Privacy Policy

At IntelliAssess, we value your trust and are fully committed to protecting your privacy. This policy outlines how we collect, process, secure, and retain your data when you use our AI-powered online assessment, identity verification, and proctoring services.

1. Information We Collect & Process

We collect information that you directly provide to us, as well as data automatically generated during exam sessions:

  • Account & Roster Information: Names, email addresses, roles (Admin/Teacher/Student), and student invitations sent by instructors.
  • Assessment Data: Questions, student answers, grading rubrics, exam scores, and uploaded PDF/document course materials (which are indexed in our vector databases).
  • Proctoring & Device Data: Webcam snapshots, selfie enrollment files, audio noise metadata, browser active window/blur state events, and clipboard blocker alerts.
  • Billing Information: All subscription transactions are processed securely through Stripe. We do not store credit card credentials on our servers.

2. AI & Automated Processing

IntelliAssess uses advanced artificial intelligence to automate grading, generate assessments, and audit exam logs. For example, student submissions are evaluated using LLM systems aligned with specific rubrics uploaded by instructors. To prevent algorithmic bias, human instructors retain final approval rights and can override any AI-generated marks or comments at any time.

3. Proctoring, Audio, & Exam Security

When proctoring is enabled by an administrator, we monitor the testing environment to prevent exam manipulation:

  • Webcam Face Verification: We collect a startup selfie enrollment image. During the exam, webcam snapshots are analyzed via AWS Rekognition to check for facial absences, coverage, multiple faces, or identity mismatches.
  • Audio Proctoring: We analyze microphone inputs for sustained high ambient noise levels or secondary voices. Audio is analyzed in-memory to detect irregularities; no continuous audio files are permanently recorded.
  • Browser Locks: Our environment security restricts clipboard actions (copy/paste), detects window size changes, checks when the student navigates away from the exam tab, and flags if developer debugging tools are opened.

4. Personal API Keys & BYOK Storage

If an administrator configures the application to use their own third-party keys (Bring Your Own Key - BYOK mode) for OpenAI, Groq, or Gemini, these keys are stored securely using encryption. They are strictly used to run AI generations authorized by the key holder and are never shared or used for other accounts.

5. How We Share Data

We do not sell, rent, or trade your personal information. Data is only shared with authorized sub-processors necessary to run the service:

PartnerPurpose
StripeSubscription billing and transaction processing.
OpenAI / Groq / GeminiAI question generation and grading assistant pipelines.
Amazon Web Services (AWS)Cloud infrastructure, hosting, database storage, and AWS Rekognition.

6. Data Retention Policies

We retain your information in accordance with our retention policy:

  • Account & Assessments: Retained for as long as your account remains active. An administrator can delete assessments, libraries, and student rosters at any time.
  • Proctoring Logs: Images, event warnings, and device logs collected during proctoring sessions are archived and automatically deleted after **90 days**.
  • System Backups: System backups are retained in secure storage for a maximum of 30 days.

7. Security Safeguards

We implement comprehensive technical and organizational safeguards to secure your data, including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256).
  • Database level security, utilizing parameterization to prevent SQL injections and utilizing clean CORS policies.
  • Access control lists ensuring that student details and rosters are only visible to the designated teacher or organization administrator.

8. Your Data Rights

Depending on your location, you may have rights under the GDPR, CCPA, or other local privacy regulations:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Deletion: You can request the deletion of your account and related data.
  • Right to Correction: You can update inaccurate profile details directly from the dashboard settings.

9. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of your rights, please reach out to our team at:

Email: support@intelliassess.ai

10. Google User Data

IntelliAssess integrates with Google Classroom so that teachers can publish assessments to their classes, sync rosters, and send grades back to Classroom. This section explains exactly what Google data we access, why we access it, how long we keep it, and what we never do with it.

Connecting a Google account is entirely optional. IntelliAssess works fully without it, and no Google data is accessed unless a teacher explicitly signs in with Google and grants permission on Google's own consent screen.

