Privacy Policy
Privacy Policy
Last updated: 2026-07-30
This privacy policy describes how Instagrity collects, uses, stores, shares, and protects user data. It covers the core service and explains how Instagrity handles data from external providers such as Google, Microsoft, Stripe, OpenAI, and compatible AI assistants when those integrations are connected.
- Product data
- Accounts, classes, essays, annotations, grading records, external-provider data where connected, and support submissions
- Data sales
- Instagrity does not sell student, classroom, or external-provider user data
- Visible service providers
- Supabase, Vercel, OpenAI, Stripe, Google, Microsoft, Resend, and similar providers where enabled; contractual roles require review
- School review
- Schools assess deployment requirements while Instagrity keeps its stated privacy, security, deletion, and limited-use commitments
Instagrity may store account details, profile names, class and roster information, assignment details, essay text, feedback data, annotations, premium entitlement records, support submissions, and system activity records required to operate the service. When external-provider integrations are connected, Instagrity also stores the provider-specific data described in the External provider data section below.
Instagrity connects to external providers only when a user or authorized organization chooses to enable those features. The specific data accessed and how it is used depends on the provider and the feature being used.
When you use Google with Instagrity, the Google user data Instagrity accesses depends on the feature you choose to connect.
Google Sign-In. Instagrity may receive your Google account email address and Google account identifier to authenticate you, create or locate your Instagrity account, protect account access, and route you into the correct teacher, student, or admin workspace.
Google Drive import. Instagrity may receive your Google account email address, basic profile information, Google account identifier, selected file metadata, and the contents of files you explicitly select through the Google Drive Picker or an equivalent Google file-selection flow. Instagrity uses this data to import files you choose as classroom materials, assignment materials, or student-submission attachments.
Google Classroom integration. Instagrity may receive your Google account email address, basic profile information, Google account identifier, course lists, course metadata, roster information (Google Classroom user identifiers and student display names), grade-category data, coursework metadata, due dates, links, and related Classroom identifiers. Instagrity does not import or collect Google Classroom student email addresses. Instagrity uses this data to help teachers or authorized school users connect classes, map Google Classroom courses to Instagrity classes, preview or import rosters as Google Classroom roster placeholders, map categories, and import or sync coursework where the integration is enabled. Roster placeholders are matched to Instagrity student accounts when the student signs in or connects their Google account.
How Instagrity uses Google user data. Instagrity uses Google user data only to provide and improve user-facing Instagrity features that the user or organization authorizes. Google user data is used for authentication, account identity, selected Google Drive file import, Google Classroom course and class mapping, roster preview, import, and roster placeholder matching, category and coursework mapping, import, and sync, and for security, abuse prevention, support, audit, and legal compliance where needed.
No sale of Google user data. Instagrity does not sell Google user data.
Prohibited uses. Instagrity does not use Google user data for targeted advertising, personalized advertising, retargeting, interest-based advertising, selling to data brokers, providing to information resellers, determining credit-worthiness, lending, surveillance, or creating unrelated databases. Instagrity does not use Google user data to train AI models unrelated to the Instagrity service. If Google-derived classroom content is included in an Instagrity AI-assisted workflow requested by a teacher, student, or authorized school user, that processing is limited to providing the requested user-facing Instagrity feature.
Sharing and transfer. Google user data may be processed by Instagrity’s authorized infrastructure and service providers (Supabase, Vercel, OpenAI, Stripe, Google, Resend, and similar providers) only as needed to operate the service. Instagrity does not transfer Google user data to third parties for advertising, resale, data brokerage, credit, lending, surveillance, or unrelated model training. AI providers process classroom content only when an AI-assisted feature is requested and only to provide that feature. Stripe generally processes billing data rather than classroom or Google-derived content unless incidental account metadata is involved.
Data protection. Instagrity uses encryption in transit and managed infrastructure protections for data at rest. Access to Google user data is limited to authorized personnel and service providers who need access to operate, secure, support, or maintain the service. Instagrity uses application access controls, server-side integration routes, Supabase row-level security where applicable, rate limiting, challenge verification where configured, security-event logging, and audit-oriented records to help protect user data from unauthorized access, disclosure, alteration, or loss.
