Privacy policy
Last updated October 2, 2026
The design principle: your coursework lives on your device, our servers hold the minimum needed to run your account, and nothing is ever sold. Here is exactly what that means.
1. What stays on your device
Everything the extension scrapes from Canvas: your courses, assignments, due dates, grades, syllabus text, announcements, and any notes you write. All of it is stored locally in your browser (IndexedDB). The dashboard, grade calculator, alerts, and calendar export all run entirely on your device. Apart from material you explicitly send to AI features as described in section 4, nothing here is uploaded unless you turn on desktop sync, or you press Save to my dashboard in the desktop app. Neither one happens on its own, and both are described next.
Study tips can show a YouTube search link for a topic, which can be one you missed in practice. Nothing goes to YouTube unless you click one. If you do, YouTube gets the words in that search.
Reading and display choices stay in this browser or extension unless you explicitly save a setup to your account. They include text size, spacing, reduced motion and Keep this setup. They remain after sign-out and apply to everyone using GradeGem in that browser profile. The website, desktop app and extension each keep their own local choices; saving an account copy never changes another device automatically. These controls ask for no diagnosis and do not add preferences to AI prompts.
On a shared computer, sign out in the extension's Settings with Also remove my saved classes, grades and notes from this browser checked, and those are removed from that browser. Your AI consent records stay, because they are never deleted.
2. Desktop connection and optional account sync
When you install both GradeGem apps on Windows, the extension can connect to the running desktop app on this device through the browser's native messaging permission. This local connection is on by default. Turn off Connect to desktop on this device in extension Settings to stop it, or disconnect in the desktop app. Only verified Canvas tab titles, addresses, course names and assignment names, links, due dates, submission status and module progress with observation times are shared locally for the desktop preview. Other browser tabs, cookies, grades, scores and page bodies are not shared. Cloud sync remains off by default; the local connection does not enable it or upload your preview.
Separately, you can enable Read-only Canvas sync in extension settings. While a supported Canvas page is open, this reads your own active courses, current grades, personal assignment due dates and submission status through Canvas's read-only API using your existing browser session. We do not collect an API token or send your Canvas cookies to GradeGem. Grades stay in this browser. Submission status and module progress are included in the optional desktop sync described below. It never submits coursework or marks it complete. Turning it off stops API requests; cached data remains until you clear it. A local Canvas account identifier prevents different students' records from mixing and remains bound to this browser profile when cached coursework is cleared.
If you want your courses and due dates to appear in the GradeGem desktop app, you can turn on Sync my dashboard to the desktop app in the extension's settings. While it is on, the extension uploads a small snapshot to your account after you browse Canvas: your course names, and the names, due dates, Canvas links, and (when a Canvas page said so) whether a piece of work is a quiz or a discussion, for assignments due in the next several weeks, plus submission status, module progress and their observation times. That is the whole list. It is stored as a single record tied to your account, readable only by you.
What sync never includes: your grades and scores, your private notes, your practice history, and your syllabus text. Turn the toggle off and the stored snapshot is deleted immediately. Deleting your account deletes it too. If you never turn sync on and never press Save to my dashboard, no coursework snapshot reaches our servers. Material you explicitly send to AI features is handled separately as described in section 4.
The desktop app can fill that same record a second way, for students who do not run the extension. Its Browser linkcard reads a Canvas tab you already have open, on your own machine, and shows you what it found; nothing leaves the machine until you press Save to my dashboard. With the extension connection, that first save also enables automatic updates for this GradeGem account and school while connected. Disconnect stops those updates. That press uploads the same short list described above, your course names plus the names, due dates, and Canvas links of assignments, into the same single record. It only reads: it never clicks, fills in, or submits anything in Canvas, and it takes no grades or scores.
If the browser link is the only one of the two you ever used, there is no sync toggle to switch off, so the routes to remove that record are deleting your account, which deletes it, or asking us at legal@gradegem.com. Your data export always shows exactly what is stored, either way.
3. What our servers store
- Account basics: your email, sign-in records, and role (student or educator).
- Saved display setup, only if you choose to save it: the four display choices above, an account link, a revision number and an update time. Anyone authorized to use a shared account can read or change its saved setup. Each device applies it only when you choose Use saved setup. Removing the account setup removes its choices from the active database; a revision and update time remain until account deletion to prevent an old device from restoring them. Your export includes this record. Account deletion removes it, and existing provider backup retention still applies.
