Privacy Policy
What Markpilot stores, what it never stores, who else processes your data, how long it lives, and how to delete it. Written plainly, because you should be able to answer your school's questions from it.
Last updated: 22 July 2026
1. Who we are
Markpilot ("Markpilot", "we", "us") is a tool that helps teachers mark assessments and draft report comments and student feedback. It is operated from Australia. Our contact point for anything in this policy is hello@markpilot.co.
This policy is built on the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), which is where we are based. Teachers anywhere in the world are welcome to use Markpilot, and we apply the same data practices described here to everyone. Wherever you are, the handling below applies; and if your local law (for example, the GDPR in the UK and EU, or student-privacy laws in the United States) gives you additional rights, you are welcome to exercise them by contacting us — see section 10.
If you use Markpilot as an individual teacher, you are our customer; if your school arranges access, your school is our customer and this policy operates alongside any agreement we have with them.
2. Whose data this is about
Two kinds of people appear in Markpilot:
- You, the teacher (or school staff member) — the account holder. We hold your email and account details.
- Your students — who appear only as identifiers you choose (a first name, initials, or a student ID), attached to the marks, comments and feedback you create. Markpilot never generates or derives its own student identifier, and does not collect student contact details, dates of birth, photographs, or logins. Students do not have Markpilot accounts.
You decide how students are identified. First names or initials are enough for the product to work, and we encourage the least identifying option your reporting needs allow.
3. What we collect and store
How you sign in
You sign in with your Google or Microsoft account — your school staff account, or a personal one, your choice. When you do, Google or Microsoft confirms your identity and passes us your email address (usually your school email) and basic profile information. We never receive or store your password. We keep your email address to identify your account; we do not store your Google or Microsoft credentials. Note that a school email address can identify both you and your school through its domain, so if you prefer to keep Markpilot separate from your school identity, you may sign in with a personal Google or Microsoft account instead.
Account and billing
| Data | Why |
|---|---|
| Your email address (from Google or Microsoft sign-in) | To create and secure your account and send you service emails |
| Plan, billing status, usage counters | To run your subscription and monthly credit allowance |
| Stripe customer and subscription identifiers | To link your account to your Stripe billing. We do not store card numbers — payment details are handled by Stripe. |
Your gradebook (the product itself)
| Data | Why |
|---|---|
| Class details and roster identifiers (the names or initials you enter) | To organise your marking by class and student |
| The marks and band judgments you record or accept | They are your gradebook, so you can return to them across sessions |
| The parent comments and student feedback generated, and any edits you make | So your drafts persist and can be exported |
| End-of-semester report comments you generate | Same — your record, retained until you delete it |
| Short evidence quotes and, for AI-marked papers, per-question transcriptions of a student's answers | To let feedback and the moderation report cite what a student actually wrote. Kept on the same clock as the page images below, and deleted together with them: when you delete a student's scans, their transcribed text goes too. |
| Downscaled images of marked answer pages (only if you use AI paper marking) | So the review surface can show each answer beside its mark across sessions: moderation, parent meetings, cross-marker checks. Stored in a private bucket, reachable only through short-lived signed links; kept for one school year (365 days), extended whenever you open them again, and cleared by a daily job only once an assessment has sat untouched for that whole period. You can delete any student's scans from their review at any time. Pages with no marked answers on them (covers, instructions) are never uploaded. |
Assessment structure (your and your school's material)
Question text, mark schemes, rubrics and stimulus text from the papers you upload are stored so the tool can mark against them consistently. This is your and your school's material, not student data.
Operational data
We keep aggregate usage and cost records (counts, score bands, model and token usage) to run and improve the service. These do not identify students.
4. What we never store, and what expires
Never stored: your original files. When you scan a paper, it is rendered to images in your browser; the original PDF never leaves your device. We also never store passwords (sign-in is handled by Google or Microsoft) or card numbers (payments are handled by Stripe).
Stored with an expiry, not forever: the two things we keep that come from student work (downscaled images of marked answer pages, and short transcriptions and evidence quotes) are time-bounded and teacher-deletable, as set out in the table above. Everything else we retain is the structured result of your marking: the marks, bands and comments that make up your gradebook.
5. How AI processing works
Marking and drafting are done by an AI service, Anthropic (the Claude API). To process your request, we send the relevant material — the student response pages (as browser-rendered images), the question and rubric text, and the marks — to Anthropic for that request only. Anthropic does not use data submitted through its API to train its models. What Markpilot keeps afterwards is what section 3 sets out: the structured result (marks, comments) in your gradebook, and, for AI-marked papers, the time-bounded answer-page images and transcriptions that power the review surface.
6. Who else handles your data
We use a small number of trusted providers ("sub-processors") to run Markpilot. Each receives only what it needs:
| Provider | Purpose | What it receives |
|---|---|---|
| Google / Microsoft | Sign-in (you choose which) | They confirm your identity and pass us your email and basic profile; they do not receive your Markpilot data, and we do not receive your password |
| Supabase | Database and sign-in | Your account and gradebook data, stored at rest |
| Anthropic (Claude API) | AI marking and drafting | Student response pages and text for the duration of a request (see section 5) |
| Stripe | Payments | Your email and payment details (held by Stripe; we store only identifiers) |
| Resend | Service emails | Your email address and message content |
| Vercel | Hosting | Request traffic; no dedicated data store |
7. Where your data is held
Your account and gradebook data is stored by Supabase in a data centre in Singapore. AI processing by Anthropic occurs in the United States. By using Markpilot you consent to your data (and the student identifiers and marks you enter) being stored and processed in these locations. We take reasonable steps to ensure our providers protect it to a standard consistent with the Australian Privacy Principles.
8. How long we keep it, and deletion
We keep your data for as long as your account is active, and delete it when you delete it:
- Delete a task removes its marks, comments and evidence quotes.
- Delete a class removes its roster, marks, comments and semester comments.
- Delete your account (from the account page) removes your classes, rosters, tasks, comments and analytics, and your sign-in record.
If you want us to delete specific data on your behalf, or you cannot reach the controls above, email hello@markpilot.co and we will action it.
9. Security
Every record is locked to your account: the browser never queries the database directly, and every request goes through our server, which authenticates you and scopes the query to your account so no other user can read your data. Data is encrypted in transit. Access to production systems is limited. No system is perfectly secure, but these are the controls we run and maintain.
10. Your rights and choices
Under the Australian Privacy Principles you can ask to access the personal information we hold about you, ask us to correct it, and ask us to delete it. You can do most of this yourself from your account, or email hello@markpilot.co. You also choose how students are identified in the first place — using initials or IDs instead of full names is the simplest way to minimise the personal information entered.
If you are outside Australia, the same access, correction and deletion controls apply to you, and any additional rights your local law gives you (such as data portability or objection under the GDPR) can be requested at the same address.
If you are unhappy with how we have handled your information, you can contact us, and you have the right to complain to the Office of the Australian Information Commissioner (oaic.gov.au), or to the data-protection authority in your own country.
11. Students and children's data
Much of the data you enter concerns students, who are often minors. Markpilot is a tool for teachers and schools; we do not collect information directly from students, and students have no accounts. When you enter student identifiers, marks or work, you do so as their teacher or school, and you confirm you are authorised by your school to use a tool like Markpilot for that purpose. If you are an individual teacher, please check your school's policy on using external tools with student information before entering it. We act on your instructions and hold this data only to provide the service to you.
12. Changes and contact
We may update this policy as the product changes; we will update the date at the top when we do, and material changes will be notified through the service. For any question about this policy or your data, contact hello@markpilot.co.