Last updated: August 2026
Students: full name, student ID, birth date, gender, grade level, department/class enrollment, a school email address (used for notifications like results being released, kept separate from the ID used to log in), exam answers and scores, and integrity signals during proctored exams: things like typing rhythm, fullscreen/tab-switch events, and paste attempts. We do not record keystroke content itself, only behavioral patterns used to flag possible academic integrity concerns for a teacher to review. If a teacher, supervisor, or school admin enables a text-to-speech accommodation for you, that setting is stored on your profile.
Staff (teachers, HODs, school admins): full name, email address, role, department, and two-factor authentication enrollment status (the actual authenticator secret is managed by our authentication provider, Supabase, not stored by us directly).
Organizations: organization name, contact name and email, exams and questions you create, whatever fields you configure to collect from your own respondents, and payment records (plan, amount, and a reference note for wire transfers; we never handle card numbers or bank login credentials).
Everyone: basic technical data needed to run the service, such as session tokens (to keep you logged in), and error reports sent to our error-tracking tool (Sentry) when something breaks, which may include technical context like the page you were on but is not used to build a profile of you. When an error happens, Sentry also captures a short visual replay (roughly the 60 seconds leading up to it) of what was on screen, to help us understand and fix the problem; text and media are masked by default so exam content isn't captured in the clear. We also detect repeated frustrated clicking on something that isn't responding (a "rage click") and report it the same way, with the page and element involved, so we can find and fix broken interactions.
If you use the chat assistant (the "?" icon), we store the messages you send it and its replies, so we can review and improve its answers. If you're logged in when you use it, we also store your role (e.g. teacher, student) at the time, so we know what kind of question it was answering. The assistant itself is never given access to your actual account data, exam results, or session status, only general information about how the platform works.
Two optional features use a third-party AI service (Anthropic): polishing the wording of a question a teacher is writing, and extracting questions from a PDF a teacher uploads. Both are opt-in, both only process content a staff member explicitly submits in that moment, and both produce suggestions only. A human teacher always reviews and decides whether to use the output.
The chat assistant (the "?" icon) also uses Anthropic to generate its replies. It only answers general questions about how the platform works, using information we've given it. It has no access to your account, your data, or anyone else's, and is instructed to say so and point you to a real person rather than guess if you ask it something account-specific.
When a school or organization submits a sign-up request, we also use Anthropic to draft a short internal summary of that request for our own staff to review. It's never shown to the requester, never changes what you submitted, and never approves or rejects anything on its own; a person always makes that decision. We do not use AI to grade students, make integrity determinations, or make any decision about a student without a human reviewing it first.
Within a school, access is role-based and enforced at the database level. A teacher only sees their own students and classes, a head of department only their own department, and so on. We never share student data across schools or organizations; each runs on its own isolated database.
We use a small number of service providers to actually run Smart Assess, each only with the access they need to do their specific job: Supabase (database, authentication, and file storage), Vercel (hosting), Resend (sending transactional email like password resets and notifications), Anthropic (processing exam questions you explicitly submit for AI-assisted polishing or PDF import, generating chat assistant replies, and drafting an internal summary of a new school/organization sign-up request for our staff), Sentry (error monitoring and the session replay described above), and Cloudflare Turnstile (verifying that submissions to public forms, like contact and signup requests, aren't automated bots). None of these providers can use your data for their own purposes.
We handle personal data consistent with Jamaica's Data Protection Act, 2020: we only use data for the purpose it was collected for, keep it secure, and don't retain it longer than necessary. As a data subject, you have the right to:
To exercise any of these, contact us at the email below. Students should generally go through their school, since the school is our direct customer and the party best placed to verify the request and handle guardian consent.
If we experience a data breach that affects or could affect your personal data, we will notify the Office of the Information Commissioner of Jamaica and affected individuals within 72 hours of becoming aware of it, as required by the Act. If you believe your data has been mishandled, you can also contact the Office of the Information Commissioner of Jamaica directly.