- Consent records: for each course where you turn on AI help, the acknowledgment, the level you picked, the timestamp, and an optional syllabus citation. These are append-only and are never deleted, because they are the record that protects you.
- Billing: your subscription state, solve-credit ledger, and license redemptions. Card numbers never touch our servers; Stripe handles payment details.
- Previous device registrations: hashed random installation identifiers and registration dates may remain in your account history and export. These records no longer limit access. Local installation identifiers can still support the browser connection; they are not hardware fingerprints.
- Referrals: your own referral code, and if you joined through someone else's code, a link to the account that referred you. We keep it to award the credits and to stop the same person rewarding themselves. You can see it in your export, and it is removed when either account is deleted. We do not tell your friend anything about how you use GradeGem.
- Usage counters: per-day counts of AI feature calls, used for rate limits and abuse protection.
- Workspace classes and chats: they save to your account automatically. That means your questions, the answers you get back, each class's notes and extracted text from files you upload to it, your “Sound like me” description, and the prices you were quoted there. Class names come from Canvas or from you, and a chat is named after its first question. For a class linked to Canvas we keep that course's identifier. These stay until you delete the chat, the class or your account; deleting a chat deletes its answers and deleting a class deletes its chats, notes and saved file text. You can remove class files separately; this stops including them in future questions, but does not erase answers already saved in chats. The permission level you confirm for a class is an append-only record like a consent record: it stays after you delete the class and is anonymized when you delete your account (section 7). We also keep the IDs of classes and chats you deleted, with no names or text, so a delayed save cannot bring them back; those go when your account does. Your export includes all of it.
Who runs it with us: Supabase (database and sign-in), Railway (hosting), Stripe (payments), Resend (email), Google Workspace (our mailboxes), Slack (internal alerts), browser push services (optional reminders) and the AI provider named in section 4. The full list, with what each one receives, is available from legal@gradegem.com.
4. What passes through when you use AI features
When you run an AI feature, the text or image you provide (the reading you paste, the problem you capture) is sent to our server, which sends it to OpenAI's API to generate the response, then returns it to you. When you pick an assignment for the Tutor, the Rubric feedback tool, or the Solver's Rubric kind, its name, what kind of work it appears to be, and the rubric posted on its page go with that request. If you explicitly use an assignment page or attach its instructions, that text can also accompany your request. When you tap Tailor to this assignment in Study tips, that assignment's name, what kind of work it appears to be, when it is due, its points and the study tips on your screen go with that request. A Workspace question also sends that class's notes and saved file text, your “Sound like me” description where the class is at Full Assist, and the last few turns of the chat, and the Workspace saves the question and its answer as described in section 3. Grades and due dates are not automatically added to this AI context. Outside the Workspace, we do not build a server-side archive of your coursework out of these requests. We do keep metadata about each AI request (feature, model, timing, token counts, cost) for reliability and cost analysis; that metadata never includes your problem, your text, or the answer, and it is in your data export. One exception, always by your explicit action: if you report an answer as wrong, that report includes the problem and the answer so we can fix it. It can also retain a separate correction answer and your description of the failure. Attached documents, extracted readings and images are excluded from the report archive. For text problems, the Solver keeps a shared cache of solution methods keyed by a hash of the problem; final answers are never cached, and cache entries are not linked to your identity for other users.
You can attach PDF, DOCX, TXT or MD files to supported study requests. Text is extracted on your device; the file basename and extracted text are sent as separate materials when you submit the AI request. Original document files are not uploaded or stored on our servers. In the Workspace, uploading a class file saves its basename and extracted text privately to your account until you remove the file, delete its class or delete your account. This saved text is included in that class's new chat questions and is part of your data export. Uploading alone does not call an AI provider. Outside the Workspace, these materials are request-only. Requests with attached materials are excluded from shared answer caches. The picker shows file, page and subscription text limits; it rejects oversized text rather than silently shortening it. Review extracted material before sending it, and share only what you have permission to use.
