Skip to main content

Student Data Privacy, Security, and Compliance

ClassLens is an AI-assistive grading and teaching tool for Google Classroom, built to fit inside K-12 district compliance requirements.

This page is for district CIOs, Technology Directors, and Data Privacy Officers reviewing ClassLens for classroom use.

Compliance at a glance

CASA Tier 2

Security assessment complete. Score 9.1 out of 10, zero Critical, zero High findings.

Google OAuth Verified

Verified by Google, including the restricted Google Drive scope.

SOC 2 Type I

Attested by Percilchofe CPA LLC (License No. 1188), as of April 4, 2026, unqualified opinion. Full report available under NDA.

FERPA School-Official Posture

Under 34 CFR 99.31(a)(1)(i)(B). ClassLens temporarily stores student submissions and drafted grading results to process grading jobs and support teacher review. These application copies expire within 48 hours. Separate grading identifiers, opt-out records, and email-related records can remain longer, as described in Privacy Policy Section 7. Where a teacher has feedback emailed, our email provider, Amazon SES, keeps addresses that bounce or draw a complaint on its suppression list until they are removed; Privacy Policy Section 7 lists those email records and the opaque grading and opt-out identifiers that can outlive a job.

Clickwrap Terms Acceptance

Affirmative consent required at sign-in, with an append-only audit log of every acceptance, kept for the life of the account.

COPPA-Aligned

Published data retention schedule for the data we hold. ClassLens is designed for teachers and authorized school staff. Students do not need a ClassLens account for their work to be graded. Sign-in does not check whether an account holder is a teacher, and an existing Classroom course is not required to explore ClassLens. The course list shows only Google Classroom courses where the signed-in account is a teacher.

Grading model

Teachers review every grade before any student sees it. There is no mode where AI-generated grades are released without teacher review.

Draft Only (default)

Grades are saved as drafts in Google Classroom. The teacher returns each grade manually through Classroom after reviewing it. In Draft Only mode, generated feedback is also available in a read-only teacher view until 24 hours from job start. ClassLens does not send that feedback to students.

Grade & Review

After grading, the teacher sees the Batch Review Dashboard inside ClassLens. They review every grade in a summary table, edit scores and comments inline, and click Return Checked to send grades to students. One click, but the teacher always sees every grade first.

Districts can request that Grade & Review be disabled entirely for their teachers, limiting all grading to Draft Only. ClassLens is best suited to rubric-graded work that a teacher reviews before students see it, and it fits low-stakes practice and formative assessment especially well. It is less suited to highly subjective creative or performance work that has no defined rubric.

Data handling

Stored on ClassLens servers

  • Teacher account data (name, email, Google ID)
  • OAuth tokens, encrypted at rest with AES-256-GCM
  • Job metadata (assignment ID, rubric, grading settings, status, timestamps)
  • Opaque Google-issued student IDs, used to detect resubmissions and to honor a per-student AI-grading opt-out where a teacher has recorded one
  • Class-wide aggregate knowledge-gap data (criterion names, met/not-met counts, teaching recommendations; no individual student names, IDs, or PII)
  • TOS acceptance log entries (immutable, IP address, user agent, timestamp)

Transient, not retained on ClassLens servers

  • Student names
  • Student email addresses
  • Student submission content
  • Student grades (written back to the teacher’s Google Classroom, not retained on ClassLens servers beyond the duration of the grading job and the deletion failsafes that back it, at the latest within 48 hours)
  • AI-generated feedback (delivered to the student as a comment on their Google Doc or as an email, or exported to a teacher-owned Google Sheet; not retained on ClassLens servers beyond the duration of the grading job and the deletion failsafes that back it, at the latest within 48 hours)

Student submission files are held in server memory for the duration of a single grading call, uploaded to a private Google Cloud Storage bucket controlled by ClassLens, referenced by Google Cloud Vertex AI via a gs:// URI for inference, and best-effort deleted from Cloud Storage after grading. A 24-hour bucket-level lifecycle policy serves as the failsafe.

