Privacy Policy - EasyClass AI
Introduction
EasyClass AI ("EasyClass," "we," "us," or "our") is committed to protecting the privacy of our users, including teachers, school administrators, and the students they serve. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our website at easyclass.ai and our educational technology platform (collectively, the "Service").
We are committed to complying with the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
Contact Information:
- Privacy Inquiries: privacy@easyclass.ai
- General Support: support@easyclass.ai
Table of Contents
1. Information We Collect
1.1 Teacher/Administrator Account Information
When you create an account, we collect:
- Email address
- Full name
- Password (encrypted)
- School or organization name (optional)
- Grade levels taught
- Subject areas
- Role (teacher, administrator, substitute, tutor)
1.2 Subscription and Payment Information
When you subscribe to a paid plan, we collect:
- Billing name and address
- Payment method details (processed securely by Stripe)
- Transaction history
We do not store complete credit card numbers on our servers. Payment processing is handled entirely by Stripe, Inc.
1.3 Content You Create
Teachers may create and store:
- Lesson plans
- Quizzes and assessments
- Assignments and worksheets
- Rubrics and grading criteria
- Display boards and presentations
- Notes and pages
- AI-generated educational content
1.4 Student Data (Collected via Teacher-Created Content)
When teachers create shareable content (quizzes, assignments, spiral reviews), we collect from students:
- Student name (as entered by the student for identification)
- Answers and responses to questions
- Submission timestamp
- Anonymized IP address (hashed for duplicate detection only, not stored in identifiable form)
- Score and performance data
Important: Student data is collected on behalf of teachers for educational purposes. Teachers are responsible for obtaining appropriate consent from students and/or parents as required by their school's policies.
1.5 Grading and Assessment Data
When using our AI grading features:
- Student work/submissions (text, uploaded documents)
- Teacher-provided rubrics and criteria
- AI-generated feedback and scores
- Grade adjustments made by teachers
1.6 Google Classroom Integration Data
When you connect your Google Classroom account:
- Course names and IDs
- Assignment names and IDs
- Student submission content (for grading purposes)
- We sync grades back to Google Classroom at your direction
We do not permanently store Google Classroom student email addresses. We access this data temporarily to facilitate grading and grade sync.
1.7 Usage and Analytics Data (Teachers Only)
For teacher accounts, with consent, we collect:
- Pages visited and features used
- Session duration and frequency
- Device type and browser information
- Referral source
We do not collect analytics data on student-facing pages. Students taking quizzes, assignments, or spiral reviews are never tracked by our analytics systems.
2. How We Collect Information
2.1 Information You Provide
- Account registration forms
- Profile settings
- Content creation tools
- Customer support communications
- Survey responses
2.2 Information Collected Automatically
- Server logs (IP addresses are hashed)
- Cookies (with your consent)
- Analytics data (teacher pages only, with consent)
2.3 Information from Third Parties
- Google (when you use Google Sign-In or connect Google Classroom)
- Stripe (payment confirmation, not full card details)
- Referral partners (referral code usage)
3. How We Use Your Information
3.1 To Provide the Service
- Create and manage your account
- Process and store your educational content
- Enable AI-powered content generation and grading
- Facilitate student assessment and feedback
- Sync with Google Classroom
- Process payments and subscriptions
3.2 To Improve the Service
- Analyze usage patterns (teachers only, with consent)
- Develop new features
- Fix bugs and technical issues
- Optimize performance
3.3 To Communicate With You
- Service announcements and updates
- Customer support responses
- Marketing communications (with consent, opt-out available)
- Transactional emails (receipts, password resets)
3.4 For Safety and Compliance
- Prevent fraud and abuse
- Enforce our Terms of Service
- Comply with legal obligations
- Respond to legal requests
4. Student Data and Educational Records
4.1 Our Role
EasyClass acts as a "school official" under FERPA, providing services on behalf of teachers and schools. We process student data solely for educational purposes as directed by teachers.
4.2 What Student Data We Collect
| Data Type | Purpose | Retention |
|---|---|---|
| Student name | Identify submissions to teacher | 90 days or until deleted |
| Answers/responses | Assessment and grading | 90 days or until deleted |
| Scores | Academic record | 90 days or until deleted |
| Hashed IP | Duplicate detection only | 90 days |
4.3 What We Do NOT Collect from Students
- Email addresses (not required for quizzes/assignments)
- Home addresses
- Phone numbers
- Social Security numbers
- Biometric data
- Precise geolocation
- Browsing history or behavioral tracking
4.4 How Student Data is Protected
- Encrypted in transit (TLS/HTTPS) and at rest
- Isolated per teacher (Row Level Security)
- Never sold or used for advertising
- Never used to build student profiles
- Automatically deleted after 90 days or when content expires
- Teachers can delete all student responses at any time
4.5 AI Processing of Student Work
When teachers use AI grading:
- Student work is sent to our AI provider for analysis
- Student names are NOT sent to AI - work is anonymized before processing
- Our AI provider (OpenRouter) has Zero Data Retention enabled
- AI does not learn from or retain student submissions
5. AI-Powered Features and Data Processing
5.1 AI Content Generation
Teachers can use AI to generate:
- Lesson plans
- Quizzes and assessments
- Worksheets and activities
- Rubrics
- Reading passages
- And 80+ other educational tools
Data sent to AI: Teacher prompts, subject/grade level, topic information.