When Solver correction recovery is available, the current result can hold an exact copy of the request and result in your device's memory for up to 24 hours. Closing or reloading that surface can remove it. Our server stores only a fingerprint of that copy and metadata about its original solve, ownership, expiry and correction attempt. The fingerprint cannot be used as a replacement for the request. To correct the same question, your device resends the exact original copy; changed questions or attachments do not qualify. If the copy is missing or expired, you can still file a report, but automatic correction may be unavailable. These replay materials are processed for that request and are not kept in a server archive or shared cache. We retain report and correction records for support and quality review until account deletion; they are included in your account export. Reporting does not add your work to a training or shared test corpus.
One more thing rides along with a Solver request, and only if you have used spaced practice: a list of up to three topic labels you have missed repeatedly, like “integration” or “acid-base and pH”. Your practice history itself never leaves your device; the labels are computed there and sent so the explanation slows down where you have struggled. They contain no problem text, no answers, and no grades, and they are not archived.
OpenAI processes API inputs under its own commercial terms and does not train on API data by default.
We request that OpenAI not store the generated response. This does not mean zero retention: OpenAI may keep abuse-monitoring data for up to 30 days, with exceptions for legal requirements, and prompt caching can retain encrypted processing data for up to 24 hours. See OpenAI's API data controls. You do not need a separate ChatGPT subscription to use GradeGem.
5. What we will never do
- Sell your data, or share it with advertisers or data brokers.
- Show your data to your school or instructors.
- Train AI models on your coursework.
- Use Canvas API access without your read-only sync opt-in, or collect other students' grades and submissions.
The use of information received through the GradeGem browser extension will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
6. Age, students under 18, and FERPA
GradeGem is for high school and college students aged 13 and up. The first time you sign in on a device we ask for your birth month and year. The check runs on your device: the date is never sent to us or saved. After that, the device keeps a note that the question was answered, with no date or identifier in it, so you are not asked again every time you sign in there. If the answer shows you are under 13, nothing is sent at all, not even your email address. The only trace is a note in that browser tab, with no date or identifier in it, so the question is not simply answered again; it clears when the tab is closed.
GradeGem is not directed at children under 13 and we do not knowingly collect personal information from them. If we learn that an account belongs to a child under 13, we delete it. If you believe a child under 13 has an account, email legal@gradegem.com and we will delete it.
If you are 13 to 17, this whole policy applies to you in the same way. We never sell your personal information or share it for advertising, and we do not build advertising profiles. AI features handle requests from students of every age the same way, as described in section 4. A parent or guardian can write to legal@gradegem.com with questions about a teen's account.
If you are under 18 and live in California, you can remove content or information you have given us through GradeGem: delete your account from your account page, or email legal@gradegem.com to ask us to remove a specific item, such as an answer you reported. Removal may not be complete or comprehensive: the anonymized records described in section 7 stay, and a request already sent to our AI provider follows its retention terms described in section 4.
GradeGem is a student-installed tool: you choose to install it, and it reads only records you already have the right to see. We are not a school official and we do not receive records from your school, whether you are in high school or college. We designed the product FERPA-conscious anyway: course records stay on your device, and the account-side data we do hold is exportable by you at all times from your account page.
7. Export and deletion
Every plan, including free, can download a full export of the account data we hold, anytime, from the account page. Account deletion removes your personal data. A few records are kept in anonymized form, stripped of anything that identifies you, and this is the whole list: your per-course consent records, because that log is append-only by design and is your own evidence that you acted within a course's rules; your credit ledger, as a financial record; the permission levels you confirmed for saved classes, keeping only the level and its date, with no class name or chat text; and, if your school bought seats, the fact that a seat was redeemed, plus any course AI policy or course claim you made as an instructor, because students relied on what those policies said. Each of those is stamped with its own separate random reference, so none of them can be joined back to the others.
8. Security
Access tokens, license keys, and link codes are stored hashed, not in plain text. Database access is locked down with row-level security. AI calls only run server-side; no API keys ship in the extension. If we ever have a breach that affects you, we will tell you directly and promptly.
9. Changes
If this policy changes in a way that matters, we'll say so in the product or by email before it takes effect, not bury it in a diff.
10. Contact
Privacy questions, data requests, and anything a parent or school needs in writing: legal@gradegem.com. For everything else, the contact page is faster.