Privacy Policy
Effective Date: September 22, 2026
Grady Labs Inc. (“Grady,” “we,” “us,” or “our”)
This Privacy Policy describes how Grady Labs Inc. and our grading and feedback service, Grady, collect, use, disclose, retain, and protect information when you use our public website, standalone web application, or institutional LMS/LTI service. This policy distinguishes between the standalone service and institutional LMS/LTI processing because the information collected, our legal role, and the retention model are different for those two product paths.
Grady also maintains a detailed internal Data Privacy Policy (TR-2025-004), which is available to institutional partners under appropriate confidentiality terms.
1. Scope and Our Role
1.1 Institutional LMS/LTI Service
When an educational institution uses Grady through an institutional LMS/LTI deployment, the institution controls the student and instructor information and determines the purpose of the processing. Grady acts as the institution's data processor or service provider and processes information under the institution's instructions and the applicable institutional agreement. Student requests relating to institutional records should be directed to the institution, and Grady will assist the institution as required by the applicable agreement and law.
1.2 Standalone Service, Website, and Direct Interactions
When an instructor creates and uses a standalone Grady account, visits our website, submits a demo request, contacts support, or makes an analytics choice directly with Grady, Grady Labs Inc. determines the purposes and means of processing the account, website, support, cookie, and analytics information described in this policy and acts as the data controller or business for that information, as applicable.
2. Information We Collect and Process
2.1 Institutional LMS/LTI Grading
Our institutional LMS/LTI grading workflow is designed around data minimization. For that workflow, Grady processes the content needed to grade a student submission together with internal LMS identifiers needed to return the grade or feedback to the correct location. The LTI workflow is designed so that Grady does not require student names, instructor names, or email addresses as part of the grading payload.
2.2 Standalone Instructor Accounts
The standalone service processes information needed to create, authenticate, secure, support, and administer the account. This may include:
- Instructor name and email address.
- Authentication information, account credentials, session identifiers, and security-related account information.
- Account settings and preferences.
- Support communications and information you provide when asking for assistance.
- Product usage information described in the analytics section below, when you consent to optional analytics.
- User Content that you choose to upload, including assignments, rubrics, grading criteria, answer keys, student submissions, and related materials.
The institutional LTI rapid-purge process described below does not apply to content uploaded through a standalone account. Standalone User Content may remain associated with the account while it is active and is subject to the standalone account-retention rules in this policy and the Terms of Service.
2.3 Website and Demo Requests
If you submit the Request a Demo form on our website, we collect the information you submit: first name, last name, university email address, country, role, institution, and any optional message. We use this information to respond to the request, communicate about Grady, and manage the prospective institutional relationship.
2.4 Technical and Cookie Information
Our website and standalone application also process technical information associated with browser requests, authentication, and analytics as described in Section 7.
3. How We Use Information
We use information described in this policy to:
- Provide grading, feedback, account, and related Platform functions.
- Authenticate users and secure accounts and systems.
- Return grades and feedback through an institutional LMS/LTI workflow when applicable.
- Operate, support, troubleshoot, and maintain the Service.
- Respond to support, privacy, security, and institutional inquiries.
- Process payments or Credits where applicable.
- Understand standalone product usage and diagnose product issues through PostHog only when the user has consented to optional analytics.
- Measure use of the public marketing website through the cookieless analytics described below.
- Comply with applicable law and valid legal process.
- Protect the rights, security, and integrity of Grady, our users, institutions, and the public.
We do not use student submission content to train or fine-tune Grady AI models.
4. Institutional LMS/LTI Data Flow and Retention
The institutional LMS/LTI workflow follows a separate processing and retention model from the standalone service:
- Secure Transfer: The LMS sends the assignment content and required internal identifiers to Grady over an encrypted connection.
- Data Minimization and Anonymization: The grading workflow is designed to avoid direct personal identifiers in the grading payload and to process anonymized content.
- Grading: The anonymized content is processed in Grady's secured grading environment.
- Grade Return: The resulting grade and feedback are returned to the institution's LMS or other authorized institutional destination.
- Submission Purge: After the grading transaction is completed and the result is returned, the anonymized submission content used for the LTI grading workflow is permanently deleted from the grading environment within 30 minutes.
This LTI submission-purge rule applies to the institutional LMS/LTI grading workflow. It does not describe retention for standalone accounts, account records, support communications, consent records, authentication cookies, or analytics data.
