Privacy Policy
Last updated: September 2026
1. Overview
OhMyGrade (“we”, “us”) is an AI-powered exam grading platform for IGCSE and O-Level students. This policy explains what data we collect, why we collect it, and how we keep it safe.
2. Data We Collect
- Account info: Your email address, name (if provided), and Google profile data (if you sign in with Google).
- Exam submissions: The PDFs/images you upload for grading, the selected paper code, and the AI-generated grading results.
- Usage data: How many papers you've graded, timestamps, and which papers you selected (used for your dashboard history).
- Feedback: Messages you submit via the feedback form on our landing page.
3. How We Use Your Data
- To grade your exam papers and show you results.
- To display your grading history and progress on your dashboard.
- To enforce free-tier limits (2 checks per month).
- To monitor API costs and prevent abuse.
- To improve our service based on your feedback.
We do not sell your data to third parties. We do not use your data for advertising.
4. Data Storage
Your data is stored in Supabase (PostgreSQL database + file storage), hosted on secure cloud infrastructure. Uploaded answer sheets are stored in a private bucket — only you and our service can access them. Mark scheme texts are stored in our database for grading purposes.
5. AI Processing
When you submit a paper for grading, your answer sheet and the relevant marking scheme text are sent to Google's Gemini API for AI-based grading. Google processes this data according to their own privacy policy. We only send the marking scheme text (extracted from PDFs), not the original marking scheme PDFs.
6. Your Rights
- Access: You can view all your data on your dashboard.
- Deletion: You can request deletion of your account and all associated data by contacting us.
- Export: You can screenshot or save your grading results at any time.
7. Cookies & Authentication
We use essential cookies for authentication (keeping you logged in). We do not use tracking cookies, analytics cookies, or advertising cookies.
8. Analytics & Error Reporting
We use Vercel Analytics to count page views and understand which pages are used. It is cookieless and does not identify you individually.
We use Sentry to receive automatic reports when something breaks, so we can fix it. A report includes technical details about the device you were using — your browser and its version, your operating system, the approximate location and connection quality of your internet connection — along with your account email and the name, size and type of any file you were uploading at the time. We keep these details because without them we cannot tell which phone or which network a failure came from, and cannot fix it. Your login credentials are removed before a report is sent.
On our grading pages we also record a session replay: a reconstruction of what happened on your screen — the pages you moved through, what you clicked, and what was shown to you, including your marks and feedback. Anything you type into a form field, including your password, is hidden from the recording, and the paper you upload is never itself sent to Sentry. We do not record replays on our public past-paper pages.
9. Contact
Questions about privacy? Reach us via the contact page.