Privacy Policy

Version 2026-08-24 · Effective date: August 24, 2026

AssignHQ ("we", "us") provides tools for teachers to create, deliver, and grade assignments and assessments, including optional AI tutoring and exam-integrity features. This policy explains what information we collect, how we use it, and the choices you have. Questions: admin@assignhq.org.

Information we collect

Account information

Classroom content

Exam-integrity data (proctored assessments only)

Google Classroom data

Teachers can optionally connect their Google account to import their Google Classroom classes. If you connect, we access, with your consent, via the Google Classroom API:

We use this data only to create the corresponding classes in AssignHQ, add or invite the students on your roster, and attach co-teachers. We store your Google refresh token encrypted, and we cache roster identifiers and email addresses so re-syncing works reliably. We do not use Google user data for advertising, we do not sell it, and no humans read it except for security purposes, to comply with law, or with your explicit consent. You can disconnect Google Classroom at any time inside AssignHQ, or revoke AssignHQ's access from your Google Account security settings, and we will no longer be able to access your Classroom data.

AssignHQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we use information

Service providers

We use a small number of service providers to run AssignHQ:

These providers process data on our behalf, and under their API terms may not use it to train their models or for their own purposes.

Students and children

AssignHQ is a school service. A student uses it because a teacher assigned it, and the personal information we collect from a student is collected for that school's educational purposes and for no other commercial purpose. We do not sell student data, we do not advertise to students, and we do not use student work or grades to train any AI model, ours or a third party's. Teachers control whether students take part under their own name or anonymously.

Complying with the Children's Online Privacy Protection Act is our responsibility. It is not the school's and it is not the teacher's. Some of what we publish is written for grade levels where students are under 13, so COPPA applies to us directly. Where we rely on a school's authorization rather than contacting a parent, we ask a named person at that school who has authority over student records to confirm it, we show them what we collect before they do, and we keep a record of who authorized it and what they were shown. That record does not move any legal duty onto them.

Any school we work with, and any parent who asks their school, can find out from us: what personal information we collect from students, how we use it, who else receives it, how long we keep it, and how to review or delete it. Those answers are on this page. A school can ask us at any time to show it everything we hold for its students, to stop collecting anything further, or to delete it, and we will do that.

Students under 13 are identified by name in AssignHQ only through a school whose authorization is on record. On the Free plan there is no school to authorize, so the Free plan holds no student identity: students are known by nicknames the Service generates, every question is multiple choice, and there is no tutor and no other place a student can type free text, so the Free plan may be used with students of any age. The notice a school representative reads before authorizing is published at our school notice, and a plain-language note schools can share with parents is at a note for parents.

FERPA binds schools and districts that receive US Department of Education funding. It does not bind vendors directly. Where a school is subject to it, we act as a school official under that school's direct control: we use education records only to provide the service the school asked for, we do not pass them on to anyone else, and the school can inspect, correct, or delete them. Most private and independent schools receive no such funding and are not subject to FERPA at all, and we do not ask them to pretend otherwise.

Retention and deletion

Security

Data is encrypted in transit (TLS) and at rest by our storage providers; OAuth refresh tokens are additionally encrypted at the application level. Access to production systems is limited to the AssignHQ team.

Changes

If we make material changes to this policy we will update this page and the effective date above, and where appropriate notify account holders by email.

What changed in version 2026-08-24. Desmos is removed from the list of service providers. The graphing calculator a student can open inside an assignment is now built into AssignHQ and runs entirely in the student's browser, so opening it sends no request to anyone outside AssignHQ and shares no IP address. The previous entry described a calculator loaded from Desmos's servers; that is no longer how it works, and we are removing the entry rather than leaving it describing something that does not happen. Nothing about what we collect, who receives it, or how long we keep it has changed for anyone.

What changed in version 2026-08-20. Sentry’s entry now covers all three of our applications rather than the server alone: the web app and the desktop exam app send error reports too, scrubbed the same way — no student names, answers, grades, or assignment codes, and no session replay anywhere. No new provider and no new category of data; it means a crash on a student’s screen is something we can fix without asking the student what happened.

