[ PRIVACY POLICY ]

Your data, and what we do with it.

Last updated: August 2026

Gradovate reads your grades from your school's portal so it can compute your GPA, track your progress, and generate study recommendations. Doing that requires storing some of your academic data on our servers. This page says exactly what we store, how long we keep it, and who can see it — in plain English, without overstating our position.

What we collect

Where your grade data is stored, and for how long

Your grade, transcript, and report-card data is cached on Gradovate's servers, not only on your device. We do this so the app loads instantly, works when your school's portal is down, and can compare terms over time.

That data is retained for as long as your account exists. When you delete your account, it is purged. We do not keep archived copies, we do not export it, and we do not maintain a long-term store of student records beyond active accounts.

How your school password is handled

We never see or transmit your school password. Your school sign-in happens inside a secure WebView on your device. If you stay signed in, your school username and password are saved in your device's iOS Keychain — encrypted, locked to that one device, never synced to iCloud, and never sent to Gradovate's servers or anyone else. They are used only to sign you back in when your school session expires, and they are erased when you sign out, disconnect your school account, erase local data, delete your account, or delete the app.

Canvas

Canvas is not connected today. An earlier version of the app asked students to generate a personal access token in Canvas and paste it in; we stopped supporting that because it hands an app more access than it needs, with no way for a school to see who holds one or to revoke it. If Canvas returns, it will use OAuth, where you approve access on Canvas's own screen and your school can revoke it at any time. We will update this page before that ships.

AI analysis

When you generate a study plan or analysis, your grade data is sent to Anthropic's Claude API. Under Anthropic's commercial terms, data sent through the API is not used to train their models. We do not use your data to train any model of our own.

Sharing with EssayLab

Gradovate and EssayLab are both our products. They share one profile, keyed by your email address, so you don't rebuild the same academic picture twice. That shared profile holds your academic snapshot (GPA, rank, course rigor, test scores), numeric essay trait scores (0–5 per trait — never the text of your essays), and application context you enter yourself, such as activities, awards, and intended major.

EssayLab can read and write only the essay-score portion. It has no access to your grades, transcripts, or report cards. Because both products are ours, this is not a sale and not third-party sharing — but it is a real data flow between two products, so we are telling you about it.

Analytics

Our usage analytics are tied to your account, not anonymous. Events include your user ID and email address alongside the screen you opened and basic device information. We use them to understand which features get used and where the app is failing. We do not use advertising trackers, retargeting pixels, or third-party analytics services, and we delete analytics events associated with your account when you delete your account.

What we don't do

We do not sell your data, and we do not share it with third parties for their own purposes. Our service providers — Anthropic for AI analysis, Supabase for storage — process data on our behalf under their terms. We do not use your data to train AI models. We do not serve advertising.

Who can see your data

You can, always. Our support staff can only with your permission on a specific support ticket, and that access is logged. If your district signs a Data Processing Agreement with us, administrators covered by that agreement can access records under its terms; today no district account has any access path to student records. Parent access is not built.

Deleting your data

You can delete your account from inside the app, under Profile. It runs immediately and removes your grades, GPA history, transcripts, report cards, study statistics, college targets, shared profile, analytics events, and settings.

You can also email support@gradovate.com with the subject Data Deletion Request. We reply within 5 business days and complete every request within 30 days. Residual copies inside our database provider's automated backups age out within 7 days and are not separately retrievable by us.

FERPA

We store student academic records, so we do not claim to sit outside FERPA's scope. When we operate under a signed district Data Processing Agreement, we treat that data as an education record and act as the district's school official with a legitimate educational interest. Without such an agreement, the data is yours: it is not shared with your district or anyone else, and you are the only person who can request access or deletion.

Changes to this policy

If we make material changes to how we handle your data, we'll notify you in the app before they take effect.

Contact

Questions about your privacy? Email support@gradovate.com