Privacy, in plain language
GradeForge Privacy Notice
Last updated: September 3, 2026
Who this notice is for
This notice explains how GradeForge handles information for its English-language Ontario Grade 9 Math learning service. “GradeForge,” “we,” and “us” refer to GradeForge, the operator of this service. Questions can be sent to support@gradeforge.ai.
Information we collect
Before you create an account
The five-question gap scan uses a signed, opaque attempt token. The anonymous attempt stores the reviewed question identifiers, your selected answer positions, grading outcomes after submission, timing needed to operate and protect the check, and the resulting starting skill. It does not require your name, email, school, class mark, or account identifier. Unclaimed attempts expire after seven days.
A weekly challenge similarly stores the challenge version, selected answer positions, completion result, and a random anonymous token. Anonymous challenge attempts expire after seven days. If you use a shared challenge link, a random share identifier and rotating browser UUID record one visit and whether that browser started the challenge; those records expire after 14 days. They contain no name, email, school, contact list, or device fingerprint, and GradeForge never shows a sharer an individual recipient’s activity.
For aggregate measurement, these anonymous activities also use a random browser UUID. It contains no name, email, school, answer, IP address, or device fingerprint, and it rotates after 30 days. It helps avoid counting every attempt from one browser as a different student.
When you create an account
We collect the email and authentication details needed to sign you in. A display name and learning preferences are optional. We store your submitted work, progress, mastery evidence, misconceptions, study plans, missions, reminders you choose, and purchase or entitlement records needed to provide the service. When you claim a gap scan or start a challenge while signed in, its random browser UUID may be temporarily linked to your account so we can avoid double-counting; that browser link is removed after 30 days while your account learning record remains. We do not ask for a school name.
Service and measurement data
We use first-party events to understand whether the check, diagnostic, missions, and challenges work. Anonymous first-party events are deleted after 30 days. When an event belongs to an account, its rotating browser link is removed after 30 days and the account event is kept while the account remains active; account deletion removes it. We keep one daily aggregate of qualified Ontario Grade 9 Math activity for trend measurement after short-lived source records expire. That aggregate contains only a date, metric version, and count—no account, browser, attempt, answer, mark, or school identifier. Event properties are restricted to approved operational codes and must not contain answers, marks, email addresses, names, or school information. Our hosting and security systems may temporarily process technical request information, such as an IP address, to deliver, rate-limit, and protect the service; GradeForge does not add raw IP addresses to learning or analytics records.
How we use information
- Provide, grade, save, and improve learning activities.
- Recommend a next skill and build personalized missions from reviewed evidence.
- Keep accounts secure, prevent abuse, and recover access.
- Process purchases and preserve billing records required by law.
- Measure aggregate activation, retention, challenge sharing, and reliability.
- Send reminders only when you opt in; you can opt out.
When information is shared
We use service providers only to run GradeForge: Supabase for authentication and data infrastructure, Netlify for hosting and server functions, Stripe for payment processing, Resend when you opt in to email reminders or receive a transactional message, and Google if you choose Google sign-in. Some providers may process information outside Ontario or Canada, where local laws may apply; we minimize what they receive and use contractual, access-control, and security safeguards appropriate to the service. We may also disclose information where required by law or to protect students and the service.
GradeForge does not sell personal information. We do not use third-party advertising pixels during this launch.
Challenge cards and links
A downloaded result card contains only the challenge title, score or skill badge, and GradeForge branding. It never contains a name, school, account identifier, class mark, answers, or private learning history. Sharing uses your device’s share sheet or clipboard; GradeForge does not upload your contacts or send messages on your behalf.
Retention and deletion
Unclaimed gap scans and anonymous challenge attempts expire after seven days. Challenge-share identifiers expire after 14 days. The anonymous browser UUID rotates, anonymous first-party events are deleted, and UUID links on account-linked activity are removed after 30 days. Account learning records are kept while your account is active so you can see progress. Identifier-free daily activity counts are retained for aggregate launch and service trends. Student accounts can request a machine-readable export or permanently delete the account from Your data choices; successful deletion also clears GradeForge browser storage on that device. Author, reviewer, or admin accounts must contact support first so published review provenance can be transferred or anonymized before deletion. Some transaction records may be retained where required for fraud prevention, tax, accounting, or legal obligations.
Your choices
You can use the initial check without signing in, decline reminders, request password recovery, download an account export, or delete your account. A parent or guardian may contact us about a student’s information. To ask a privacy question, request a correction, or raise a concern, email support@gradeforge.ai.
Safeguards and changes
We use access controls, row-level security, short-lived private tokens, minimized analytics, and encrypted transport. No system can promise absolute security; suspected private-data exposure is treated as a launch-stopping incident. We will update the date and notice when our practices materially change.