Privacy
Privacy Policy
Effective date: August 5, 2026 · Last updated: September 23, 2026
Plain-language summary
GradeLikeMe is designed for faculty and authorized adult users. We ask users not to submit student names, identification numbers, email addresses, contact information, or other information that could identify an individual student. GradeLikeMe does not sell personal information. AI-generated feedback is intended to assist instructors and does not replace professional judgment.
1. Who operates GradeLikeMe
GradeLikeMe is an independent business based in California, United States. You can reach us at hello@gradelikeme.com for privacy questions or hello@gradelikeme.com for support. We do not publish a street address for this small independent business; a mailing address will be provided where it is required for a valid legal or regulatory purpose.
2. Scope of this policy
This policy covers the GradeLikeMe website and application. It does not cover your institution's systems, your learning management system, or any third-party site you reach from here. Where your institution has its own agreement with you about student records, that agreement continues to apply.
3. Information you supply
- Account information: your email address and authentication credentials, or the basic account details Google returns if you use Google sign-in.
- Grading preferences: display name, discipline, teaching-voice notes, default tone, style, and length, feedback guidance, and grading rules.
- Assignment setups: course, assignment name, instructions, total points, and rubric criteria with descriptors.
- Support and privacy communications you send us, including anything you type into a request form.
- Billing information related to a paid subscription: your billing email, the plan you chose, and subscription and renewal status. Full payment-card details are entered with our payment provider at checkout and are never received or stored by GradeLikeMe.
4. Content submitted for processing
When you paste or upload work for review, that text is held in your browser for the session and transmitted to the AI provider listed below for the duration of the drafting request. We ask you to submit de-identified work only. The application does not write submitted work, generated drafts, or scores to its database.
5. Information collected automatically
Like most web applications, technical information is generated when you use GradeLikeMe: IP address, browser and device characteristics, timestamps, diagnostic and error logs, authentication events, and essential cookies. Approximate location may be inferred from an IP address by our hosting provider. Our hosting, edge, and security providers process standard technical request information as needed to deliver, secure, diagnose, and prevent abuse of the service. Those providers keep their own technical records under their own terms and retention practices; we do not set or independently verify those retention periods, so we do not state them here.
We also keep a technical record of each AI request made from your account: which operation ran, which model, how many tokens it used, how long it took, an estimated processing cost, and a random per-submission identifier used only to group the requests about one submission. These records let us run the service, count submissions against your plan allowance, and apply fair use. They never contain student work, assignment or rubric text, generated feedback, scores, or any student identifier.
5a. Plan, submission allowance, and fair use
Your account stores your plan, how access is granted, your submission allowance, and one row per submission that used your allowance — the random submission identifier and a timestamp only. We also store per-feature usage counts for features that are limited on the free experience. We use these to enforce your submission and feature allowances and to detect automated or shared use that would put the service at risk. Any resulting pause on AI drafting is temporary and reviewable, and we do not build advertising or profiling profiles from this data.
6. Why we process this information
- To create and secure your account and keep you signed in.
- To save and sync your assignment setups, rubrics, and grading preferences.
- To generate the draft feedback and rubric structure you request.
- To keep records of the policy version you accepted and of privacy requests you file.
- To detect, investigate, and prevent abuse, fraud, and security incidents.
- To respond to support requests and to fix defects.
- To meet legal obligations and to establish or defend legal claims.
We rely on performing our agreement with you, our legitimate interest in operating and securing the service, your consent where you gave it, and compliance with law.
7. Vendors and subprocessors we actually use
Lovable
Application build, hosting, and the AI gateway that routes model requests
Information involved: Requests to the application, diagnostic logs, and the text sent for AI drafting while a request is in flight
Lovable's published documentation states that end-user data from deployed applications is not used to train Lovable's AI models. Lovable keeps operational and diagnostic records under its own terms; we do not set those retention periods.
Supabase (provided through Lovable Cloud)
Account authentication and the database that stores assignment setups, rubrics, preferences, consent records, and privacy requests
Information involved: Email address, authentication events, assignment/rubric/preference records, consent records, privacy request records
Google — Gemini model family (accessed through the Lovable AI gateway)
Generates draft feedback and converts pasted rubric text into structured criteria
Information involved: The assignment, rubric, grading preferences, and the submitted work text for the duration of the request
Retention and model-training treatment on the provider side is governed by the provider's own terms, which we do not control. We make no claim of zero retention and no claim of training; review the applicable provider terms and send de-identified work only.
