Trust and security
Pedagrade was built for instructional designers who work with confidential material. This page answers the questions a security, privacy, or accessibility review usually raises, in one place. It's written to be printed or saved as a PDF and passed along.
The short version
- Private AI. Course content is analyzed on hardware we own and operate. It is never sent to OpenAI, Anthropic, or any other AI company.
- Never used for training. Your content is never used to train or improve any model.
- Minimal retention. A free trial audit isn't saved. Signed-in users' audits are saved only to their own account, and they can delete any audit themselves.
- Encrypted in transit and at rest. Everything runs over HTTPS/TLS, and saved data is encrypted at rest.
- Stays in the United States. Course content is processed and stored in the US.
- No access to your environment. Pedagrade only sees the text a user chooses to paste or upload. No installers, extensions, or connections into your systems.
What Pedagrade is
A web application that reviews an e-learning course: it checks whether the objectives are measurable, maps each one to where it's taught, practiced, and assessed, and reviews the design against established learning-science frameworks and accessibility (WCAG 2.1 AA at the content level), with cited recommendations and suggested fixes. Users paste course text or upload a file (Word, PowerPoint, PDF, Articulate XLIFF export, or plain text).
How course content is handled
| What is sent | Only the course text a user pastes or uploads, to produce their audit. Uploaded files are converted to text for the audit; the original file isn't kept. |
| Where it's processed | On private AI hardware we own and operate. Never on a third-party AI service. |
| Training | Never used to train or improve any model. |
| Free trial audits | Processed to produce the result, then not saved. |
| Signed-in audits | Saved to the user's own account so they can reopen them. Each user can only ever access their own audits. |
| Deletion | Users can delete any saved audit themselves from their History. Account deletion on request to support@pedagrade.com. |
| Sharing | Course content is never shared with other users, sold, or shared with third parties for their own use. |
Where data lives and how it's protected
| AI processing | On Pedagrade's own server in Ohio, United States. Course text is processed in memory to produce the review. |
| Saved reviews and accounts | Supabase (Amazon Web Services, us-east-1, Virginia, United States), encrypted at rest. |
| In transit | HTTPS/TLS for every connection. |
| Who can see it | Each user can only access their own saved reviews, enforced by the database itself (row-level security). Administrative access is limited to the founder. |
| Logs | Course content is not written to the application's or the AI server's logs. |
How long we keep things
| Data | How long |
|---|---|
| Free reviews (no account) | Not stored. Processed to produce the result, then discarded. |
| Uploaded files | Converted to text for the review. The original file is never stored. |
| Signed-in reviews | Until you delete them (from History) or close your account. |
| Account | Until you ask us to delete it. Deleted within 30 days of a request to support@pedagrade.com. |
| Billing records | Kept by Stripe for as long as tax and accounting law requires. |
| Newsletter sign-up | Until you unsubscribe. After that we keep only a note not to email you again. |
| Feedback and survey answers | Kept to improve Pedagrade. Ask and we'll delete yours. |
Student data and FERPA
Pedagrade is for course design material: storyboards, scripts, objectives, and assessments. It isn't built to hold student records, so please don't upload student names, grades, or other education records. Course materials generally aren't education records under FERPA. If student information is uploaded by mistake, email support@pedagrade.com and we'll delete it within 5 business days.
Contracts and questionnaires
- Data processing agreement. We'll review and sign your DPA, or provide ours on request.
- Security questionnaires, including HECVAT and custom vendor questionnaires. Completed within 5 business days.
- NDA on request, and a call to walk your team through how data is handled.
If something goes wrong
If we confirm a security incident that affects your data, we'll notify affected customers without undue delay and within 72 hours, with what happened, what data was involved, and what we're doing about it.
Accessibility
A tool that reviews courses for accessibility should meet the standard itself. We've reviewed pedagrade.com and the app against WCAG 2.1 AA with automated and keyboard testing, fixed what we found, and published our Accessibility Conformance Report (VPAT). Screen-reader testing is next. If you run into a barrier, email support@pedagrade.com and we'll fix it.
Accounts, payments, and cookies
- Accounts use email and password, with a self-serve password reset. SSO isn't required.
- Payments for the optional Pro plan are handled by Stripe (PCI DSS Level 1). Card details are entered on Stripe's own checkout; Pedagrade never sees or stores card data.
- Cookies: a sign-in session cookie, one small cookie that limits the free trial to one audit, and, only for visitors who claim a bonus audit, one that unlocks that single extra audit. No advertising or cross-site tracking.
- Website analytics on pedagrade.com are cookie-free and aggregate only. They never run inside the app or on course content.
Service providers
Course content is processed only on our own hardware. These providers support the rest of the service. Last reviewed September 29, 2026.
| Provider | What it does | Where | Receives course content? |
|---|---|---|---|
| Supabase | Account sign-in and the database that stores signed-in users' saved reviews | United States (AWS us-east-1) | Saved reviews only, in the user's own account |
| Cloudflare | Secure network connection (TLS) to the app, and email routing | Global network | Encrypted traffic passes through; nothing stored |
| Stripe | Subscription billing | United States | No |
| Resend | Sending email, such as the opt-in newsletter | United States | No |
| Vercel | Hosts the pedagrade.com marketing website | Global network | No |
Network allow-list
If your web filter blocks Pedagrade, allow these hosts over HTTPS (port 443). There are no other domains, ports, or protocols involved.
app.pedagrade.compedagrade.compedagrade.com is a newer domain, which is the usual reason a filter flags it before its category is assigned. We're happy to help you request a recategorization.
What Pedagrade does not do
- No downloads, installers, executables, browser extensions, or local agents.
- No access to your network, file shares, mailboxes, LMS, or authoring tools.
- No use of your content for AI training, by us or anyone else.
Certifications
Pedagrade is an independent, founder-run product and does not yet hold a SOC 2 or ISO 27001 certification. We'd rather say that plainly than imply otherwise. Everything on this page describes how the service actually works today, and we're glad to complete your questionnaire or walk your team through it on a call.
Questions: support@pedagrade.com. For a team pilot or procurement: todd@pedagrade.com.
Last updated September 29, 2026.