Our approach
Ezergrade™ is an AI-enhanced, audio-paced spelling assessment platform for homeschoolers, co-ops, microschools, tutors, and schools of all types. We collect the minimum student information needed to deliver a test and report the result to the teacher, and we treat that data with particular care. Students never create accounts, never provide email addresses, and are never tracked across websites or for advertising.
Our commitments
- Honest Input™ — we disable autocorrect, autocomplete, autocapitalize, and spellcheck on student inputs, so results reflect what the student actually spelled. In supervised test modes it also detects when a student leaves fullscreen or switches to another app or window, and records that for the teacher.
- We never sell, rent, or trade student or teacher data.
- No advertising and no behavioral profiling — we serve no ads and run no cross-site tracking.
- No training AI on your data — we select AI providers that state they do not train on API-submitted data, and configure available no-training settings.
- Designed to fully support schools' FERPA obligations, and built around COPPA principles — teachers and schools remain in control of their student records.
- Data minimization — no student emails, dates of birth, addresses, phone numbers, or government identifiers are collected from students.
- You stay in control — teachers can view, export, correct, and delete students, classes, tests, and results at any time.
- We don't keep student data indefinitely — after 24 months with no paid subscription and no sign-in we send 30 days' notice, then delete the account if it's still dormant.
- We never claim a certification until it is official — every statement on this page describes what Ezergrade actually does today.
Federal & state student privacy laws
Here's exactly how each law applies to Ezergrade — specific and verifiable, not a blanket badge. Full detail (and the "why") is in the For Schools tab of our FAQ.
- FERPA — no federal certification exists for vendors to hold; FERPA compliance is relationship-based. Under our Data Processing Agreement, Ezergrade acts as a "school official" with a legitimate educational interest, remains under the school's direct control over education records, uses data only for the disclosed purpose, and follows FERPA's redisclosure limits.
- COPPA — Ezergrade is the operator, and COPPA obligations are ours to meet, not the school's to absorb. Full detail in Children's privacy below.
- PPRA — out of scope for our product. PPRA protects sensitive survey categories (political beliefs, religion, sexual behavior, mental health, income) that Ezergrade never collects.
- State laws (e.g. Illinois's SOPPA) — our DPA carries the terms state operator-contract laws require: school-official status, reasonable security, breach notification, deletion timeframes, and breach-cost allocation. Where your state needs anything further, we'll add it to your agreement directly.
Children's privacy (COPPA)
Ezergrade is used by children, so we treat the Children's Online Privacy Protection Act as our responsibility. Ezergrade is the operator of the Service, and COPPA obligations are ours to meet — giving notice of our data practices, securing children's information, limiting how long we keep it, and honouring requests to review or delete it. We do not pass those obligations to the schools and teachers who use us.
Specifically:
- We collect the minimum. Students provide only a first name, last name, and teacher-assigned student number to identify themselves. No student accounts, no student email addresses, no birthdays, no home addresses, no phone numbers, no government identifiers.
- We never sell children's information, share it for advertising, or give it to data brokers. The providers that run the Service receive it only to support internal operations and are barred from any other use, so they are not third parties under children's privacy law. One disclosure, only if a teacher asks for it: pushing grades to Google Classroom sends each student's score to their school's own gradebook — score and the school's Google-issued identifier, never the name.
- We don't keep it indefinitely. Abandoned accounts — not covered by an active paid subscription, and no sign-in for 24 months — get at least 30 days' written notice, and are deleted if still dormant when it expires. We maintain a written retention policy stating the purpose, the business need, and the deletion timeframe for every category of data.
- We maintain a written children's information security program — a named security owner, at least annual risk assessment, safeguards scaled to the data at risk, regular testing, and annual review. We obtain written security assurances from every provider that handles children's information.
- Parents can review or delete. Email support@ezergrade.com to review, delete, or refuse further collection of your child's information. Where a school controls the record, we will help that school act on your request.
Who authorizes a child's participation depends on the setting, and holding an Ezergrade account does not by itself confer that authority. A school may authorize collection for a school-directed educational purpose. A homeschool parent or guardian authorizes their own child directly. A co-op, microschool, or homeschool program authorizes it the same way a school does, where participating families have delegated that choice. Private tutors are not currently supported for students under 13. Our Children's Privacy and COPPA notice sets out each basis, and is written so it can be shared with a school or a parent.