Human access. Humans do not review Google user data except when needed to provide support requested by the user or their school, investigate abuse or security issues, comply with legal obligations, or operate internal aggregated or de-identified service operations. When a teacher or school administrator intentionally imports or uses Google-derived content in Instagrity, normal teacher, administrator, and authorized collaborator access inside the product is part of the authorized classroom workflow.
Retention and deletion. Google account identifiers and connected external-account metadata are removed or disconnected from active service records when you delete your Instagrity account or disconnect the integration, subject to backup, legal, and audit retention. Google Drive files imported into Instagrity become classroom, assignment, or submission content and follow the same deletion and retention practices as other classroom content. Google Classroom imported or mapped classes, rosters, invitations, assignments, mapping records, and sync logs follow product deletion, administrative handling, and legal or audit retention practices. If Google access is revoked or tokens expire, Instagrity marks the connection state and stops syncing until reauthorization occurs.
When Microsoft sign-in is enabled and a user chooses it, Instagrity may receive the user’s Microsoft account email address, account identifier, and basic profile details needed for authentication. Instagrity uses this data to create or locate the user’s Instagrity account, protect account access, and route the user into the correct workspace. Microsoft sign-in data is used only for authentication and account identity within the Instagrity service. Instagrity does not sell Microsoft sign-in data or use it for advertising, data-broker resale, credit-worthiness, lending, or unrelated AI model training.
Instagrity uses Stripe to support subscription checkout, billing, seat purchases, invoices, refunds, disputes, and payment-status handling. Instagrity may store Stripe customer identifiers, subscription status, purchased seat counts, invoice or checkout references, refund and dispute metadata, and entitlement records needed to operate paid plans. Payment card details are handled by Stripe and are not stored or used by Instagrity for classroom workflows. Billing data is used for account administration, payment support, accounting, audit, abuse prevention, and legal obligations. Stripe does not receive classroom content or external-provider user data from Google or Microsoft integrations unless incidental account metadata is involved.
When a teacher, student, or authorized school user requests an AI-assisted feature, Instagrity may process relevant classroom content through AI service providers to provide grading, feedback, coaching, assessment, rubric, or instructional-support features. AI processing is limited to the requested Instagrity feature and related service operations. Instagrity does not sell classroom content or external-provider user data to AI providers. Instagrity does not use that data for targeted advertising, data-broker resale, credit-worthiness, lending, or training AI models unrelated to the Instagrity service. Premium teacher seats and entitlement rules govern whether AI features are available for a given classroom workflow.
Instagrity uses infrastructure providers to host the application, authenticate users, store product data, deliver transactional emails, monitor reliability, and protect the service.
Supabase may process authentication, database, storage, and access-control data.
Vercel may process hosting, deployment, performance, and request data needed to serve the application.
Resend may process recipient, sender, subject, delivery, and message-content data needed to send service emails.
These providers process data only as needed to operate, secure, support, or maintain Instagrity. They do not receive data for advertising, data-broker resale, credit-worthiness, lending, or unrelated model training. Additional infrastructure providers may be introduced as the product evolves. See the Service providers and subprocessors section below for additional detail.
Instagrity+ is Instagrity's optional MCP (Model Context Protocol) connection for compatible AI assistants such as ChatGPT and Claude. In simple terms, it is a small, guarded door: the assistant asks Instagrity for one specific thing, and Instagrity checks whether the signed-in account is allowed to see or change it before responding. Signed-in users can follow the separate ChatGPT and Claude screenshots in the Instagrity+ setup guide. The public Instagrity+ MCP page lists the current capability groups and live read/write totals. MCP protocol requests to /mcp are a separate anonymous public-information endpoint with no account data; the setup guide copies the OAuth-protected /mcp/user account connector.
The connection is optional and requires each person to complete individual OAuth authorization. The OAuth token uses a stable account subject to bind requests to the signed-in Instagrity account. The baseline account connection uses the openid sign-in scope. Validated hosted AI clients may also request standard identity or connection-continuity scopes such as profile, email, phone, or offline access for provider compatibility; the approval screen lists the scopes actually requested. Those scopes do not grant classroom, administrator, write, or Native AI permission. Publishing the integration to a workspace does not create a shared administrator account. Every request checks the authenticated identity, role, class access, collaboration rights, and specific resource authorization; write-capable requests additionally check the owning teacher's active Premium product capability. Student, guardian, and service-account profiles cannot use the current teacher connector. Supported teachers and admins must also complete the current Student Data Use Acknowledgment before the account connector is authorized.