Google Cloud Vertex AI under the Google Cloud Data Processing Addendum does not use submitted data to train Google's foundation models. Google formally approved Zero Data Retention (a no-prompt-logging exception) for our Vertex AI project on April 30, 2026. Eligible jobs may cache shared assignment, rubric and grading context for up to five minutes, limited to that job. Google separately caches inference inputs, outputs and derived data in project-isolated memory with a 24-hour expiry. This memory cache is not stored at rest. See Privacy Policy Section 6.1 for scope and deletion details.

During an active grading job, student names and email addresses from the selected class are held in memory so the AI can address students by first name and feedback delivery can reach the correct mailbox, and in an encrypted job cache. That cache is cleared once the job finishes successfully; a job that ends incomplete keeps its cache so the work is recoverable, and either way the 48-hour expiry is the outer bound. In Grade & Review mode they also remain in the short-lived review queue alongside the drafted grades until the teacher releases them, with a 24-hour failsafe expiry. They are not written to the database, where students are identified only by opaque Google Classroom identifiers.

In Grade & Review mode, ClassLens keeps the drafted results for teacher review, with each student's name and email address and the names, links and version details of their files. It does not keep a copy of the submission files: the review screen loads each file in the teacher's browser directly from Google Drive. This review copy is deleted when the teacher releases the grades or keeps them as drafts, with a 24-hour expiry as the failsafe. In Draft Only mode, a separate read-only copy of student display names, submission identifiers, scores, criterion results and generated feedback is available to the teacher who ran the job for up to 24 hours from the start of the job. Account deletion removes access to the Draft Only copy and attempts to delete it; if that deletion fails, the copy still expires on its own 24 hours from the start of the job. Opening it does not extend the window, and returning grades in Google Classroom does not delete it. It contains no separate student email-address field, submission files or attachment links. Generated feedback may itself include a student's name or details from their work. Sheet Export jobs do not create either teacher-review copy. The encrypted job-processing cache retains its separate 48-hour expiry failsafe. Email, provider caches and recipient mailboxes follow the separate retention periods in Section 7 of the Privacy Policy.

Google OAuth scopes

ClassLens requests the following scopes during Google sign-in. Scopes marked restricted are subject to Google's annual CASA Tier 2 security assessment. Scopes marked required must be granted for ClassLens to function; any scope not marked required is optional under Google's granular consent and degrades the related feature gracefully if denied.

openid, email, profileRequired

Standard Google sign-in. Used to create the teacher account and to show the teacher’s name and email inside ClassLens.

classroom.courses.readonlyRequired

Read the list of Google Classroom courses the teacher owns or co-teaches so the teacher can pick which class to grade.

classroom.coursework.studentsRequired

Read student submissions attached to an assignment and write back draft grades in Google Classroom.

classroom.rosters.readonly

Read the roster of a selected class so the AI can address students by first name in the teacher’s draft comments.

classroom.profile.emails

Read student email addresses for the selected class so email-delivery of teacher-reviewed feedback reaches the right student mailbox.

classroom.topics

Read and create Classroom topics so teachers can organize assignments into topics directly from ClassLens.

drive (restricted)Restricted

Read student submission files attached to Classroom assignments (Classroom-created files are not accessible via the non-restricted drive.file scope) post teacher-authored feedback as Drive Comments on the student’s document, and create the teacher-owned Google Sheet when the teacher chooses Sheets export. This is the scope that required a CASA Tier 2 assessment.

gmail.send (restricted)Restricted

Legacy Gmail sending permission may remain on an existing Google grant. Company email delivery through Amazon SES does not use or require it.

Subprocessors

Google

Google Classroom, Drive, and Sheets APIs (OAuth-scoped, teacher-authorized).

Google Cloud Platform

Vertex AI for AI inference (governed by the Google Cloud Data Processing Addendum; customer data is not used to train Google’s foundation models; Zero Data Retention formally approved by Google for our Vertex AI project on April 30, 2026) and Cloud Storage for transient submission staging (private bucket, U.S. region, 24-hour lifecycle policy). ClassLens uses Google Gemini models through Google's US multi-region Vertex AI endpoint for grading, rubric generation, and knowledge gap reports. Inference stays within the United States, rather than a single US region. Eligible jobs may cache shared assignment, rubric and grading context for up to five minutes, limited to that job. Google separately caches inference inputs, outputs and derived data in project-isolated memory with a 24-hour expiry. This memory cache is not stored at rest. See Privacy Policy Section 6.1 for scope and deletion details.