Google — Sign-in (OAuth)
Optional 'Continue with Google' sign-in
Information involved: Email address and basic account identifiers returned by Google when a user chooses Google sign-in
Paddle.com (Merchant of Record and payment provider)
Processes subscription orders and renewals, calculates and remits tax, issues invoices and receipts, and handles refunds, chargebacks, and payment fraud prevention
Information involved: Name, billing email, billing country/address, tax identifiers where relevant, payment-method details entered at checkout, and subscription status. GradeLikeMe receives only billing email, plan, and subscription status — never full card details
Google Fonts
Serves the site typefaces
Information involved: IP address and browser information are visible to the font host when a page loads
Google Ads (advertising measurement)
Measures whether our own Google Ads campaigns lead to sign-ups and subscriptions
Information involved: Page-visit information the site-wide Google tag makes visible to Google (such as IP address and browser details), and — sent only after a checkout completes successfully — the purchase event: the amount charged, the currency, and the Paddle transaction identifier
Used to measure our own advertising. It is not used to serve third-party ads inside the application, and no student work, rubric, feedback draft, or score is ever shared with it.
Cloudflare (edge runtime used by the hosting platform)
Runs server-side application code and serves requests
Information involved: Network-level request metadata such as IP address and timestamps
Serves and secures requests at the network edge, so processing may occur in the region closest to the person making the request. Network-level records are kept under the provider's own terms.
8. AI providers and model training
Draft feedback and rubric extraction are produced by a Google Gemini model reached through the Lovable AI gateway. The text you send is transmitted for the duration of the request so the model can return a draft. GradeLikeMe does not store submitted student work, generated drafts, or scores, and we do not use your content to train any model of our own.
Lovable's published documentation states that end-user data from deployed applications is not used to train Lovable's AI models. That statement is about Lovable. It is separate from the retention and training terms of the underlying model provider, which we do not control and have not independently verified. For that reason we do not claim a specific provider-side retention period, and we do not claim provider-side zero retention. If provider-side treatment matters to you, review the current privacy and data-processing terms of Lovable and of Google's Gemini API before submitting content, and send only de-identified work as this policy asks.
Our own AI usage records contain operational metadata only: which operation ran, which model, token usage, how long the request took, an estimated processing cost, and a random per-submission identifier. They do not contain submitted student content, assignment or rubric text, generated feedback, scores, or student identifiers.
9. Payments and our Merchant of Record
Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns.
Paddle.com acts as reseller and Merchant of Record for paid GradeLikeMe subscriptions. When you buy or renew a subscription, Paddle.com collects and processes the information needed to complete the sale — your name and billing email, billing address or country, tax identifiers where relevant, and your payment-method details — and uses it for payment processing, subscription management and renewals, invoicing and receipts, tax calculation and remittance, refunds and chargebacks, fraud prevention, and related payment and accounting services. Paddle.com handles this information as its own controller for those purposes, under its own privacy notice.
GradeLikeMe receives only what it needs to give you the right access: your billing email, the plan and billing period you chose, subscription status, and renewal or cancellation dates. We do not receive or store full payment-card numbers, card security codes, or bank credentials. We share your account email and account identifier with Paddle.com so your purchase can be matched to your account, and we may exchange information with it to resolve a billing question, refund, or dispute.
Student work, generated feedback, and scores are never shared with the payment provider.
10. What is stored, and where
Stored in our database
- Account email address and authentication records (held by the authentication provider).
- Grading profile: display name, discipline, teaching-voice notes, default tone, style, length, feedback guidance, and grading rules.
- Assignment setups: course, assignment name, instructions, total points, rubric criteria and descriptors, and feedback settings.
- Consent records: the policy version accepted, which documents were acknowledged, an optional marketing choice, and a timestamp.
- Privacy and support requests you submit through the app: the request type, your message, and a timestamp.
Not written to our database
- Submitted student work is not written to the database by the application. It is held in your browser during the session and sent to the AI provider only for the duration of a drafting request.
- Generated feedback drafts are not written to the database by the application.
