Privacy Policy
Level Up Classroom Inc. — Last updated July 2026
1. Who We Are
Level Up Classroom is operated by Level Up Classroom Inc., an Ontario corporation. This privacy policy applies to all products operated by Level Up Classroom Inc., including LevelUpClassroom.com and OSSLTPrep.com. Our Privacy Officer can be reached at reece@levelupclassroom.com.
Data Storage Location
All Level Up Classroom data is stored on Google Firebase servers located in Toronto, Canada (northamerica-northeast2 region). Your data remains within Canadian jurisdiction and is subject to Canadian privacy laws including PIPEDA and, for Ontario school board use, MFIPPA (Municipal Freedom of Information and Protection of Privacy Act).
2. Legal Basis for Collection
Student personal information is collected under the authority of the Education Act (Ontario) and with the informed consent of the school board or institution, and/or the parent or guardian of the student. For school board deployments, the board acts as the data controller and Level Up Classroom Inc. acts as the data processor. For individual teacher use outside of a school board agreement, the teacher is responsible for obtaining parental consent using the consent forms provided within the platform.
3. Data Ownership
School boards and institutions retain full ownership of all student data. Level Up Classroom Inc. processes student data solely on behalf of the school board or teacher and does not claim any ownership rights over student records, grades, attendance data, or any other educational information entered into the platform. Students retain ownership of all content they create (assignments, essays, written responses).
4. Information We Collect
We collect only the information necessary to provide the educational service:
Teacher Accounts: Email address, display name, and authentication credentials (managed by Firebase Authentication or Google OAuth).
Student Information: First name and last name (or a pseudonymous nickname in Privacy Mode), student number, email address (optional), parent/guardian contact information (optional — name, email, phone when provided by the teacher). Ontario Education Numbers (OENs) may be stored optionally at the discretion of the school board or administrator for SIS integration purposes.
Educational Data: Grades, assessment scores, attendance records, learning skills evaluations, classroom activities, assignment submissions (Google Drive links), and OSSLT practice test responses and scores.
Quiz & Test Monitoring (soft proctoring): When a teacher enables it on a quiz, we record assessment-integrity signals during the attempt: time spent on each question and section, the number of times the browser tab or window lost focus (and total time away), blocked copy/paste attempts, and the number of times fullscreen was exited. These signals are shown only to the student's teacher to support fair assessment. No camera, microphone, screen recording, or live monitoring is ever used, and each signal is individually configurable (and can be turned off) by the teacher per quiz.
Usage Data: AI generation counts and subscription status for service operation. We do not collect browser fingerprints, IP-based location data, or device identifiers for tracking purposes.
Information we do NOT collect:
- Student home addresses or phone numbers
- Location or GPS data
- Camera, microphone, or biometric data
- Browser history or browsing activity outside the platform
- Contact lists or personal files
- Social media profiles
5. Data Minimization
We collect only the minimum personal information required to deliver the educational service. Many student fields (email, parent contact, student number) are optional and left to the teacher's discretion. Privacy Mode lets classes operate with minimal student information — no names, numbers, emails, or parent contacts required — using pre-selected nicknames. A nickname that can be re-linked to a student is still personal information under Ontario's identifiability standard.
6. How We Use Your Information
Student data is used solely for providing the educational services described in this policy:
- To enable teachers to manage their classes, record grades, and track student progress
- To provide students with access to their own grades, attendance, and class activities
- To generate AI-powered report card comments and educational content (see Section 7)
- To deliver OSSLT practice tests and Literacy Dojo exercises with automated scoring
- To facilitate communication between teachers and students within the class stream
Student data is never sold, rented, used for advertising, used for profiling, or shared with third parties for marketing purposes.
7. AI Features & Third-Party Data Processing
Level Up Classroom uses Anthropic's Claude AI for certain features. Here is exactly what data is sent to Anthropic and when:
Report Card Comments
The student's first name or preferred name is sent along with aggregate grade data (category averages, strongest/weakest areas), attendance summary counts, and learning skill ratings. No last names, student numbers, email addresses, or other identifying information are included. The teacher reviews and edits all AI-generated comments before use.
Class Emails (AI-assisted drafting)
Only the class name, teacher-written bullet points, and desired tone are sent. No student names or personal information are included.
OSSLT Essay Grading
Only the essay prompt and the student's written response text are sent. No student names or identifying information are included.