What changed in version 2026-08-16. Privacy classes are withdrawn. They were a class type in which a student's name was scrambled in the teacher's browser and never reached us in readable form; no school ever created one, so no data was ever held under that mode, and the clauses describing it are removed rather than left describing a thing that does not exist. Every class is now a Gradebook class, and student names, work, feedback and grades are protected the way this policy describes everywhere else: encrypted at rest under a key that exists for that school alone, with a master key held off our servers and every access to it logged where the school's own administrators can read it. Nothing about what we collect, who receives it, or how long we keep it has changed for anyone.

What changed in version 2026-08-15. The plans changed, and with them the rule about who may use AssignHQ. There is now one Free plan for individual teachers and one School plan; the paid individual plan is gone. The Free plan is built to hold no student identity: students are known by generated nicknames, every question is multiple choice, and there is no tutor and nowhere a student can type free text, so it may be used with students of any age. The previous rule that limited individual plans to grades 9 through 12, and the grade a teacher declared when creating a class, are withdrawn. Students under 13 are identified by name only through a school whose authorization is on record, which is unchanged. Stripe's entry now describes school invoicing rather than individual subscriptions. Nothing about what we collect for a school, who receives it, or how long we keep it has changed.

What changed in version 2026-08-14. Which students may use AssignHQ now depends on the plan, and the documents behind a school's authorization now exist as published pages. Previously the terms said AssignHQ was for students 13 and over everywhere, which sat badly beside a catalog that includes elementary material. Now: a school whose authorization is on record may enroll students of any age, including under 13; Free and individual paid plans, which have no school behind them, are limited to classes in grades 9 through 12, declared by the teacher at class creation and refused below that. Amazon Web Services joins the service-provider list: it holds the encryption keys that seal student data at rest (never the data itself), a design described on our security page. Two documents are newly published: the school notice a school representative reads before authorizing (the authorization record stores which version they read), and a note for parents schools can send home. Nothing about what we collect, who receives it, or how long we keep it has changed.

What changed in version 2026-08-13. This version corrects who is responsible for children's privacy. The previous text said that teachers and schools were "responsible for obtaining any consents required for their students (including under COPPA and FERPA in the United States)". That was wrong. The Children's Online Privacy Protection Act places the duty on the operator, which is us, and the Federal Trade Commission's own guidance says operators should not state anywhere that the school is responsible for complying with it. The section above now says plainly that the duty is ours. Alongside it, AssignHQ now asks a named person at a school who has authority over student records to authorise the collection of student information, and keeps a record of who authorised it and what they were shown, rather than leaving that to an individual teacher's click. We have also committed in writing to show a school everything we hold for its students, to stop collecting, or to delete it, on request. Nothing about what we collect, who receives it, or how long we keep it has changed.

What changed in version 2026-08-08. The list of AI providers is shorter, and every provider left on it is based in the United States. Mistral (France) read text out of the documents teachers upload, and Alibaba Cloud — reached through the routing service OpenRouter — was the fallback for scanned pages Mistral could not read. Both have been removed from the product, along with OpenRouter itself and the hosts Groq and Cerebras it reached. Text extraction is now Datalab, in New York, and the fallback for an unreadable page is OpenAI, which was already on this list. No student's name, email, or grade was ever sent to any of these providers, and nothing about what we collect, keep, or delete has changed. Separately, Desmos is now named: it supplies the optional graphing calculator, which has always loaded from Desmos's servers when a student opens it, and should have been listed here already.

What changed in version 2026-08-05. One addition: Stripe is named as our payment processor for paid teacher plans. Paid plans are now available, and Stripe handles the checkout. This does not change anything about student data — Stripe never receives it — and free accounts are unaffected.

What changed in version 2026-08-02. Three corrections, none of which changed the product — the text had fallen behind it. (1) The Privacy-class paragraph previously said that no stored key capable of unlocking a student name existed anywhere on our systems. We do hold an encrypted backup of that key so a teacher who loses a device can still read their own class list; it is described accurately above, and we cannot open it. (2) Gradebook classes no longer use a per-student join code — we removed it because a printed code is a bearer token, and a name is now claimed by the first device that takes it. (3) Alibaba Cloud is named as the fallback provider for reading text out of scanned documents.

Contact

AssignHQ · admin@assignhq.org