- Scores or grades you enter are not written to the database by the application.
Account and application records are held in a managed Supabase database provided through Lovable Cloud, hosted on Amazon Web Services infrastructure in Canada (the ca-central-1 region). Server-side application code runs on our hosting platform's edge network, so a request may be handled in the region closest to you, and our service providers may process information in other jurisdictions to deliver their services.
11. Retention
Account records, grading preferences, assignment setups, consent records, privacy requests, and our AI usage metadata are kept while your account is active. When you delete your account from the app, those account-associated application records and usage records are deleted along with the account.
One exception: records of payment events may survive account deletion after the link to your account is removed. These de-identified billing and payment-event records may be retained for up to seven years where reasonably necessary for tax, accounting, refund, fraud-prevention, dispute, or legal-compliance purposes.
Deletion removes information from the active GradeLikeMe account and database through the application's deletion process. Residual copies may remain temporarily in vendor-managed backups, diagnostic systems, or security systems, according to those providers' own retention practices and legal obligations.
12. Your choices and requests
You can review and edit your grading profile and assignment setups in the app at any time. You can also request access, correction, an export, or deletion, and report a privacy or security concern, from the Contact, Data Access & Deletion page. We verify identity by requiring you to be signed in to the affected account before completing a request, and we do not send personal information to an unverified email address. Some information may be retained where needed for legal obligations, billing records, fraud prevention, or security.
13. Selling, sharing, and advertising
We do not sell personal information. We do not run third-party advertising inside the application, and we do not share personal information for cross-context behavioral advertising.
We do advertise GradeLikeMe ourselves, and we measure whether our own ads lead to sign-ups and subscriptions using Google Ads conversion measurement, which acts as a service provider for this advertising measurement. The site-wide Google tag makes standard technical visit information (such as IP address and browser details) visible to Google. After a checkout completes successfully, a purchase event is sent to Google with the amount charged, the currency, and the order's transaction identifier — never on a page visit or a click alone, and never with student work, a rubric, a feedback draft, or a score. Google is listed among the vendors in Section 7.
14. Cookies and analytics
The application uses essential cookies and similar browser storage for authentication and security. The site-wide Google tag (Google Ads) is also present and is used for the advertising measurement described in Section 13. Details are in the Cookie Notice.
15. Security
We use access controls scoped to your account at the database level, encrypted connections provided by our hosting and database providers, and server-side handling of API credentials so they are never exposed to the browser. No system is completely secure, and we do not claim that GradeLikeMe is. We have not completed an independent security audit or certification.
16. International transfers
GradeLikeMe is operated from the United States. Our primary database infrastructure is currently hosted in Canada, and our service providers may process information in additional jurisdictions in order to deliver hosting, authentication, AI drafting, payment, and security services. Using GradeLikeMe therefore involves cross-border processing of the limited information described in this policy.
Each provider may apply contractual, organizational, or other legally recognized transfer safeguards as applicable under its own terms and applicable law. We do not claim any specific transfer mechanism, certification, or regional guarantee on their behalf, and we do not represent that a particular adequacy or contractual mechanism is in place unless we have verified it.
17. Privacy rights and requests
Depending on where you live, you may have rights to know, access, correct, delete, obtain a copy of, or limit certain uses of your personal information, and to be free from discrimination for exercising those rights. Rather than limiting these to particular jurisdictions, GradeLikeMe accepts reasonable access, correction, deletion, and copy/data-access requests from any user regardless of residency, submitted through the data request page. We may need to verify your identity before acting, and we may decline or limit a request where a legitimate legal, security, or retention obligation applies — in which case we will tell you why.
18. Children's privacy
GradeLikeMe is intended for faculty and other authorized adults. Accounts are for people 18 or older. The service is not directed to children, and we ask that no student-identifying information — of any age — be submitted. If you believe a child provided information to us, contact hello@gradelikeme.com and we will remove it.
19. Changes to this policy
We will update this page and the "Last updated" date when this policy changes. Material changes will be communicated in the application.
20. Contact
Privacy: hello@gradelikeme.com · Support: hello@gradelikeme.com · Mail: Available upon valid legal request
This document is an initial business document prepared by the operator. It is not legal advice and has not been reviewed by an attorney. Obtain attorney review before accepting paid or institutional customers.