Privacy policy
Privacy policy
Last updated: 2026-09-13
Grademap is an academic companion app. It helps university students track grades, plan study time and see where a class is heading. This policy explains what personal data it holds, why, who else sees it, how long it is kept, and what you can make us do about it. It is written against the app as it is actually built, not against what it might do later.
The data controller and the contact address are shown at the top of this page.
1. What we collect
Nearly all of it is data you type in. Grademap has no tracking pixels, no advertising, and no third-party marketing tools of any kind.
| Category | What that means | Where it comes from |
|---|---|---|
| Account | Email address, a password (stored hashed, never in readable form), your username and display name, your avatar if you upload one, and your settings. | You, at sign-up and in Settings |
| Academic content | Your years, semesters, classes, categories and weightings, pieces of work and their marks, deadlines, calendar events, reminders, study plans, what-if scenarios. | You |
| Study content | Study sessions and the time logged against them, notes, uploaded materials, flashcard decks and cards, cloze exercises, mock exam papers and your attempts at them. | You |
| Social | Buddy invitations and links, weekly shared stats, online presence, co-study sessions and anything shared inside them, who is attending an event. | You, and buddies you accept |
| AI | Your GradeBot conversations and their messages; facts GradeBot has inferred about how you study, if you leave that switched on; a record of each AI call and what it cost. | You, and the AI features |
| Billing | Your Paddle customer and subscription identifiers, subscription status and renewal date, and a log of billing events. Never your card details — see §3. | Paddle |
| Security | Failed username sign-in attempts, so the sign-in endpoint can be rate-limited. | Automatic |
| Feedback | Anything you send through the in-app feedback form. | You |
| Usage analytics | Anonymous page-view counts — which screens get opened. No cookies, no identifier, nothing tied to you. See §7. | Automatic, on the web app |
| Error reports | If the app breaks, a technical description of the failure, with an opaque account identifier. See §3. | Automatic |
Uploads. Files you attach — lecture slides, documents, session artifacts — are stored as files, in storage areas separated by account. Your avatar is stored in a public area: an avatar image can be fetched by anyone who knows or guesses its address. Nothing else you upload is public.
2. Why we use it, and the lawful basis
| What for | Lawful basis (UK/EU GDPR Art. 6) |
|---|---|
| Running the app — your grades, plans, notes and calendar | Contract. It is the service you signed up for. |
| Accounts, sign-in, and keeping your data yours | Contract |
| Taking payment for Pro, and keeping billing records | Contract, and legal obligation for the records tax law requires us to keep |
| AI features, when you use one | Contract |
| Social features, when you invite or accept a buddy | Contract |
| Rate-limiting sign-in, and keeping the service standing | Legitimate interests — keeping accounts from being broken into |
| Anonymous page-view counts, and error reports | Legitimate interests — knowing what is used, and what is broken |
We do not sell personal data and we do not use it for advertising. There is no automated decision-making with a legal or similarly significant effect: a projected grade is a calculator’s output, not a decision about you.
3. Who processes your data
These are the only other companies involved, and the only things they receive.
| Processor | What it receives | Where |
|---|---|---|
| Supabase (database, files, auth, email) | Everything in §1 that is stored. Also sends your sign-up and password emails. | EU — Frankfurt (eu-central-1) |
| OpenAI (AI features) | Only what an AI feature needs, at the moment you use it — see below. Never a file. | United States |
| Paddle (payments) | Your email, and whatever you type into Paddle’s checkout, including your card details. Paddle is the merchant of record — see below. | EU / US |
| Vercel (hosting, analytics) | Serves the app. Anonymous page-view counts. Server logs including IP addresses, as any web host keeps. | EU / US |
| Cloudflare (Turnstile) | A bot check on the sign-up form. Cloudflare sees the request, not your account data. | Global |
| Sentry (error reports) | Technical error reports, configured to send no personal data: no IP address, no request bodies, no cookies, and the account reduced to an opaque identifier. No session replay. | EU / US |
What actually goes to OpenAI, and what does not. When you use an AI feature, we send the text it needs and nothing more: your message, the relevant classes, work and marks, and — for a feature that reads your own writing — the text of the note or material concerned. Files never leave our storage. Text is extracted from a document first, and only the text is sent.