Data NOT sent: Student PII, student names, student email addresses.
5.2 AI Grading
When grading student work:
- Student submission text is sent to AI
- Rubric criteria is sent to AI
- Student names are removed before AI processing
- AI returns scores and feedback
- Teacher reviews and can adjust grades
5.3 AI Provider
We use OpenRouter as our AI routing service, which may process requests using various AI models (Claude, GPT-4, etc.).
- Zero Data Retention is enabled
- AI providers do not train on your data
- Processing occurs in the United States
6. Cookies and Tracking Technologies
6.1 Our Cookie Consent System
We ask for your consent before placing non-essential cookies. You can manage preferences at any time through our cookie consent banner or in your account settings.
6.2 Cookie Categories
Essential Cookies (Always Active)
- Authentication tokens (Supabase)
- Cookie consent preferences
- Session management
Analytical Cookies (With Consent)
- Google Analytics - understand how teachers use the platform
- PostHog - product analytics for improvements
Marketing Cookies (With Consent)
- TikTok Pixel - measure advertising effectiveness
6.3 Student Pages - No Tracking
We do not place any tracking cookies or run any analytics on student-facing pages, including:
- /quiz/* (student quiz taking)
- /assignment/* (student assignment submission)
- /spiral-review/* (student spiral review)
This ensures COPPA compliance and student privacy.
6.4 Managing Cookies
- On first visit: Cookie consent banner appears
- Change preferences: Click "Manage Cookies" in account settings or website footer
- Browser settings: You can also block cookies in your browser
7. Information Sharing and Disclosure
7.1 We Do NOT Sell Your Data
We do not sell, rent, or trade personal information to third parties for their marketing purposes. This applies to both teacher and student data.
7.2 Service Providers
We share data with trusted service providers who help us operate:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database and authentication | Account data, content |
| Stripe | Payment processing | Billing information |
| OpenRouter | AI processing | Anonymized content for AI features |
| Resend | Email delivery | Email addresses for transactional emails |
| Netlify | Hosting | Server logs |
| Classroom integration | As authorized by you |
All service providers are contractually bound to protect your data and use it only for the services they provide to us.
7.3 Legal Requirements
We may disclose information if required by law, such as:
- Court orders or subpoenas
- Government requests
- To protect our rights or safety
- To investigate fraud or security issues
7.4 Business Transfers
If EasyClass is acquired or merged, your information may be transferred. We will notify you before any material changes to how your data is handled.
7.5 With Your Consent
We may share information for other purposes with your explicit consent.
8. Data Retention
8.1 Teacher Account Data
- Active accounts: Retained while your account is active
- After deletion: Permanently deleted within 30 days
- Inactive accounts: We may delete accounts inactive for 2+ years after notice
8.2 Student Response Data
- Default retention: 90 days from submission
- Content expiration: Deleted when quiz/assignment expires
- Manual deletion: Teachers can delete student responses anytime
- Account deletion: All student data deleted when teacher deletes account
8.3 Payment Records
Retained for 7 years for tax and legal compliance
8.4 Server Logs
- IP addresses are hashed immediately
- Logs retained for 90 days for security purposes
9. Data Security
9.1 Technical Safeguards
- Encryption in transit: All data transmitted via TLS/HTTPS
- Encryption at rest: Database encryption enabled
- Access control: Row Level Security ensures users only access their own data
- Authentication: Secure password hashing, optional two-factor authentication
- Infrastructure: Hosted on secure, SOC 2 compliant platforms
9.2 Organizational Safeguards
- Limited employee access to production data
- Security awareness training
- Incident response procedures
- Regular security reviews
9.3 Breach Notification
In the event of a data breach affecting your information, we will:
- Notify affected users within 72 hours
- Notify relevant authorities as required by law
- Provide information about the breach and steps taken
10. Your Rights and Choices
10.1 Access Your Data
You can access your data by viewing your profile and content in the app, or by exporting all your data as JSON (Settings → Privacy Controls → Export My Data).
10.2 Correct Your Data
You can update your profile information at any time in Settings.
10.3 Delete Your Data
Delete Student Responses: Settings → Privacy Controls → Delete Student Data
(Removes all student responses while keeping your content)
Delete Your Account: Settings → Privacy Controls → Delete Account
(Permanently deletes your account and all associated data)
10.4 Data Portability
You can export all your data in a machine-readable JSON format.
