Privacy Policy

Effective August 11, 2026 · Version 2.2

NUDGELEARN LLC ("we", "us", "our") operates the NudgeLearn Graderat nudgelearn.app, which teachers and parents use to grade student work. This policy explains what data it collects, how we use it, and your rights. We take children's privacy seriously; section 7 lists the student-privacy laws we hold ourselves to and how.

What we never do

  • We never sell student work, student names or any other personal information
  • We never use student work for advertising, and we run no ad networks or ad trackers
  • We never build advertising or behavioral profiles of students
  • We never collect facial recognition or other biometric data
  • We never set cookies on, or collect IP addresses or device fingerprints from, students. Students have no accounts and never sign in
  • We never give student work to another company to train its models

1. Who uses NudgeLearn

The Grader. Teachers and parents upload photos, scans or files of completed student work: worksheets, tests and essays. We grade that work and return marks, corrections and feedback. When a teacher or school uses the Grader, we process student work on their behalf, as their service provider, for the educational purpose of grading, and under their direction. Students do not have accounts and never sign in.

Schools and FERPA. When a school or district uses the Grader, we act as a school official with a legitimate educational interest under FERPA (34 CFR 99.31(a)(1)(i)(B)). We are under the direct control of the school with respect to the student records we handle, we use them only for the grading purpose the school directs, and we do not redisclose them to anyone except the sub-processors listed in section 5. The school remains the owner of its student data and can require its return or deletion at any time. We will sign a data processing agreement on request: see our Data Processing Addendum.

2. What we collect

From the Grader (teachers and parents)

  • The photo, scan or file of the student's work that a teacher or parent uploads, which may include a name written on the page
  • The problems transcribed from the page, the student's written answers, the correct answers, and the resulting score
  • For essays: the transcribed text of the essay, the rubric it was scored against, and the per-criterion scores and feedback
  • For teachers using class features: student names, optional notes, optional student email addresses for returning work, and the class or assignment labels the teacher enters to organize grades
  • Corrections a teacher makes to a grade, so the score on record is the teacher's and not ours

From any account holder

  • Email address (used for sign-in)
  • Timezone preference
  • Subscription and billing status via Stripe. We never store card numbers

3. How we use it

  • Grade a photo, scan or file of a student's work and place marks on it, using AI (Anthropic Claude) with text recognition (Google Cloud Vision)
  • Score essays against the rubric the teacher chose, and write per-criterion feedback
  • Organize grades into the classes and assignments the teacher created, and return marked work to the student when the teacher sends it
  • Process subscription payments (via Stripe)
  • Send sign-in codes and magic-link emails (via Resend)

We do not sell data, use it for advertising, or share it with third parties beyond the service providers listed in Section 5. We do not load advertising or analytics trackers on Grader pages or any page that displays student work.

4. Data retention

Data typeRetention
Grader uploads & graded results (Free plan)Kept while your account is active; papers auto-delete 90 days after upload (your 50 most recent are kept). Delete any paper on demand
Grader uploads & graded results (paid plans)Kept until you delete the paper or your account; deleting your account purges all grader data
Student names, class and assignment labelsKept while the class exists; deleted with the class or the account
Account data (teacher or parent)Kept while the account is active; deleted within 30 days of account deletion
Billing recordsPer Stripe's retention policy (7 years, tax and accounting)

Our full written Data Retention Policy details the business justification for each retention period and the deletion mechanisms used.

5. Service providers

We share data only with the following providers, solely to operate the service:

  • Anthropic: AI grading. Receives the uploaded image of the student's work. Per Anthropic's commercial terms, this data is not used to train its models.
  • Google Cloud Vision: Text recognition (receives the uploaded image of the student's work to locate the handwriting). Under Google Cloud's terms this content is not used to train or improve Google's models and is not retained after the request is served
  • Resend: Transactional email (the account holder's email address, and any student email address a teacher enters to return work)
  • Stripe: Payment processing (billing info only; we never see card numbers)
  • Neon: Database hosting (all structured data, stored in the US)
  • Railway: Application hosting (processes data in the US)

6. Children's privacy (COPPA)

  • Students have no accounts, never sign in, and never provide us information directly. Everything we hold about a student was uploaded or entered by their teacher or parent
  • When a school or teacher uses the Grader for a classroom purpose, they authorize the collection on the parents' behalf, as COPPA permits for school-directed educational services
  • When a parent uses the Grader for their own child, the parent is the account holder and provides the information themselves
  • We collect no more than grading requires: no age, no address, no phone number, no contact information for a student unless a teacher enters an email address to return work
  • A teacher or parent can review, correct, export or delete a student's work at any time from the app, or by emailing us
  • We do not condition use of the Grader on disclosing more information than necessary

7. Compliance

We operate the Grader to meet the student-privacy laws that apply to a service that works the way it does:

  • FERPA(20 U.S.C. 1232g, 34 CFR Part 99). Where a school or district uses the Grader, we act as a school official with a legitimate educational interest under 34 CFR 99.31(a)(1)(i)(B): under the school's direct control, using the records only for the purpose it directs, and never redisclosing them. The school owns the data and can require its return or deletion at any time.
  • COPPA (16 CFR Part 312), including the amendments effective April 22, 2026. Students never provide us anything directly and hold no accounts, so collection happens through the teacher, parent or school that authorizes it. We publish a written Data Retention Policy with a deletion timeline for every category we hold, we name every third party that receives data in section 5, we collect no biometric identifiers, and we retain nothing indefinitely.
  • California SOPIPA(Cal. B&P Code 22584) and comparable state student-privacy laws. We do not sell student information, serve targeted advertising, or build advertising or behavioral profiles of students.
  • New York Education Law 2-d, where the school is subject to it: no sale or commercial use of student data, security controls in section 9, and breach notice to the school.
  • State and district agreements.We will sign a district's own data privacy agreement, including the NDPA standard form used by the Student Data Privacy Consortium. Our starting point is the Data Processing Addendum.

These statements are based on our interpretation of what each law requires of a service built the way the Grader is built.

8. Your rights

  • Access: request a copy of the data we hold about you or a student
  • Deletion: delete any paper from the app, or delete your account and all associated data, from the dashboard or by emailing us
  • Correction: change a grade, a student name or a class label in the app at any time
  • Portability: export your grades and graded work

Where a school or district is the account holder, requests about a student go through the school, since the school holds the education record. We support the school in meeting them.

9. Security

  • In transit: TLS 1.2 or higher on every request (HTTPS only), with HTTP Strict Transport Security enforced
  • At rest: all structured data, including graded work, is stored in our US database (Neon) and encrypted at rest with AES-256 by the provider
  • Access: database credentials and API keys are held as environment secrets, never committed to code. Sessions are JWTs with no persistent session store
  • Automatic purges: Free-plan papers auto-delete 90 days after upload
  • Browser hardening: nosniff, SAMEORIGIN framing, a restrictive referrer policy and a permissions policy that allows only the camera the Grader needs

If there is a breach. If student data we hold is exposed, we will notify the affected school or account holder within 72 hours of confirming it, describe what was affected and what we are doing about it, and support any notification the school itself has to make.

Information security responsibility: Our designated information security contact can be reached at hello@nudgelearn.app.

10. Changes to this policy

We will notify account holders by email before making material changes to this policy. Continued use after notice constitutes acceptance.

11. Contact

Privacy questions, access, export or deletion requests, and district data-protection paperwork all go to hello@nudgelearn.app, attention Privacy. We acknowledge every request within 3 business days and complete it within 15 business days. Schools asking for a signed agreement should start with our Data Processing Addendum.