If you choose to connect your account to a Learning Management System (LMS) like Google Classroom, we will receive information from that service. We receive the following and no other information: your name, email address, your LMS user identifier, the names and identifiers of the classes you teach, your class rosters (student names and LMS student identifiers), assignment titles and descriptions, and the student submissions for the assignments you choose to assess as permitted by your settings on that service. This is used solely to provide the integration.
Product Analytics: We use PostHog to understand how users interact with Classwise AI, diagnose errors, and improve the product.
PostHog hosts and processes our product analytics and diagnostic information. Software in the Services sends this information to PostHog as you use the app.
For signed-in educators, PostHog receives account and educator profile identifiers, name, email address, pages and features used, event times, error messages, IP address, and browser and device details.
PostHog can also receive session recordings and AI processing diagnostics. These may include Student Data displayed or processed in the Services.
Student Data includes student names, email addresses, LMS identifiers, class enrolment, submitted work, scores, feedback, and Student Tutor messages and generated responses.
We collect Student Data through educator uploads and connected learning management systems. We also collect it directly when students use Student Tutor, and may store their messages and generated responses with relevant assessment context. This data is covered by the retention and deletion provisions in Section 7.
We use cookies and browser storage to keep you signed in, remember preferences, and measure product use.
Functional Cookies: An authentication cookie keeps you signed in as you use the app. It is essential for the Services.
Analytics: PostHog collects product usage and diagnostic information as described above.
No Advertising Cookies: We do not use third-party advertising cookies.
Appendix B describes the main cookies and browser storage used by the Services, including their purpose, provider, and expected duration.
We use no advertising SDKs or device fingerprinting. We track interactions within our application for the purposes in Section 2C. We do not track you across other websites.
You can turn off analytics cookies at any time in your account settings, and doing so does not limit your access to any feature of the Services.
We use the information we collect for the following purposes:
We use information for the purposes described in this policy. We do not sell it, use Student Data for advertising, or use it to train or improve AI models.
We do not sell your personal information. We only share it in the following limited circumstances:
This list is complete. We share your information with no third party other than those named above, and we will not add one without first notifying you as set out in Section 12.
Appendix A sets out, for every third party we use, the exact data elements it receives, why it receives them, where it processes them, and how long it keeps them.
What we require of them
Every third party listed above has signed a written agreement imposing data protection, security, confidentiality, and deletion obligations at least as protective as those in this policy, in your school's Data Processing Agreement, and in our agreement with you. Each is prohibited from using your information or Student Data for its own purposes, from selling it, from using it for advertising, and from using it to train any AI or machine learning model. We remain responsible to you and to your school for how they handle it.
We take reasonable measures to protect your personal information from loss, theft, misuse, and unauthorized access. However, no security system is impenetrable.
Encryption
All confidential and sensitive information — all personal information and all Student Data — is encrypted throughout. It is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using AES-256. This applies to data held by us and to data held by every third party in Appendix A.
The specific steps we take
If something goes wrong
If a security incident affects your personal information or Student Data, we will notify you and your school or district without undue delay and in any event within 72 hours of becoming aware of it. The notice will describe what happened, what data was involved, what we have done, and what you should do.
Password creation. Classwise AI supports email and password registration and sign-in, as well as sign-in through Google or Microsoft. The registration form requires passwords of at least 12 characters, including an uppercase letter, a number, and a special character.
Two-step authentication. Multi-factor authentication is required to access Internal Settings. Educators may also access Classwise AI through supported LTI 1.3 launches from their LMS. When you sign in through Google or Microsoft, your identity provider manages authentication under its own policies.
We retain your account information for as long as your account is active, subject to the inactive-account limit below.
Inactive accounts. If an account has not been accessed for 12 months, we will notify the account holder and then permanently delete the account and all data associated with it within 60 days.
Backups. Deletion reaches our backups. Backups are overwritten on a 14-day cycle, so every copy is gone within 60 days of the deletion request.
Analytics records. PostHog retains usage events and session recordings for periods set by our plan and configuration, as described in Appendix A.
Regardless of your location, we believe you should have control over your personal information. You have the following rights:
Decline third-party sharing. Apart from the third parties strictly necessary to run the Services — hosting, storage, and, if you use the grading features, our AI service providers — you can decline sharing with any third party in Appendix A from your account settings, and keep full access to the Services. A school or district administrator can set this once for all of their users.
Advertisers. We share nothing with advertisers, so there is nothing here to opt out of. We do not sell or share personal information, as those terms are defined under California law, and we do not use or disclose it for cross-context behavioural advertising. If that ever changed we would give you 30 days' notice and a working opt-out before it took effect.
For Users in Certain Jurisdictions (e.g., EEA, UK, California):
You may have additional rights, subject to local laws:
To exercise any of these rights, please contact us at hello@classwise.ai.
