Privacy Policy
Last updated: 2026-08-09 — TeachPal v1.0.2
The short version: We collect only what we need to run the service. We never sell your data or your students' data. You can request deletion at any time. We don't use your data to train AI.
1. What we collect
- Account information: Your name, email address, and hashed password when you register.
- Usage data: The date you joined and when you last logged in. We do not track page views or build behavioral profiles.
- Educational data you enter: Student names, grade levels, assignment scores, grades, teacher notes, and AI-generated feedback that you save to your gradebook.
- Bug reports: If you submit a bug report, we collect the description and any details you provide.
2. What we do NOT collect
- We do not collect payment information directly (handled by Stripe when billing is enabled).
- We do not collect student email addresses or personal contact information.
- We do not use cookies for tracking or advertising. Session cookies are used only to keep you logged in.
- We do not sell, rent, or share your data with advertisers or data brokers, ever.
3. How we use your data
- To provide and operate the TeachPal service.
- To send transactional emails (password reset, account notices). We do not send marketing email without your explicit opt-in.
- To improve the product -- we may review aggregate, anonymized usage patterns (e.g., which features are used most).
- To respond to bug reports and support requests.
4. AI processing
TeachPal uses the Anthropic Claude API to process grading requests. When you submit student work for grading, that text is sent to Anthropic's servers. Per Anthropic's current API policy, they do not use API inputs or outputs to train their models. See Anthropic's Privacy Policy for details.
We do not use student work, grades, or feedback to train any AI model ourselves.
5. Data storage and security
- Data is stored in a SQLite database hosted on Railway (cloud infrastructure).
- Passwords are hashed using industry-standard bcrypt-equivalent hashing (Werkzeug). We never store plaintext passwords.
- All connections to TeachPal use HTTPS/TLS encryption.
- We are a small team. Access to production data is limited to the founder.
6. Data retention
- Your data is retained as long as your account is active.
- You may request account deletion at any time via the contact form. We will permanently delete your account and all associated data within 30 days.
- Bug reports may be retained indefinitely to help improve the service.
7. Your rights
Depending on where you are located, you may have rights under GDPR, CCPA, FERPA, or other laws, including:
- The right to access a copy of your data
- The right to correct inaccurate data
- The right to delete your data
- The right to data portability (export your grades as CSV)
To exercise any of these rights, use the contact form and we will respond within 30 days.
8. Children's privacy (COPPA)
TeachPal accounts are for teachers (adults 18+). We do not knowingly collect personal information directly from students. Student data entered by teachers (names, grades) is treated as educational records under FERPA. Teachers are responsible for compliance with their school or district's policies regarding student data.
9. Changes to this policy
We will notify registered users by email at least 14 days before any material changes to this policy take effect.
10. Contact
Privacy questions or data requests: use the contact form on TeachPal. We aim to respond within a few business days.