Depending on the requested action, MCP may process teacher and class information, assignment titles and instructions, assessment context, rubrics, submitted student work and attempt metadata, supported attachment metadata or bounded text/image content, grading preparation and scores, teacher feedback, inline annotations, and private unpublished rubric, assessment, or assignment drafts. Instagrity projects only the data needed for the selected action. The connector's structured student identity field is limited to the first 8 characters of a class-scoped Enrollment ID alias; the alias is not a global student, account, email, profile, or SIS identifier, and full IDs are not returned. User-authored work, filenames, and selected images may themselves contain names or other personal details already included in that content. Instagrity does not claim to remove text embedded inside returned image pixels.
Free teacher accounts are read-only through MCP. They can use allowed read tools but cannot save grades, feedback, rubrics, assessments, assignment drafts, or assessment-question edits through the connection. Eligible Premium owning teachers receive the same reads and may be able to preview, then explicitly confirm, supported changes. A preview never saves anything. Editing assessment questions after publication or student activity requires extra acknowledgement; a confirmed retroactive-reconcile edit can update affected submitted-attempt snapshots and scores and creates durable audit history. Admin profiles and class collaborators remain read-only through MCP. A managed AI workspace may also disable write actions, and Instagrity's role, class, entitlement, ownership, confirmation, archived-class, and idempotency checks still apply.
MCP runs on demand for the selected request. It does not perform background synchronization, indexing, bulk export, or prefetching, and Instagrity does not maintain a separate MCP conversation history. Prompts, tool arguments, and relevant context supplied by an MCP client may be transmitted to Instagrity when they are part of the request. Submission and attachment content is treated as untrusted data and cannot authorize a tool or expand access.
Instagrity passwords are not given to ChatGPT, Claude, or another AI assistant. OAuth uses authorization tokens. The selected AI-platform provider is an independent recipient or processor where legally appropriate; data returned to that platform may become part of the user's conversation and is then governed by that platform's retention, privacy, compliance, and workspace settings. Disconnecting the integration does not delete data already present in that external platform and does not undo Instagrity changes already saved through a confirmed write.
For MCP security and operations, Instagrity records bounded metadata such as request stage, method, size, protocol/header presence, tool name, outcome, safe error category, timestamps, and sanitized audit fields. Operational telemetry may record tool argument names and value types, but not ordinary argument values, raw prompt bodies, attachment bodies, passwords, OAuth tokens, or secrets. Confirmed writes also create bounded replay/idempotency records and the ordinary classroom or audit records needed to apply and explain the requested change; those records may include safe write metadata such as a teacher-supplied reason or comment. The current cleanup function permits committed MCP replay records to be removed after 30 days, while the separate database security-event ledger uses a 90-day default. Those periods do not control ordinary classroom records, required audit history, OAuth-provider records, or external conversation history. Instagrity does not use MCP-originated content for advertising, sale, data brokerage, or unrelated model training, and the MCP route does not send tool content to public-page analytics.
OAuth grants and token revocation are managed by the OAuth provider and AI client. Instagrity does not maintain a local grant or token store, so users disconnect by opening the connected AI platform's connector, plugin, app, or workspace settings and disconnecting or revoking Instagrity there. Future calls then fail until a new authorization is completed. Teachers, students, guardians, and schools may submit privacy or access questions through Contact Instagrity.
This section is part of the current Privacy Policy version shown at the top of this page. Instagrity will update this notice and provide service or public-page notice where practical when MCP materially changes the data categories, recipients, actions, retention, or user choices described here. If a new use requires additional consent, Instagrity will request it before using the data for that new purpose.
Data is used to authenticate accounts, organize classes, publish assignments, accept writing submissions, generate or display grading results, release teacher feedback, support account and billing workflows, investigate issues, and keep the service available and secure. Provider-specific data uses are detailed in the External provider data section above.
Every account uses Instagrity's baseline privacy and data-handling commitments. Self-serve accounts do not waive those protections. Data is handled to authenticate users, run classroom workflows, provide billing and support operations, maintain security, and operate the service responsibly under the current standard terms.
