Level Up Classroom
Privacy by design

What we do with your students’ data

Four specific things, each of which you can hold us to — and, at the bottom, the limits. Written by the teacher who builds it, for the person at your board who has to sign off on it.

1. The AI never learns their name

When you generate a report card comment or ask for a suggested mark, the student’s name is replaced with a placeholder before the request leaves your browser, and put back in the answer after it returns. The model is asked about “Student A”. You read the real name. The substitution is reversed on your own device, on text that never went anywhere.

The name is taken out of the submitted work too, not just the name field — an essay that begins “By Amelia Nguyen” would otherwise defeat the whole exercise.

2. No camera. No microphone. Ever.

Online tests are kept honest without watching anyone. There is no webcam proctoring, no microphone, no screen recording and no third-party invigilator — nothing in a student’s test ever opens a camera. Instead every student can get a different version of the same test, which removes most of the reason to watch them in the first place.

What is recorded is behavioural and shown to you afterwards: time per question, tab switches, blocked paste attempts. Every one is a toggle you control, students are told before they start, and nobody is locked out mid-test by an algorithm deciding they look guilty.

How the testing works →

3. Students are never tracked. At all.

No analytics, no advertising pixel, no measurement of any kind runs for a signed-in student. Not reduced — off.

And it is enforced rather than assumed: if a teacher has consented on a shared classroom computer and a student then signs in on it, the running tag is actively switched off for that session. The usual failure here is a product that declines to start tracking a student while happily continuing a session that was already going.

4. The sensitive fields are kept apart

A class record is readable by the students in that class — that is how a student sees their own marks. So the fields that must not be are held somewhere else entirely: OEN, parent name, parent email, parent phone, accommodations, your private notes, and report comments all live in a separate teacher-only record, stripped from the class document on every single write.

Everything is stored in Canada — Google Cloud’s Toronto region.

And here is what this does not do

Removing the name does not make a request anonymous, and we will not tell a school that it does. Pseudonymised data is still personal data under PIPEDA and under GDPR, because it can be reversed — and here it is reversed by design, since you need the real name back.

What still goes to the AI on a grading request: the student’s actual work, their marks, a summary of their past results, and whatever you wrote in your own notes. A note reading “since her family moved from Sudbury in October” identifies a child perfectly well with no name attached. An uploaded photo or PDF is sent as a file and is not rewritten, so a name handwritten at the top of the page does go.

This reduces exposure. It does not eliminate it. Any vendor telling you otherwise is either not thinking about it or hoping you are not.

The full legal detail lives where it should:

Built by a teacher, in Ontario

Because the person who has to defend this to a principal is also the person who wrote it.

Start free — no credit card