Schools evaluating Ezergrade can request our COPPA compliance workbook — covering how children's data flows, which providers receive it and on what basis, our security program, and our retention schedule — along with our Data Processing Agreement, by emailing support@ezergrade.com.
Where AI is — and isn't — used
The core assessment workflow — test delivery, audio playback, exact-match grading, and grade record storage — does not use AI. Grading is an objective string match: the student either spelled the word correctly or they did not.
AI is used only in specific, optional features (such as the AI Word Generator, file import, optional student spelling feedback, paper-scan OCR, and the Chat with Ezer assistant). For optional student spelling feedback, the data sent to the AI provider is the list of words, what the student typed for each, and whether it was correct. Ezergrade never adds a student's name, number, class, or grade, and answers that do not look like a single spelling word are replaced with a placeholder first. Full detail is in our Privacy Policy.
Security
- Encryption in transit — all traffic is protected with TLS/HTTPS.
- Encryption at rest — database content is encrypted at rest by our database provider.
- Access controls — Row Level Security ensures teachers can access only their own data; students can access only their own active test session.
- No student credentials — students join by class code, minimizing stored credentials and attack surface.
No method of storage or transmission is 100% secure, but we use commercially reasonable measures to protect your data, and we notify affected teachers and schools of any qualifying data breach without unreasonable delay — and no later than 30 calendar days after confirming a breach, consistent with state requirements such as Illinois's SOPPA. A fuller security overview mapped to the NIST Cybersecurity Framework is available to schools on request at support@ezergrade.com.
Accessibility
We want Ezergrade to work for every student and teacher. The product is built with accessibility in mind: test words are delivered as audio, student screens use high-contrast "chalk" colors chosen for legibility, and type is set in readable display and body fonts. Because Ezergrade is audio-paced, students who find reading difficult can hear each word rather than rely on text alone.
Accessibility is an ongoing commitment, not a finished box — we continue to improve. Our Accessibility page gives our WCAG 2.1 AA conformance summary — including exactly what our assessment covers and what it does not yet — and schools can request a detailed conformance report (VPAT®/ACR) there. If you or a student encounter an accessibility barrier, please tell us at support@ezergrade.com and we'll work to address it.
Who processes data for us (subprocessors)
We use a small set of trusted providers solely to operate the Service:
- Database and authentication provider — database hosting, authentication, real-time (United States)
- Hosting and content-delivery provider — hosting, delivery, and security (global edge network)
- Payment processor — payment and subscription processing (we do not store full card numbers)
- Enterprise OCR provider — OCR text extraction for Paper Mode answer sheets
- Google Classroom APIs — roster import and grade passback, when a teacher authorizes it
- AI provider — text and image processing for the optional AI features described above
- Transactional email provider — delivery of account and authentication emails
The current named list — each provider's identity and location — is available to any customer on request: email support@ezergrade.com. Our Data Processing Agreement also commits us to notifying you before a sub-processor changes.
For schools, co-ops & districts
We're glad to put a data-privacy agreement in place. Under that agreement, and where FERPA's school-official requirements are satisfied, Ezergrade processes education records under your direction and solely to provide the assessment and practice features you request — never for any other purpose.
- Read our Data Processing Agreement (DPA) — it's public, and agreeing to our Terms accepts it, so your school is already covered. Email support@ezergrade.com if you need a separately signed copy or want us to review your own agreement.
- Have your own agreement? If your school or district uses a standard student data privacy agreement — including the SDPC's National Data Privacy Agreement (NDPA) — send it along and we'll review it promptly.
- More questions? See the For Schools tab of our FAQ for FERPA, COPPA, state law, security, and subprocessor details.
Contact
Questions about privacy, security, or a data request? Email support@ezergrade.com. Parents and guardians can also reach out to review, correct, or request deletion of a child's data, and we'll work with the relevant teacher or school to fulfill valid requests.
Ezergrade™ is committed to protecting user privacy and providing a safe, honest assessment environment for teachers and students.