Assignment Grading Assistance
When a teacher chooses to use AI grading assistance on a submission, the student's first name or preferred name, the assignment's title and instructions, any rubric attached to it, and the student's submitted work are sent so the AI can produce a suggested mark and feedback. No last names, student numbers, or email addresses are included. This runs only when a teacher initiates it on a specific submission — never automatically, and never in the background. The suggestion is not the grade: a teacher reviews, edits and decides every mark before it is recorded. Individual students can be excluded from all AI processing (see below), which is enforced on our servers rather than in the browser.
Rubrics, Assignments, Lesson Plans, Quizzes
Only the topic, grade level, and assessment category are sent. No student data of any kind is included.
Anthropic data handling: Anthropic (a US-based company) processes AI requests on US-based servers. Anthropic's API terms state that API inputs and outputs are not used to train their models. Prompt data is not retained beyond the immediate API request lifecycle. Where a student is named at all, only a first name or preferred name is sent — never a full name, student number, or email address.
Opting a student out of AI processing
Any student can be excluded from every AI feature above, individually. Once set, no data relating to that student is sent to Anthropic for any reason. The check is enforced on our servers, so it cannot be bypassed by the browser. Ask your teacher or school administrator to set it, or contact us at reece@levelupclassroom.com.
8. Google Classroom Integration
Connecting Google Classroom is entirely optional and off by default. Nothing is read from or written to Google Classroom unless a teacher explicitly connects a course and asks us to. Teachers can disconnect at any time from Settings → Integrations, which revokes our access with Google and deletes the stored credential.
When connected, we request only the permissions needed for the features the teacher uses:
| Permission | Why we need it |
|---|---|
classroom.courses.readonly |
List your courses so you can choose which one to link. |
classroom.rosters.readonly |
Import your student roster so you don't have to retype it. |
classroom.profile.emails |
Match each Level Up student to the right Classroom student. Email is the only reliable identifier Google exposes for this, and without it grades cannot be returned to the correct student. |
classroom.coursework.students |
Import your assignments, create assignments you push from Level Up, and write marks back to them. Google only permits an application to grade coursework it created itself. |
classroom.announcements |
Import existing announcements, and post announcements you choose to publish from Level Up. |
classroom.courseworkmaterials.readonly |
Import your course materials. |
classroom.topics.readonly |
Preserve the topic each imported item belongs to. |
Limited Use disclosure
Level Up Classroom's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained from Google Classroom is:
- Never sold, rented, or transferred for advertising or any commercial purpose.
- Never used for advertising, ad targeting, remarketing, or personalization.
- Never used to train, fine-tune, or improve any AI or machine-learning model — ours or anyone else's.
- Never read by humans, except with your explicit consent, where required by law, or where strictly necessary for security or to resolve a support issue you have raised.
- Used only to provide the features in the table above, at your request.
We store the minimum required to keep the connection working: an OAuth credential (held server-side only and never exposed to the browser), the identifier of the linked course, and the identifiers of the assignments we created. Imported content becomes part of your class in Level Up and is governed by the rest of this policy.
Imported content and AI features
Once you import an assignment, it becomes an ordinary Level Up assessment — which means the AI features in Section 7 can act on it if you choose to use them. If you ask Level Up to AI-grade a submission against an imported assignment, that assignment's title and instructions, the student's first name, and the submitted work are sent to our AI sub-processor (Anthropic) to produce the suggestion. This only ever happens when a teacher explicitly invokes an AI feature — never in the background, never as part of import or grade sync — and the data is not retained by the sub-processor or used to train models. Individual students can be excluded from all AI processing, which is enforced on our servers. See Section 7 for the full AI disclosure.
Google does not give applications the contents of student file attachments — only links. Where a teacher AI-grades a submission whose attachment is a link, Level Up reads the document's text through that link in order to grade it, under the sharing permissions the student has already set.
Security, retention and deletion of Google data
Security. The OAuth credential is stored in our Firestore database in Toronto, Canada, which encrypts data at rest, and is access-restricted by security rules so that no browser or client application can ever read it — only our server-side functions can use it. It is never sent to the browser.
Retention. The credential is kept only while your Google Classroom connection is active. Content you import from Classroom becomes part of your class and follows the same retention schedule as any other class data (see Section 14).
Deletion. Disconnecting from Settings → Integrations revokes the grant with Google and deletes the stored credential immediately. Deleting your Level Up account does the same. You can also revoke Level Up's access at any time from your Google account permissions.
