What we store, and what we never collect
This page is for teachers and the people who ask them questions — a principal, an IT director, a parent. It is a plain summary of the same facts set out in our Privacy Policy, which is the binding document.
The short version
We hold the minimum needed to run an assignment: what the teacher wrote, what the student answered, and the grade. We never collect the sensitive categories a student information system holds — no birth dates, no addresses, no parent contacts, no ID numbers, nothing about health, discipline, or eligibility.
How much we hold about a student depends on the plan the teacher is on:
School plan
Records by design, held for a school whose named representative has authorized it. Teachers enter or import their rosters, and student work, feedback, and grades are kept for the school year so the gradebook works. Everything student-linked is encrypted at rest under a key that exists for that school alone.
| Item | Stored? | Notes |
|---|---|---|
| Student's name | Yes | Entered by the teacher, or imported from the school's LMS or student information system. That is what a roster is. Encrypted at rest under the school's own key. |
| How a student is matched to a name | Yes | The student opens the teacher's link and picks their own name, or launches from the school's LMS. The first device to claim a name owns it for that assessment; a second device asking for the same name is refused, and the teacher releases it if someone picked wrong. |
| Answers, written work, and grades | Yes | Kept until the teacher or school deletes them, or the optional end-of-term cleanup runs. |
| Tutor conversations | Yes | What a student and the AI tutor said to each other on a problem, so the teacher can see where help was needed. Encrypted at rest. |
| Student email address | Only if the school provisions accounts | Most students never have one; they open a link or launch from the LMS. |
Free plan
For an individual teacher with no school agreement behind them. There is nobody to authorize us to hold student names, so the Free plan is built not to hold any: it collects no personal information from students at all.
| Item | Stored? | Notes |
|---|---|---|
| Student's name | No | There is no name field. When a student first opens an assignment we generate a two-word nickname for them ("Amber Falcon") and show it to them; nobody types a name, and the teacher's own list of who is who lives outside AssignHQ, because we offer nowhere to store it. |
| The nickname | Yes | This is the identity our servers see. The same device resumes it automatically; a new device picks it from the class list, and a claimed nickname cannot be re-picked until the teacher resets it. |
| Answers | Yes, as choices | Every question on the Free plan is multiple choice, so what we hold is which choice a nickname picked, and the score. There is no written answer, no tutor conversation, and no other place a student can type anything. |
| Anything a student wrote in their own words | No | Not possible on the Free plan. The tutor, written responses, and free-text questions are School plan features. |
| Student email address or account | No | Students never sign in on the Free plan. |
Exams with recording
Only on the School plan, and only when a teacher turns it on for a specific assessment.
| Item | Stored? | Notes |
|---|---|---|
| Screen recording | Up to 7 days | Deleted within 7 days, or when the teacher files the assessment — whichever comes first. The student sees an unmissable notice and must acknowledge it before anything is captured. |
| Webcam or microphone | No | Not captured on any plan. |
| Integrity events | Yes | Facts like "left the exam window for 40 seconds". No content. |
What we never collect, from anyone
- Dates of birth, home addresses, phone numbers
- Parent or guardian contact details
- Social security or government ID numbers, student ID numbers from your SIS
- Health, medical, disability, IEP or 504 information
- Discipline records, attendance history, free/reduced lunch or any eligibility status
- Race, ethnicity, religion, or any demographic category
- Biometrics — no face recognition, no keystroke or eye tracking, no voice prints
- Location data
- Anything from a student's device beyond the exam window they are shown
There are no fields for these anywhere in the product. It isn't a setting we leave off — the columns don't exist.
What we never do with what we do hold
- We never sell it or rent it. Not to anyone, for any purpose.
- We never advertise to students, or build a profile of a student for anything but showing their teacher their work.
- We never train AI models on student work, and our AI providers are contractually barred from doing so with anything we send them.
- AI never grades and never sees a grade. It helps a teacher write questions and answer keys, and tutors students on problems. A student's name, email and grade are never sent to an AI provider.
Who else touches it
We use a small number of service providers to run the product — hosting, database, error monitoring, transactional email, AI providers, and payment processing by Stripe for schools that pay by card, which never receives student data. Each is named individually in the Privacy Policy, along with what it receives. They act on our instructions and may not use anything for their own purposes.
Jurisdiction is worth calling out here because reviewers ask: every provider that can see a teacher-uploaded document is based in the United States. A scanned page goes to Datalab, in Brooklyn, New York, to have its text read, with their data-retention setting turned off; if a page defeats it, the image falls through to OpenAI. Each receives the page and nothing else, and neither may use it for its own purposes. Until August 2026 that fallback was a model hosted by Alibaba Cloud and the primary reader was Mistral, in France; we removed both, so no teacher document leaves the United States today. We mention it rather than quietly rewriting the page, because a district that reviewed us in July read the older answer.
Getting it back, or getting it deleted
- Export any time. Grades and work download as a spreadsheet and a file bundle; you don't need our permission or our help.
- Ending a record's life. A teacher can archive a class at any time, and can file an assessment — which exports the grades and then deletes the student-linked records behind them. There is no one-click "delete this class" button today, so a request to delete specific records goes to admin@assignhq.org: include the class name and the assessment title, and we honor it within 30 days and confirm in writing that it is done. Deleting an account removes the account and its classes; work a student already turned in stays with the teacher whose gradebook it is, which is a deliberate choice and not an oversight.
- Backups. Deleted rows can sit in our database provider's encrypted backups for up to 7 days before those expire too. We say this plainly rather than claiming instant erasure, because instant erasure isn't how backups work at any company.
- Legal holds. If a school needs records preserved — a parent's records request, for example — a teacher can place a hold from the assessment itself, and that pauses every deletion clock on it. The hold runs until it is lifted, or until the end date the person placing it set; we default that date to 90 days rather than leaving it open, because an abandoned hold is student work we promised to delete and kept instead.
For an administrator reviewing us: our Terms of Service carry the education-records commitments schools typically ask for, including the FERPA school-official and direct-control terms, no-sale and no-AI-training commitments, deletion and breach-notice obligations, and a clause making any signed district agreement control over them. If your district uses the SDPC National DPA or a state template, send it over — we'd rather sign yours than argue about ours.