Privacy Policy

Last updated: August 2026

Data categoryCollected fromUsed forSold or used for ads?
Identity & contactStudents, staff, orgsLogin, communication, class rostersNever
Exam content & answersStudents, teachers, orgsDelivering, grading, and reporting on examsNever
Exam integrity signalsStudents (during proctored exams)Flagging possible integrity concerns for a teacher to reviewNever
Payment recordsSchools, organizationsBilling (plan, amount, reference note only, never card or bank login details)Never
Technical & error dataEveryoneKeeping you logged in, diagnosing bugs (including short screen replays and click-frustration signals to help us find and fix problems)Never
Chat assistant messagesEveryone (site visitors and logged-in users)Answering questions and reviewing/improving the assistant’s answersNever

Who this applies to

Smart Assess ("we", "us") is an exam and assessment platform used by schools, their students and staff, and by organizations running one-off assessments. Schools and organizations are our direct customers; students and staff use the platform through their school's account. This policy covers all of them.

What we collect

Students: full name, student ID, birth date, gender, grade level, department/class enrollment, a school email address (used for notifications like results being released, kept separate from the ID used to log in), exam answers and scores, and integrity signals during proctored exams: things like typing rhythm, fullscreen/tab-switch events, and paste attempts. We do not record keystroke content itself, only behavioral patterns used to flag possible academic integrity concerns for a teacher to review. If a teacher, supervisor, or school admin enables a text-to-speech accommodation for you, that setting is stored on your profile.

Staff (teachers, HODs, school admins): full name, email address, role, department, and two-factor authentication enrollment status (the actual authenticator secret is managed by our authentication provider, Supabase, not stored by us directly).

Organizations: organization name, contact name and email, exams and questions you create, whatever fields you configure to collect from your own respondents, and payment records (plan, amount, and a reference note for wire transfers; we never handle card numbers or bank login credentials).

Everyone: basic technical data needed to run the service, such as session tokens (to keep you logged in), and error reports sent to our error-tracking tool (Sentry) when something breaks, which may include technical context like the page you were on but is not used to build a profile of you. When an error happens, Sentry also captures a short visual replay (roughly the 60 seconds leading up to it) of what was on screen, to help us understand and fix the problem; text and media are masked by default so exam content isn't captured in the clear. We also detect repeated frustrated clicking on something that isn't responding (a "rage click") and report it the same way, with the page and element involved, so we can find and fix broken interactions.

If you use the chat assistant (the "?" icon), we store the messages you send it and its replies, so we can review and improve its answers. If you're logged in when you use it, we also store your role (e.g. teacher, student) at the time, so we know what kind of question it was answering. The assistant itself is never given access to your actual account data, exam results, or session status, only general information about how the platform works.

Why we collect it

Strictly to run the platform: authenticating you, delivering and grading exams, routing work to the right teacher, detecting technical issues, and (for organizations) billing. We do not use student or staff data for advertising, and we do not sell personal data to anyone, ever.

Our use of AI

Two optional features use a third-party AI service (Anthropic): polishing the wording of a question a teacher is writing, and extracting questions from a PDF a teacher uploads. Both are opt-in, both only process content a staff member explicitly submits in that moment, and both produce suggestions only. A human teacher always reviews and decides whether to use the output.

The chat assistant (the "?" icon) also uses Anthropic to generate its replies. It only answers general questions about how the platform works, using information we've given it. It has no access to your account, your data, or anyone else's, and is instructed to say so and point you to a real person rather than guess if you ask it something account-specific.

When a school or organization submits a sign-up request, we also use Anthropic to draft a short internal summary of that request for our own staff to review. It's never shown to the requester, never changes what you submitted, and never approves or rejects anything on its own; a person always makes that decision. We do not use AI to grade students, make integrity determinations, or make any decision about a student without a human reviewing it first.

Who we share it with

Within a school, access is role-based and enforced at the database level. A teacher only sees their own students and classes, a head of department only their own department, and so on. We never share student data across schools or organizations; each runs on its own isolated database.

We use a small number of service providers to actually run Smart Assess, each only with the access they need to do their specific job: Supabase (database, authentication, and file storage), Vercel (hosting), Resend (sending transactional email like password resets and notifications), Anthropic (processing exam questions you explicitly submit for AI-assisted polishing or PDF import, generating chat assistant replies, and drafting an internal summary of a new school/organization sign-up request for our staff), Sentry (error monitoring and the session replay described above), and Cloudflare Turnstile (verifying that submissions to public forms, like contact and signup requests, aren't automated bots). None of these providers can use your data for their own purposes.

How long we keep it

School and student data is retained for as long as your school's subscription is active, plus a reasonable period afterward in case of billing disputes or reinstatement. Anonymous organization respondent data is deleted automatically after a retention period your organization configures per exam. You can request deletion of your data at any time by contacting us (see below).

How we protect it

Every table in our database enforces row-level security, meaning access rules are checked by the database itself, not just by application code. Staff accounts require two-factor authentication. All traffic is encrypted in transit (HTTPS). We do not store card or bank login details. Payments are either handled by a third-party processor or via manual bank transfer with a reference note only. We also run periodic internal security reviews of the platform.

Students and children

Many of our users are minors. We collect the minimum student data needed to run exams and report results, and access to it is scoped to the student's own school. Because students use Smart Assess through their school, the school (as our direct customer) is responsible for obtaining any parental or guardian consent required under its own policies and applicable law before enrolling a student.

Your rights under Jamaica's Data Protection Act

We handle personal data consistent with Jamaica's Data Protection Act, 2020: we only use data for the purpose it was collected for, keep it secure, and don't retain it longer than necessary. As a data subject, you have the right to:

  • Know what personal data we hold about you and why
  • Request a copy of it
  • Ask us to correct it if it's inaccurate
  • Ask us to delete it, subject to any legal or billing retention requirements
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these, contact us at the email below. Students should generally go through their school, since the school is our direct customer and the party best placed to verify the request and handle guardian consent.

If we experience a data breach that affects or could affect your personal data, we will notify the Office of the Information Commissioner of Jamaica and affected individuals within 72 hours of becoming aware of it, as required by the Act. If you believe your data has been mishandled, you can also contact the Office of the Information Commissioner of Jamaica directly.

Cookies and local storage

We use browser storage (cookies/local storage) to keep you logged in, and, for student accounts, to remember a device token used to enforce single-device login (a student can only be signed in on one device at a time; logging in elsewhere signs out the other session). The desktop app and exam-taking pages also store exam answers locally on your device (using your browser or OS's built-in storage) so nothing is lost if your internet connection drops, syncing to our servers once you're back online.

Changes to this policy

If we make a material change to how we handle data, we'll update the date at the top of this page and, where appropriate, notify school administrators directly.

Contact us

Questions about this policy, or requests to access or delete your data, can be sent to privacy@smartassessja.com.

Read our Terms of Service →