Closed-test notice

Where data goes in MarkCTRL

Current, code-verified summary for protected testing. Updated August 19, 2026. Version beta-data-notice-2026-08-19.

Do not use real student data yet.

Final Terms of Service, Privacy Policy, Acceptable Use Policy, retention schedule, privacy contact, and school/minor agreements are not approved. This notice is not a substitute for them. Use synthetic or properly de-identified test material only. Student-facing use and any use involving someone under 18 remain blocked.

Current storage and processing locations

  • Supabase: authentication plus PostgreSQL account, course, assignment, rubric, submission, grade, feedback, and settings records. Current database hostname identifies AWS us-east-2 (Ohio, United States).
  • Render: backend requests, application logs, rate-limit state, and temporary Redis cache. Repository blueprint does not set a region; Render documents Oregon as default for an omitted blueprint region. Production region must still be confirmed in Render dashboard.
  • Vercel: website hosting, CDN delivery, and web request logs. Static assets use global CDN. Vercel documents Washington, D.C. as default function region; production settings must still be confirmed.
  • Email: recipient address, delivery metadata, and operational message content may go to Resend or configured SMTP provider. Active production provider and region are not yet verified.

What AI providers receive

Google Gemini is primary AI and document-reading provider. Requests may include rubrics, answer keys, educator instructions, example papers, submission text, original PDF/image bytes, prompts, and generated feedback. Groq is text fallback; current design sends extracted text and grading context, not original images.

Google states paid Gemini API prompts and responses are not used to improve its products, while unpaid-service content may be used for product improvement and human review. MarkCTRL billing status and data controls are not yet verified. Groq says inference data is not retained by default, but may be held up to 30 days for reliability or abuse review unless zero-data-retention controls apply.

AI output can be wrong, incomplete, inconsistent, or biased. Educators must review every score and comment before release. AI must not make final academic decisions.

Retention and deletion today

  • Original uploaded submission bytes remain in live PostgreSQL until feedback is released, then code clears those bytes and MIME type.
  • Extracted text, course records, submissions, grades, feedback, and settings do not yet have automatic expiry.
  • No complete self-service account deletion exists.
  • Database backup expiry, hosting log retention, and email-provider retention are not yet verified.
  • A data export exists, but complete privacy-request export coverage has not been verified.

Browser and account data

Supabase auth cookies and tokens keep users signed in. MarkCTRL also stores an access token in browser local storage and a short-lived browser cookie, an activity timestamp cookie for idle logout, theme preference in local storage, and local grading-timer state. Current app code contains no advertising SDK or product analytics SDK.

Known launch blockers

Operator legal identity, service address, monitored privacy/legal/security contacts, governing law, final retention rules, vendor agreements, AI account tier, school authority, student age model, and international transfer terms still need approval. Google Gemini API terms effective March 23, 2026 also restrict API clients likely accessed by people under 18. Production student use cannot proceed until this is resolved.

Provider evidence