5. Standalone Account and User Content Retention
Standalone account information and User Content may remain associated with an active account so the instructor can access and use the Service. If the account is terminated, Grady retains the standalone account data for sixty (60) days to allow the user to export content. After that period, the account data may be permanently deleted. Grady may retain aggregated or de-identified information that cannot reasonably be linked to an identifiable individual, subject to applicable law.
Support, security, legal, consent, and transaction records may be retained for the period required to fulfill the relevant operational, contractual, security, or legal purpose. Cookie and analytics retention periods are stated in Section 7.
6. Core Privacy Commitments
- Data Minimization: We limit institutional LMS/LTI processing to the content and internal identifiers required to perform the authorized grading workflow.
- Separate Product Models: We do not describe standalone account processing as zero retention. The LTI purge process and the standalone account-retention process are separate.
- Synthetic Training Data: We do not use student submission content, including anonymized student submission content, to train Grady AI models.
- No Advertising or Cross-Site Tracking: We do not use advertising pixels, retargeting technologies, or cross-site behavioral advertising on our properties.
- No Sale of Personal Information: We do not sell or rent personal information, student submission content, or institutional data.
- US Processing: The services and analytics described in this policy are operated using infrastructure in the United States, subject to the contractual and legal safeguards applicable to the relevant processing.
7. Cookies and Analytics
This section explains how Grady uses cookies and similar technologies on our marketing website at www.gradyai.com and our standalone web application at app.gradyai.com. References to cookies include comparable browser technologies such as local storage, pixels, tags, and web beacons where applicable.
7.1 Marketing Website: Cookieless PostHog Analytics
We use PostHog to understand how the public marketing website is used. On the marketing website, PostHog runs in cookieless mode. No PostHog cookie or local-storage entry is placed on your device for marketing-site analytics. The marketing-site configuration does not recognize you across separate visits or build a persistent visitor profile.
To measure page views and distinguish visits within a short period, PostHog derives a temporary identifier from technical information your browser sends with a request, including IP address and user-agent information. The identifier is rotated and is not stored on your device. If Grady introduces device-stored analytics cookies on the marketing website in the future, we will update this policy and implement the consent controls required for that change.
7.2 Standalone Application: Strictly Necessary Cookies
The standalone application uses the following first-party cookies because they are necessary to authenticate the user and maintain a secure session:
- access_token — authenticates requests after sign-in; duration: 1 hour.
- session_id — identifies the signed-in session and supports secure sign-out; duration: 7 days.
- refresh_token — obtains a new access token when the current access token expires; duration: 7 days.
These cookies are transmitted over encrypted HTTPS connections and are configured with security attributes appropriate to their purpose. They are not used for advertising, profiling, or optional analytics. Blocking or deleting them will end or prevent a signed-in session.
7.3 Standalone Application: Optional Product Analytics
With your consent, we use PostHog in the signed-in standalone application to understand product use, identify product problems, and improve features. The analytics cookie is ph_<key>_posthog and has a duration of 365 days unless it is deleted or replaced earlier.
With consent, standalone analytics may record:
- Pages and screens opened within the application and the order in which they are visited.
- Actions taken in the interface, such as buttons, controls, and features used.
- Technical information about browser, device type, and operating system.
- Approximate location derived from IP address.
- Date, time, and duration of activity.
- An identifier that links analytics activity to the Grady account.
PostHog analytics does not receive student submission content, grades, or feedback text.
Analytics consent is requested separately from acceptance of the Terms of Service. The analytics option is not selected in advance.
7.4 Session Replay
When you consent to standalone product analytics, the same PostHog consent also enables session replay. Session replay creates a video-like reconstruction of activity within the Grady application, such as pages viewed, mouse movement, clicks, scrolling, and interface responses. It is not a recording of your camera, microphone, other applications, or other browser tabs. Passwords and other credentials are not captured. Access to session replay is restricted to authorized personnel who need it for product support and troubleshooting. Session replay does not run on the cookieless marketing website.
7.5 PostHog Retention and Hosting
PostHog acts as Grady's analytics processor under a written data-processing agreement. The PostHog environment used for the processing described in this policy is hosted in the United States. Standalone analytics data and session replay recordings are retained for one year.
