← Critique Studio

Privacy Policy

Critique Studio helps teachers grade student work. This explains what we collect, why we hold it, who else sees it, and how long we keep it.

Last updated 8 August 2026 · Silicon Neuron LLC

In short. We do not sell student data, we do not advertise to students, we do not train AI models on their work, and we delete it when you ask. Student work is used to grade for that student’s teacher and for nothing else.

Who we are

Critique Studio is a product of Silicon Neuron LLC. When a school or teacher uses it, we act as a service provider to that school — the school remains in control of its students’ education records, and we process them only as the school directs.

For anything on this page, write to privacy@critiquestudio.com.

What we collect

From teachers. Name, email address, password (stored hashed — we never see it), the courses and rubrics you create, and your billing details if you buy credits.

About students. Name, and an email address only if the course is run online. Uploaded work — documents, photos and scans. Grades, written feedback and annotations. Quiz attempts and answers.

What we never collect. Age or date of birth. Political or religious affiliation. Voting history. Biometric data.

A course can also run on student names alone, with no student account and no email address collected. We recommend that for younger students.

Why we hold it

To do the job the teacher asked for: draft a grade, show it to them for review, and keep the result so their gradebook works. We have no second use for it.

How AI is used

When a teacher runs a grading job, the student’s work is sent to an AI provider along with whatever the teacher is grading against, and a draft grade comes back. A draft is not a grade. It counts only when the teacher confirms it, and the teacher can change any part of it.

We only use providers that have agreed to keep nothing once the response is returned, and no provider may train its models on your data. The providers we use are listed on the subprocessors page.

Some features are for material a teacher writes — course content, rubrics and images. Those are not intended for student work, and the terms ask teachers not to put student work into them.

Who else sees it

Only the companies we need to run the service. Each is bound by contract to use the data only to provide their part of it. These are the ones that can see student data, and why:

CompanyWhy they receive itWhere
SupabaseDatabase, authentication and file storageUnited States
VercelWeb application hostingUnited States
Fly.ioRuns the AI grading worker and the document converterUnited States (Ashburn, VA)
ResendSends account email — confirmations, invitations, password resetsUnited States
xAI (Grok)Grades student workUnited States
Mistral AIGrades student workEuropean Union

The complete list, including companies that never see student data, is on the subprocessors page. We will publish any addition to that list, and give schools notice before a new company starts processing student data.

How long we keep it

We do not keep student data indefinitely. Each kind of data has a period and a trigger that ends it:

DataHow longWhat ends it
Student work, grades, feedback and annotationsKept for the academic term it belongs to, then deleted. Terms are removed automatically 24 months after they end, or sooner if the school chooses a shorter period.Term ends · deleted by the teacher · deletion request
Student account (name, email address, sign-in)Deleted automatically after 24 months with no sign-in. A student may delete their account sooner, and may join again later from a new invitation.24 months of inactivity · deleted by the student · deletion request
Class roster entry (the name a teacher recorded for a student)Kept with the course it belongs to, and removed when that term is.Term ends · deleted by the teacher
Quiz attempts and answersSame as the course they belong to — deleted with itCourse deletion · account closure
Teacher account and course structureKept while the account is active; deleted within 30 days of closureAccount closure
Rubrics and templatesKept while the teacher's account is active. These contain no student data and are not removed when a course or term is deleted.Account closure · deleted by the teacher
Activity log (who did what, and when)24 months, then deletedAge
Billing records (invoices, payments)7 years — retained because tax and accounting law requires it. Contains no student data.Legal requirement
Record that you agreed to these terms6 years. If you delete your account we keep the record but remove your email address, IP address and browser details — what remains cannot be read back to you.Age · kept after closure because it is the only evidence of what was agreed
Record that a deletion happened3 years. Contains the date, what kind of deletion it was and how many items were removed. It never contains a name, an email address or any student work.Age
BackupsRolling 30 days. A deletion takes effect immediately and clears backups within 30 days.Backup rotation
Data sent to an AI provider for gradingNot retained by the provider.Discarded once the response is returned

A deletion request takes effect in the live system straight away. Encrypted backups roll over within 30 days, after which no copy remains.

What we promise

  • We do not train AI models on student work. Not our own models, and no provider we use may train on it either.
  • We do not sell student data. Not to anyone, in any form, ever — including anonymised or aggregated forms.
  • We do not advertise to students, and we do not build profiles. There is no advertising in the product, and we do not profile students.
  • We use student data only to provide the service to that school. Student work is used to produce a draft grade for the teacher who uploaded it, and for nothing else.
  • We do not re-disclose student data. Beyond the subprocessors listed on this page, student data goes nowhere without the school's written authorisation.
  • A teacher reviews every AI grade before it counts. An AI grade is a draft. It counts only once a teacher confirms it.
  • We delete on request. Email privacy@critiquestudio.com and we delete within 30 days, then confirm in writing.

Access, correction and deletion

Parents and students. Under FERPA, the right to inspect and correct an education record runs through the school, not through us. Please contact your school or teacher — they can see everything we hold about a student and can export or correct it. If a school asks us for help, we respond within five business days.

Schools. Write to privacy@critiquestudio.com to request export or deletion of your students’ data. We complete deletion within 30 days and confirm in writing.

Teachers. Three controls, and each removes the stored files themselves — not just the database records:

  • Remove a student from a course — deletes the work they submitted to it, with their grades and feedback. Their work in your other courses is untouched.
  • Delete a course — deletes everything submitted to it.
  • Delete a term — deletes every course in that term and all the student work inside them. Rubrics and templates survive: they belong to the teacher and contain no student data.
  • Delete your account (Settings) — deletes every course, every file and your login.

None of these can be undone. A school can also email privacy@critiquestudio.com and we will complete a deletion within 30 days, then confirm.

Students under 13

Critique Studio is offered to schools and teachers, not directly to children. Student accounts are created only at a teacher’s or school’s direction; a child cannot sign themselves up as a student.

Where a school uses the product with students under 13, the school consents on parents’ behalf for educational use, as the FTC permits under COPPA, and is responsible for notifying parents. We do not use children’s data for advertising, and we do not build profiles for any purpose other than the grading a teacher requested.

How it is protected

  • Encrypted in transit and at rest.
  • Access is restricted so a teacher can reach their own courses and no one else's.
  • Uploaded files are private and served only through short-lived links.
  • Significant actions are recorded in an audit trail.
  • Uploads are restricted by file type and size, and Office documents are converted server-side before they are displayed.

If something goes wrong

If student data is exposed, we notify affected schools within 72 hours of discovering it, with what happened, what data was involved, and what we are doing about it. Schools may have their own deadlines to notify parents; we give them what they need to meet them.

Changes to this policy

The date at the top of this page changes whenever the substance does. If a change affects how student data is handled, we tell schools before it takes effect rather than after.