We respond to these requests within 30 days and do not charge for them. The choices listed above this paragraph are available to everyone, everywhere, and do not depend on where you live.
Legal Basis for Processing (for EEA/UK Users):
If you are in the European Economic Area (EEA) or the UK, our legal basis for collecting and using your personal information is:
Classwise AI is based in the United States, and our servers are located in the United States. If you are accessing our Services from another country, please be aware that your information will be transferred to, stored, and processed in the U.S.
Some browsers offer a "Do Not Track" (DNT) signal. Because we do not track you across websites and neither serve nor permit advertising, there is no cross-site tracking for a DNT signal to switch off. We honour Global Privacy Control (GPC) signals as a valid request to opt out of any sharing of personal information.
Students may interact directly with features of the Services, which collect information they provide and process it with relevant assessment context. Student Data is covered by this policy for all accounts and by a DPA where one has been executed. The authorization requirements for children under 13 are described in Section 1A.
If we learn that a child’s personal information was collected without required authorization, we delete it within 30 days and notify the relevant school or educator. Parents and guardians may request access or deletion through their school or educator, or contact hello@classwise.ai.
No third-party advertisements. We display no third-party advertisements or sponsored content in the Services. Our own educator marketing emails are described in Section 4.
No student advertising. We do not use Student Data for advertising or marketing. Educator email audiences may be selected as described in Section 4; we do not use personal information for cross-context behavioural advertising.
No third-party ad tracking. No third party tracks or collects information about you or your students through our Services for advertising. We use no ad networks, no advertising partners, no advertising cookies, and no cross-site tracking.
No ad tracking technologies. We use no advertising SDKs or device fingerprinting. Product analytics is described in Section 2C;
Nothing goes to advertisers. We share no data with any advertiser or ad network. We do not sell or share personal information for cross-context behavioural advertising. This applies to you automatically; you need do nothing to claim it. To confirm it in writing, contact hello@classwise.ai.
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you by email or through the Services.
Adding, replacing, or removing any third party in Appendix A is always a significant change. We will tell you by email and in the Services at least 30 days before such a change takes effect, and we will hold the incoming third party to the same data protection terms as the one it replaces.
If you have any questions about this Privacy Policy, please contact us at:
Classwise AI, Inc.
hello@classwise.ai
Referenced by Sections 1B, 3, 5, 6, 8, 9 and 12.
| Third party | Data it receives | Why | Where | How long it keeps it |
|---|---|---|---|---|
| Stripe | Name, email, billing address, payment card details (entered directly with Stripe) | Processing subscription payments | US | For the service term and longer where payment or legal rules require; no fixed public period |
| Vercel | IP address, request metadata for the client application | Hosting the web application | US | Runtime logs: 30 days |
| Railway | All data processed by the server application in transit through it | Hosting the server application | US | 90 days |
| Supabase | Account information, profile fields, saved feedback, uploaded submissions, Student Data | Database and file storage | US | 14 days backups |
| PostHog | Account and educator profile identifiers, name, email, usage events, errors, session recordings, AI diagnostics, IP/browser/device details; potentially Student Data | Product analytics and error diagnostics | US | 30 days |
| OpenAI | Submission text or images and grading context, including rubrics; submitted material may contain student identifiers. | Generating scores and written feedback | US | Abuse logs: up to 30 days |
| Submission and grading context; for Student Tutor, the student’s first name, score, feedback, submission context, and messages. | Generating scores, feedback, and Student Tutor responses | US | Gemini API prompts, context, and outputs: 55 days for abuse monitoring | |
| Anthropic | Submission text or images and grading context, including rubrics; submitted material may contain student identifiers. | Generating scores and written feedback | US | Inputs and outputs generally deleted within 30 days |
| Postmark | Recipient names and email addresses, email content, delivery status, and newsletter open and link-click events | Delivering service and marketing emails; measuring newsletter engagement | US | 45 days |
Referenced by Section 3.
| Cookie or storage key | Purpose | Whose | Lasts | Essential? |
|---|---|---|---|---|
| sb-*-auth-token (and numbered chunks) | Keeps you logged in as you move around the app | Classwise AI domain (Supabase Auth) | Up to 400 days in browser; session may end sooner | Yes — the Services cannot run without it |
| sb-*-auth-token-code-verifier | Completes secure sign-in | Classwise AI domain (Supabase Auth) | Removed after sign-in; up to 400 days if incomplete | Yes |
| Classwise preference keys (local storage) | Remembers your interface preferences | Classwise AI | Until cleared; some settings expire sooner | No |
| ph_*_posthog | Stores identifiers for analytics and session replay | Classwise AI domain (PostHog SDK) | 30 days, refreshed on use | No |