9. Sub-Processors
| Provider | Purpose | Data Location | Student PII Processed |
|---|---|---|---|
| Google Firebase / Cloud | Database, authentication, hosting | Toronto, Canada | Yes — all stored data |
| Anthropic (Claude AI) | AI-generated comments, grading assistance, content generation (Level Up Classroom) | United States | First or preferred name only, where a student is named at all (report comments, grading assistance) — plus the student's submitted work when a teacher requests grading assistance. Never last names, student numbers, or emails. |
| OpenAI | AI essay grading, writing feedback (OSSLTPrep) | United States | Student written responses only — no names or identifying information |
| Stripe | Subscription billing | United States | None — teacher billing only |
| Netlify | Web hosting, serverless functions | United States | Transient only — data passes through serverless functions but is not stored |
10. Privacy Mode (Pseudonymous Use)
For school boards or teachers requiring additional privacy protection, Level Up Classroom offers a Privacy Mode at the class level where:
- Students are identified by pre-defined nicknames (50 available per class)
- By default, no real names, student numbers, emails, or parent information are required
- Students log in with their nickname and a class-specific password
- Teachers may optionally link a real name for grading; when linked, it is stored and protected like any other student record
- AI features use the nickname only — no real names are transmitted
Because nickname data can be re-linked to a student, it is treated as personal information under Ontario's identifiability standard — Privacy Mode minimizes the personal information stored in Level Up Classroom, it does not render the data anonymous.
11. Children's Data
Level Up Classroom is designed for use in educational settings where students may be under 18 years of age. We do not collect personal information directly from minors without the involvement of a teacher, school, or school board. For school board deployments, the board provides consent on behalf of students as authorized under MFIPPA. For individual teacher use, teachers are responsible for obtaining parental/guardian consent using the printable consent forms provided within the platform. Parents or guardians may withdraw consent at any time (see Section 13).
12. Your Rights
Under PIPEDA and MFIPPA, you have the right to:
- Access: Request a copy of all personal data stored about you or your child
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your account and all associated data
- Export: Export class data in standard formats (CSV)
- Opt-out of AI features: Request that AI-powered features not be used for your child's data
- Withdraw consent: Withdraw consent at any time by notifying the teacher, school, or Level Up Classroom Inc. directly (see Section 13)
To exercise any of these rights, contact your teacher or school, or email us directly at reece@levelupclassroom.com. We will respond within 30 days.
13. Withdrawing Consent
Parents, guardians, or adult students may withdraw consent for data collection at any time by:
- Notifying the student's teacher, who can remove the student from the class or switch to Privacy Mode
- Contacting the school administration
- Emailing reece@levelupclassroom.com directly
Upon withdrawal, the student's personal data will be deleted within 30 days. If the student was in Privacy Mode, the stored data is minimal (nickname, marks, activity) and is deleted on withdrawal in the same way. Withdrawal of consent does not affect the lawfulness of processing performed prior to withdrawal.
14. Data Retention
- Active accounts: All data is retained for the duration of the account.
- Archived classes: Retained based on subscription plan (Free: 90 days, Basic: 90 days, Pro: 90 days, Ultra: indefinite). Expired archives are automatically deleted by a nightly scheduled process, and a record is preserved in deletion history.
- Deletion history: When teachers delete classes, students, or assessments, a recovery record is kept to allow restoration. These records are retained indefinitely unless the teacher requests full purge.
- Student contact information: On personal (non-board) classes, a student's contact details — parent name, email and phone, private notes, accommodations, government identifier (e.g. OEN) and photo — are automatically removed after the student has been inactive for 7 years. This does not affect the academic record (marks, credits, learning skills), which is retained separately.
- Academic records: Marks, credits and transcript data are retained in line with applicable education-records requirements. In Ontario, the student transcript/OSR is retained for approximately 55 years; on school board deployments the board is the records custodian and controls this retention. These records are never removed by the automated contact-information cleanup above.
- Account cancellation: Upon account deletion or subscription cancellation, all personal data and educational records will be permanently deleted. Contact reece@levelupclassroom.com to request full account deletion.
- School board data: Upon termination of a school board agreement, all student data associated with that board will be deleted within 90 days or returned in a standard format upon request.
15. Administrative Audit Logging
For school board deployments, Level Up Classroom maintains an audit log of administrative actions including staff management changes, timetable operations, and school configuration updates. Audit logs record the action performed, the identity of the administrator, and a timestamp. These logs are accessible to school administrators and are retained for the duration of the school's account.
16. Related Documents
These documents apply to all products operated by Level Up Classroom Inc., including LevelUpClassroom.com and OSSLTPrep.com.
17. Compliance
This privacy policy is designed to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), and applicable Ontario education privacy standards. If you believe we are not in compliance with any applicable privacy legislation, please contact our Privacy Officer at reece@levelupclassroom.com.
Level Up Classroom Inc. — levelupclassroom.com