7.6 Managing Cookies and Analytics
You may block or delete cookies through browser settings. Blocking the strictly necessary cookies described above will prevent or end a signed-in standalone session. Blocking cookies does not delete information already held by Grady or its service providers. Where the product provides an analytics control, you may use that control to change or withdraw analytics consent and clear the analytics cookie.
7.7 Do Not Track
Grady does not track users across third-party websites or services for advertising purposes. Because we do not engage in cross-site behavioral advertising, browser “Do Not Track” signals do not disable a cross-site advertising activity on Grady properties.
8. Third-Party Service Providers
We use service providers to operate Grady. These providers are permitted to process information only for authorized services and subject to applicable contractual controls.
- Amazon Web Services (AWS): cloud compute, storage, security, and related infrastructure in the United States.
- AI service providers: Grady sends the content required for grading and applies the de-identification and contractual controls applicable to the relevant workflow. Student submission content is not authorized for provider model training.
- PostHog: cookieless marketing-site analytics and, with separate consent, standalone product analytics and session replay. PostHog does not receive student submissions, grades, or feedback content through the analytics configuration described in this policy.
The institutional LMS/LTI workflow may involve additional institutional systems or approved subprocessors identified in the applicable institutional agreement or supporting documentation. The PostHog standalone analytics disclosures in this policy should not be read as a statement that PostHog is used to analyze student grading content in the LMS/LTI workflow.
9. Data Sharing and Disclosure
We do not sell or rent personal information. We may disclose information to authorized service providers that process it on our behalf; to an educational institution where disclosure is necessary to perform an institutional service; where the user directs or authorizes the disclosure; to protect security, rights, or safety; or when required by a valid and legally binding legal process. Service providers are not authorized to use the information for independent advertising purposes.
10. Data Protection and Security
Grady uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, alteration, and disclosure. These safeguards include encrypted connections, access controls, account-security measures, and restricted service-provider access. No security program can guarantee absolute security, and users remain responsible for protecting their account credentials.
11. Compliance and Institutional Processing
- FERPA: Where Grady operates under an institutional agreement that establishes the required relationship, Grady may act as a school official or service provider for the institution and process education records only for the authorized educational purpose. A standalone account does not by itself create a FERPA School Official relationship.
- US State Privacy Laws: For institutional processing, Grady acts in the service-provider or processor role specified by the applicable agreement and law. For website and standalone information that Grady controls directly, Grady processes the information as described in this policy and honors rights that apply to that processing.
- GDPR and UK GDPR: Where Grady processes personal data on behalf of an institution subject to GDPR requirements, Grady acts as a processor under an applicable Data Processing Agreement. For Grady-controlled website, account, support, cookie, and analytics data, Grady acts as controller where applicable. Grady supports human instructor review of AI-generated grading outputs.
12. Your Privacy Rights and Requests
Depending on your location and the applicable law, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to withdraw consent where processing is based on consent.
- Institutional LMS/LTI data: Direct student or education-record requests to the educational institution. Grady will assist the institution under the applicable agreement.
- Standalone account data: You may request account deletion through available account settings or by contacting support@gradyai.com. The sixty-day post-termination retention period described above applies before account data may be permanently deleted.
- Website, demo, cookie, or analytics requests: Contact security@gradyai.com. Where applicable, you may withdraw consent for optional standalone analytics through the available in-product control.
For privacy matters involving EU or UK data-protection rights, you may contact Periklis A. Papakonstantinou, Chief Information Security & Privacy Officer, at corporate@gradyai.com.
13. Government and Law-Enforcement Requests
Grady discloses information to governmental or law-enforcement authorities only when required by valid legal process or when another lawful basis permits or requires disclosure. The institutional LMS/LTI purge process limits the student submission content available in Grady's grading environment after the applicable purge is complete.
14. Policy Governance
This Privacy Policy is maintained under Grady's privacy and security governance program and is reviewed on a recurring basis by the Chief Information Security & Privacy Officer or designated privacy personnel.
15. Changes to This Privacy Policy
We may update this Privacy Policy when our services, technology, processing practices, or legal obligations change. When we make changes, we will post the revised policy and update the Effective Date. If a change affects processing that requires consent, we will obtain any new consent required before applying that change to the consent-based processing.
16. Contact Us
Grady Labs Inc. d/b/a Grady
Privacy and data-protection questions: corporate@gradyai.com
Standalone account support and deletion requests: support@gradyai.com
Security concerns: security@gradyai.com
Institutional agreements: partnerships@gradyai.com
Website: https://gradyai.com