10.5 Cookie Preferences
Manage cookie settings through our consent banner or Settings → Privacy Controls → Manage Cookies.
10.6 Marketing Opt-Out
Unsubscribe from marketing emails using the link in any email, or contact support@easyclass.ai.
11. Children's Privacy (COPPA Compliance)
11.1 Our Approach
EasyClass is designed for teachers and schools. We do not knowingly collect personal information directly from children under 13 without appropriate consent.
11.2 School Consent Model
Under COPPA, schools may consent on behalf of parents for the collection of student information for educational purposes. When teachers use EasyClass to collect student responses:
- Teachers represent they have authority to consent on behalf of students/parents
- Data is collected solely for educational purposes
- Teachers can delete student data at any time
11.3 Student Information Collected
For students (including those under 13):
- Name (as entered for assignment identification)
- Answers and responses
- Scores
We do NOT collect from students:
- Email addresses
- Photos or videos
- Precise location
- Persistent identifiers for tracking
11.4 No Behavioral Advertising
We never use student data for advertising or behavioral targeting. Student pages have no analytics or tracking.
11.5 Parental Rights
Parents may contact their child's teacher or school to:
- Review their child's data
- Request deletion of their child's data
- Withdraw consent for data collection
Teachers can facilitate these requests through their EasyClass account.
12. FERPA Compliance
12.1 School Official Exception
EasyClass operates under the "school official" exception to FERPA. We:
- Provide services that the school would otherwise perform
- Are under the direct control of the school regarding use of education records
- Use education records only for authorized purposes
- Do not re-disclose information without authorization
12.2 Education Records
Student responses and grades in EasyClass may constitute education records under FERPA. These records:
- Are accessible only to the teacher who created the content
- Are not shared with other teachers or schools
- Are not used for any purpose other than education
- Can be exported or deleted by the teacher
12.3 Annual Notification
Schools using EasyClass should include us in their annual FERPA notification to parents as a school official with access to education records.
13. International Data Transfers
13.1 Data Location
Our servers are located in the United States. If you access EasyClass from outside the US, your data will be transferred to and processed in the US.
13.2 EU Users
For users in the European Economic Area, we rely on:
- Your consent
- Standard contractual clauses with service providers
- Necessity for contract performance
14. California Privacy Rights (CCPA)
14.1 Your Rights
California residents have the right to:
- Know what personal information we collect
- Delete your personal information
- Opt-out of the sale of personal information (we don't sell data)
- Non-discrimination for exercising your rights
14.2 How to Exercise Rights
- Email: privacy@easyclass.ai
- Use the in-app data management tools
14.3 Do Not Sell
We do not sell personal information. We have not sold personal information in the preceding 12 months.
15. European Privacy Rights (GDPR)
15.1 Legal Basis for Processing
| Purpose | Legal Basis |
|---|---|
| Provide the Service | Contract performance |
| Process payments | Contract performance |
| Send service emails | Legitimate interest |
| Marketing emails | Consent |
| Analytics (teachers) | Consent |
| Security and fraud prevention | Legitimate interest |
15.2 Your Rights
Under GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent
15.3 Data Protection Officer
For GDPR inquiries: privacy@easyclass.ai
15.4 Supervisory Authority
You have the right to lodge a complaint with your local data protection authority.
16. Third-Party Services
16.1 Google Integration
When you connect Google Classroom or use Google Sign-In, Google's Privacy Policy applies to data processed by Google. We access only the data necessary to provide our services.
16.2 Links to Other Sites
Our Service may contain links to third-party websites. We are not responsible for their privacy practices.
16.3 Third-Party Service Providers
Our key service providers and their privacy policies:
- Supabase: https://supabase.com/privacy
- Stripe: https://stripe.com/privacy
- Google: https://policies.google.com/privacy
- OpenRouter: https://openrouter.ai/privacy
17. Changes to This Policy
17.1 Notification of Changes
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the new policy on this page
- Updating the "Last Updated" date
- Sending an email notification for significant changes
17.2 Review
We encourage you to review this policy periodically.
18. Contact Us
Privacy Inquiries
privacy@easyclass.aiGeneral Support
support@easyclass.aiSummary of Key Points
| Topic | Summary |
|---|---|
| Student Data | Collected on behalf of teachers, never sold, deleted after 90 days |
| AI Processing | Student names removed before AI processing, Zero Data Retention enabled |
| Tracking | No tracking on student pages, cookie consent required for teachers |
| Your Rights | Export data, delete student data, delete account anytime |
| Security | Encryption, access controls, SOC 2 compliant infrastructure |
| Contact | privacy@easyclass.ai |
This Privacy Policy is effective as of December 28, 2025.