Amazon Web Services

Hosting and Amazon SES company email in us-west-1. SES processes recipient addresses and message content, including teacher-requested student feedback; suppression addresses remain until removed. Privacy Section 7 describes delivery records and mailbox copies. EBS volumes and backups encrypted at rest.

Cloudflare

Content delivery network and TLS termination.

Stripe

Subscription billing only. Stripe never receives student data.

Google Analytics 4

A fixed set of server-side conversion, public-demo and subscription-lifecycle events. Receives an opaque visitor identifier. Never receives student data, or a teacher name or email. We do not run advertising campaigns and no Google Ads account is linked to this property, so nothing reaches Google Ads.

Google Workspace (business email)

ClassLens's own transactional email: district invitations, district removal notices, contact-form, waitlist and report-request messages, and operational alerts. Receives the recipient's name and email address and the message content. Student data is never sent to this mailbox by the grading pipeline. Messages a person chooses to write to us through the contact or report-request forms reach it as typed.

Security controls

  • AES-256-GCM encryption of OAuth tokens at rest, with a versioned key format.
  • EBS volume and backup encryption at rest for all AWS storage in us-west-1.
  • httpOnly session cookies (Secure, SameSite=Lax; 7-day idle window, 30-day absolute maximum; destroyed on logout).
  • CSRF protection via a required X-Requested-With header on all mutating session requests.
  • Nonce-based Content Security Policy with strict-dynamic.
  • Redis sliding-window rate limiting on authenticated and login routes.
  • Structured logging (pino) with automatic redaction of tokens, student content, student names, and authorization headers.
  • AWS IAM roles with no static keys, CloudTrail logging, and automatic S3 lifecycle expiry of offsite backups.
  • Nginx security headers on every response: HSTS, nosniff, Permissions-Policy, Referrer-Policy, COOP, and Cache-Control no-store on authenticated routes.
  • TOS clickwrap with an append-only acceptance audit log kept for the life of the account.

Incident response

72-hour breach notification SLA to affected schools and districts. Report security concerns or suspected incidents to support@evolvedacademics.com.

Compliance documents available on request

  • We execute the SDPC National Data Privacy Agreement, or your district’s own data processing agreement. No district has executed one with us yet.
  • CoSN K-12CVAT Lite V4.1, pre-filled, 62 questions answered.
  • Security overview one-pager (PDF).
  • OAuth scope justification document.

How to approve ClassLens for your domain

If teachers in your district see “Access blocked: admin_policy_enforced” when they sign in, ClassLens has not yet been approved in your Google Workspace admin console. This is a domain-level setting: approving the app once unblocks every teacher in the organizational units you select. Either path below works.

Option 1: Install from the Marketplace (recommended)

  1. In the Google Admin console, go to Apps → Google Workspace Marketplace apps → Apps list.
  2. Click Install app and search for ClassLens, or open the Marketplace listing directly.
  3. Choose Admin install and select the organizational units, or the whole domain, that should have access.

An admin install grants ClassLens the access it needs for the selected users, so teachers in those organizational units can sign in without being blocked.

Option 2: Trust the app by OAuth client ID

  1. In the Admin console, go to Security → Access and data control → API controls.
  2. Click Manage App Access → Configure new app.
  3. Enter the ClassLens OAuth client ID:
135589175772-rj5214dbf3k43idvl10lbq03cj488qru.apps.googleusercontent.com

Select the app, then set access to Trusted.

Exact menu labels vary slightly between Admin console versions. Google's official instructions: install Marketplace apps and control third-party app access. Want a screen-by-screen PDF for your team? Email us and we'll send one the same day.

Request the full security packet

We send our SDPC National Data Privacy Agreement exhibits, K-12CVAT, security overview, and OAuth scope justification as a single PDF bundle, usually within one business day.