10.1 What we access and why

Google permission we requestWhat it lets us read or writeWhy we need it
classroom.courses.readonlyThe names and IDs of courses you teachSo you can choose which class to publish an assessment to
classroom.rosters.readonlyThe list of students enrolled in a course you selectTo create a matching student group in IntelliAssess
classroom.profile.emailsEmail addresses of students and co-teachers in that courseTo match each Classroom student to the correct IntelliAssess account, so grades go to the right person
classroom.profile.photosStudent profile photo URLsTo show familiar faces in the roster list while you work
classroom.coursework.studentsCreate assignments, read submission states, write grades and rubrics backThe core feature: publishing an assessment and returning its grade to Classroom
classroom.announcementsPost an announcement to a courseTo notify a class that a new assessment is available
drive.fileOnly the individual Google Forms you personally select in Google's file pickerTo import those specific forms into IntelliAssess

We request the narrowest permission that makes each feature work. Where a read-only version of a permission exists and is sufficient, we use it.

For Google Drive we deliberately use drive.file rather than a broader read-only Drive permission. It gives IntelliAssess access only to the individual files you choose in Google's own file picker. IntelliAssess cannot see, list, search, or open any other file in your Drive.

10.2 How your Google sign-in is handled

We never store your Google password, and we never store long-lived Google credentials on our servers.

When you connect Google Classroom, the authorisation happens in your browser against Google directly. Google returns a short-lived access token that:

  • is held only in your browser's session storage for the current session;
  • is sent to the IntelliAssess server on a per-request basis, used immediately to make the Classroom call you asked for, and then discarded;
  • is never written to our database, never written to our logs, and never kept after the request finishes;
  • expires on its own, typically within one hour;
  • is destroyed when you close the browser tab.

We do not use Google refresh tokens, so IntelliAssess cannot access your Classroom data in the background when you are not actively using the product.

10.3 What we store, and for how long

When you sync a course roster, we store the following in your IntelliAssess account so the class list persists between sessions:

  • Each student's email address and display name, which become their IntelliAssess student record.
  • The group or class the student belongs to.
  • The Google Classroom course ID, assignment ID, and submission ID, which are non-personal reference numbers used to send the right grade back to the right assignment.
  • The time and status of each grade sync, so we can show you what succeeded and retry what failed.

We do not store student profile photos (they are displayed live from Google and never saved), course content, announcements, or any Classroom data beyond what is listed above.

For Google Forms import, we read only the forms you explicitly select in the Google file picker and store the resulting questions inside your IntelliAssess account. Because we use the drive.file permission, we have no technical ability to scan, index, list, copy, or retain any other file in your Google Drive.

Stored Google-derived data is kept for as long as your IntelliAssess account is active. When you delete your account, or when you ask us to delete the data, it is removed from our production systems within 30 days and from backups within 90 days.

10.4 Artificial intelligence and your Google data

IntelliAssess uses third-party AI services (OpenAI, Anthropic, and Google Gemini) to grade assessment answers and generate feedback.

Personal data obtained from Google APIs is never sent to any AI model. When an answer is graded, the AI receives only the question text, the grading rubric, and the answer content itself. It does not receive student names, student email addresses, Google account identifiers, course names, or any other Classroom data.

We do not use Google user data to develop, improve, or train generalised AI or machine learning models, whether our own or a third party's.

10.5 Sharing and human access

We do not sell Google user data. We do not transfer it to advertisers, data brokers, or any party for advertising, marketing, or credit-scoring purposes.

Google user data is not read by IntelliAssess staff, except in these narrow cases:

  • With your explicit prior consent, for example when you ask us to investigate a support issue on your account.
  • Where necessary for security purposes, such as investigating suspected abuse or a security incident.
  • To comply with applicable law.
  • In aggregated, fully anonymised form, for internal statistics such as counting how many syncs ran.

10.6 Limited Use commitment

IntelliAssess's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10.7 Student data and minors

IntelliAssess is used in schools, and Classroom rosters may contain data about students under 18. Teacher and school accounts act as the data controller for their students; IntelliAssess acts as a processor on their behalf. Student data synced from Google Classroom is used solely to deliver assessments and return grades to the school. It is never used for advertising or profiling, never used to build advertising profiles, and never sold.

10.8 Revoking access

You can disconnect IntelliAssess from your Google account at any time at myaccount.google.com/permissions. Revoking access immediately stops all future Classroom syncing.

Revoking access does not by itself erase the roster data already saved in your IntelliAssess account. To have that deleted as well, email support@intelliassess.ai and we will remove it within 30 days.

10.9 Contact

Questions about how IntelliAssess handles Google user data:

Email: support@intelliassess.ai