Privacy Policy
This Privacy Policy describes how Groves Holdings LLC, doing business as GradePath ("GradePath," "we," "us," or "our"), handles information when you use GradePath's website, iOS app, support, and related services.
Raw audio, raw transcripts, and capture transcripts stay private to the account owner. They are not Course Commons posts and are not available to other students. Only a separate derivative that a user deliberately reviews and submits may enter the exact-course Commons workflow.
1. Information we collect
Account and course context
We may collect your name, email address, authentication records, account identifiers, institution, academic term, course, section, membership status, profile settings, and support history.
Private Content
"Private Content" includes private notes, raw classroom recordings, raw and capture transcripts, derived private notes, uploaded or imported study material, Tutor questions and responses, citations, and related source and editing history. A classroom recording can contain your voice and instructor or classmate voices, names, comments, and other information spoken nearby. GradePath does not use voice data to identify people biometrically.
Course Commons and safety data
When you deliberately contribute a derivative to Course Commons, we process the derivative, its exact institution, course, section, and term scope, contributor display choice, rights attestation, source lineage, revisions, publication state, imports, helpful feedback, reports, blocks, moderation actions, takedowns, and appeals. Shared material is supplemental student material, not official instructor or institution content.
Referral and contribution data
We may process invite and referral codes, referring and referred accounts, verified paid-subscription status, verified university, contribution activity, helpful feedback, and fraud or duplicate-activity signals.
Purchases and billing
For App Store purchases, we receive transaction identifiers, product, entitlement, renewal, cancellation, refund, and settlement-report status from Apple. Apple handles the payment method. For a direct web subscription processed by Stripe, we may receive customer, subscription, invoice, payment-status, settlement, refund, dispute, and limited billing details. Stripe handles full card details.
Device, analytics, and support data
We may collect IP address, device and browser characteristics, app version, timestamps, crash and error data, and messages or attachments you send to support. Website page and feature interactions, performance, and heatmaps are sent to PostHog only after you select Allow analytics. Session replay is disabled. See our Cookie Policy for website analytics details.
2. How we receive information
We receive information directly from you, from your device when you use a feature, from other GradePath users when they interact with a Commons contribution, and from providers involved in a feature you choose. Those providers can include Apple for App Store purchases, Stripe for direct web billing, Google or Apple for authentication where offered, OpenAI and Anthropic for AI processing, and our hosting, analytics, and error-monitoring providers.
3. Why we use information
- Provide account access, private Capture, transcript, note, Tutor, Course Commons, referral, contribution, purchase, and support features.
- Keep Course Commons limited to an authorized exact course, section, institution, and term.
- Review rights attestations, reports, blocks, fraud signals, moderation state, takedowns, and appeals.
- Maintain subscriptions and entitlements, prevent abuse, secure the service, diagnose failures, and improve reliability.
- Meet legal obligations and respond to valid legal requests.
4. AI processing
If private transcription is enabled and you request it, GradePath sends the selected audio to OpenAI for transcription. Tutor and other AI-assisted study features may send your prompt, authorized source excerpts, private transcript or note text, limited course context, and prior conversation context to OpenAI or Anthropic. Provider selection can vary by feature, availability, and routing. We do not send content to an AI provider merely because it exists in Course Commons.
GradePath does not use Private Content to train a GradePath model. Third-party processing, retention, and training rules depend on the provider agreement and the configuration actually enabled for GradePath. See the AI Disclosure and Subprocessors page.
5. When information is disclosed
We disclose information to service providers only as needed to operate their function, to other authorized exact-course members when you deliberately contribute an eligible Commons derivative, to Stripe for direct subscription billing and fraud controls, during a business transaction subject to appropriate safeguards, or when required to protect people, enforce our rules, or comply with law. We do not sell personal information and do not use it to serve targeted advertising.
Any third party with whom GradePath shares user data must provide the same or equal protection of that data as described in this Privacy Policy and required by applicable App Store guidelines.
6. Private and shared visibility
Saving, recording, transcribing, generating, or editing Private Content does not publish it. Sharing requires a separate Course Commons submission. A submitted exact-course Commons derivative can be reviewed, formatted, moderated, and shown to other authorized members of that exact course scope. You must never submit raw audio, a raw transcript, a capture transcript, private Tutor history, another person's personal information, or content you lack permission to share.
7. Current retention boundaries
- Local raw audio: a protected device copy can remain until upload completes or you delete the capture. A file that cannot upload can remain on the device until you delete it.
- Server raw audio: the current service assigns uploaded raw audio a retention expiration 30 days after capture consent is recorded. It can be scheduled for earlier deletion when you request deletion. Deletion can remain pending while retries complete.
- Transcription requests: a request cannot outlive the related raw-audio retention deadline. Provider-side handling depends on the provider account and contract actually configured.
- Private transcript text, notes, and Tutor history: these are generally kept while the account or content remains active, until you delete the item where a control is available or request deletion through support.
- Commons and trust records: a contribution can be unpublished or removed from active access. Rights, provenance, revision, report, block, moderation, takedown, and appeal records may be retained to document actions, protect users, and resolve disputes.
- Billing records: subscription settlement evidence, provider events, refunds, reversals, fraud decisions, and tax or accounting records may be retained as required to resolve disputes, prevent duplicate charges, and meet legal duties.
- Referral, security, and legal records: we may retain limited records for chargebacks, fraud prevention, legal claims, and enforcement. Backup deletion may lag behind deletion from active systems.
The current product does not promise one universal deletion time for every data category. Contact support for an account or data deletion request.
8. Your choices and requests
You can choose not to record, not to request transcription or AI processing, and not to contribute a Commons derivative. You can unpublish eligible Commons content, use available report and block controls, and manage a subscription through the provider that billed you. To request access, correction, export, or deletion, email [email protected]. We may need to verify your identity and may retain billing and legal records that cannot lawfully or safely be deleted immediately.
9. Children and education records
GradePath is designed for college students and is not directed to children under 13. Users under 13 may not use the service. GradePath does not offer an institution-contracted education-records program or a child-directed classroom service.
10. Security and transfers
We use access controls, private storage, encrypted transport, device file protection, and other safeguards appropriate to the product design, but no service can guarantee absolute security. Providers may process information in the United States and other places where they operate, subject to their terms and our configuration.
11. Changes and contact
We may update this Privacy Policy as the product, providers, or data practices change. The date at the top identifies the current version. Questions and privacy requests can be sent to [email protected].