OpenAI does not train its models on data sent through the API. It keeps a copy for up to 30 days for abuse monitoring, unless the law requires longer, and then deletes it. (Checked against OpenAI’s published API data-usage policy on 2026-09-13.)
If you turn off “Let GradeBot remember things about how you study” in Settings, Grademap stops inferring and storing those facts, and you can delete the ones already stored.
Paddle is the merchant of record. Paddle sells you the subscription, handles the payment, and is the controller for the payment itself. Grademap never sees or stores your card number. We hold your Paddle customer and subscription identifiers and the status of the subscription. Paddle’s own privacy policy governs the payment.
International transfers. Your stored data is in the EU. OpenAI, Sentry, Paddle and Vercel may process data in the United States. Those transfers rely on the UK and EU standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.
4. Social features, and what other people can see
Grademap is not a social network, and your grades are never shared — not with buddies, not in a co-study session, not anywhere.
- Your username and display name are public. They are how another student finds you in order to send a buddy request.
- Your avatar is public, as described in §1.
- A buddy you accept can see that you are online, and weekly summary stats about your study time — hours and sessions, never marks.
- In a co-study session, everyone in it sees what is shared into that session: shared notes, materials and tasks. Nothing else from your account crosses over.
- Removing a buddy, or leaving a session, stops all of it.
5. How long it is kept
- Your content and your account — for as long as the account exists.
- Billing records — kept after deletion where tax and accounting law requires it. That means a record of the transaction, not your card details, which we never had.
- Anonymous page-view counts — not tied to you, and not deleted, because there is nothing in them to identify.
- Abuse-monitoring copies at OpenAI — up to 30 days, as in §3.
- Everything else — deleted when you delete your account.
6. Your rights
Under the UK GDPR and the EU GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to someone else. You can also withdraw consent where we rely on it.
In the app, right now:
- Correct or delete anything. Every class, mark, note, material and message can be edited or deleted directly.
- Delete your account, in Settings. This cancels a live Pro subscription, erases every file you uploaded — including your public avatar — and deletes your account and every row of data attached to it. It is immediate and it cannot be undone.
- Turn off AI inference, and delete the facts already stored.
For a copy of everything we hold about you, write to the privacy address at the top of this page and we will put one together for you. We answer any request within one month.
If you think we have got this wrong, please tell us first — but you have the right to complain to the Information Commissioner’s Office (ico.org.uk), or to the supervisory authority where you live.
7. Cookies, storage and analytics
Grademap sets no advertising or tracking cookies, and there is no consent banner because there is nothing to consent to.
- The app keeps your sign-in session and your settings in your browser’s local storage. This is strictly necessary — without it you would be signed out on every page load.
- Page-view counts. The web app records which screens are opened, using Vercel Web Analytics. It sets no cookie, stores no identifier, and cannot follow you to another site or connect one visit to another. We use it for one thing: seeing which parts of Grademap nobody opens, so they can be improved or removed.
- The marketing site at grademap.net stores one thing, and only if you press the button: whether you chose light or dark.
8. Security
Every row of your data is protected in the database itself by row-level security policies, so a request can only ever return your own rows — the rule is enforced by the database, not only by the app. Uploads are stored in per-account areas. Passwords are hashed by Supabase and we never see them. AI features and billing run on the server, so the keys they use are never in your browser. Traffic is encrypted in transit, and data is encrypted at rest.
No system is perfectly secure. If a breach affects you, we will tell you and the ICO as the law requires.
9. Age
You must be 16 or over to have a Grademap account. We do not knowingly collect data from anyone younger. If you believe a child has an account, write to the privacy address and it will be deleted.
10. Changes
If this policy changes in a way that matters, we will say so in the app and update the date below. The current version is always at grademap.net/privacy.
| Date | Change |
|---|---|
| 2026-09-13 | First published version. |
11. Contact
Use the privacy address at the top of this page for anything in this policy, including a request to see, correct or delete your data.