Self-serve accounts use Instagrity's standard privacy, security, deletion, and processor terms. Larger custom or 201+ seat packages may also include enhanced contractual commitments such as DPA review, district procurement support, security review responses, breach-notice procedures, or custom data-processing terms when separately agreed.
When Instagrity is used in a classroom or school context, student writing, student identity details, grades, and related workflow records may constitute education records or student records under FERPA or similar local rules. Instagrity supports school-authorized educational use through its stated limited-use, access-control, security, deletion, and disclosure practices. Each school, district, teacher, or organization must determine whether the service fits its own authorization, legal, policy, and parent-notice requirements; that determination does not replace Instagrity's obligations. See the Student Data Privacy Addendum for the educator acknowledgment and institutional review path.
If children under 13 use Instagrity, the service is intended to be used only under school or other legally appropriate authorization for the school-approved educational purpose. Schools and responsible organizations must determine whether COPPA consent, direct notice, parent or guardian involvement, or related obligations apply; Instagrity's own privacy, security, limited-use, and deletion practices remain applicable. Instagrity does not collect dates of birth or add age profiling through this notice.
Students, parents, guardians, eligible students, teachers, and schools may submit privacy, access, correction, export, deletion, or security questions through Contact Instagrity. Schools and authorized account holders should also use the product's available classroom, account, export, and deletion workflows. Requests remain subject to authenticated identity, role, class access, legal holds, backup and audit limits, and the rights of the school or authorized institution that controls the classroom workflow.
For a signed DPA, state-specific terms, verified subprocessor schedule, retention schedule, or procurement review, use the Student Data Privacy Addendum and contact path. The external AI workspace selected by a school is not automatically an Instagrity subprocessor.
Instagrity may process teacher, student, and classroom content through AI-assisted workflows when grading, feedback, coaching, prompt, or assessment-help features are requested. Premium teacher seats and teacher entitlement rules govern whether those AI features are available for a given classroom workflow. AI-related processing may involve third-party vendors used to operate the service. Provider-specific AI data handling is described in the External provider data section above.
Instagrity uses encryption in transit and managed infrastructure protections for data at rest. Access to user data is limited to authorized personnel and service providers who need access to operate, secure, support, or maintain the service. Instagrity uses application access controls, server-side integration routes, Supabase row-level security where applicable, rate limiting, challenge verification where configured, security-event logging, and audit-oriented records to help protect user data from unauthorized access, disclosure, alteration, or loss. Provider-specific protections are described in the External provider data section above.
Deleting content through product workflows, administrative handling, or contractual schedules may remove live product access copies, but backups, system logs, billing records, archived recovery copies, audit trails, and legally required retention copies may remain for limited periods. The current implementation also includes an administrator-controlled deleted-essay archive for recovery and audit purposes. Provider-specific retention and deletion practices are described in the External provider data section above.
Based on the current architecture, Instagrity uses visible providers such as Supabase for authentication and database services, Vercel for hosting, OpenAI for AI-assisted grading or feedback processing when enabled, Stripe for billing, Google for sign-in and related platform services where enabled, Resend for email delivery, and Microsoft for sign-in where enabled. This public description is not an exhaustive contractual subprocessor list and does not independently establish each provider's legal role. Additional providers may be introduced as the platform evolves. Provider-specific data handling, sharing, and transfer limits are described in the External provider data section above; institutions needing a verified schedule should use the Student Data Privacy Addendum and contact path.
Billing records, entitlement changes, refund activity, chargeback or dispute records, and related audit logs may be retained as needed to operate the service, review payment issues, prevent abuse, satisfy accounting needs, or comply with legal obligations.
Instagrity may disclose information where required by law, to protect the rights or safety of users or the service, to investigate abuse or security incidents, or to operate the platform through authorized vendors and subprocessors acting on Instagrity's behalf.
Instagrity may update this Privacy Policy as the service evolves. If Instagrity materially changes how it collects, uses, stores, shares, or transfers external-provider user data, Instagrity will update this page and provide notice through the service or another appropriate channel where practical. If a new data use requires additional consent, Instagrity will request that consent before using data for the new purpose.