arrow_back Back classi

Privacy Policy

Last updated: January 6, 2026

  • We do not sell personal information.
  • We do not run targeted advertising to students or based on student data.
  • We use Customer Data only to provide, secure, and improve the Services for the Customer.
  • We do not train AI models on Customer Data without the Customer's explicit approval.

This Privacy Policy describes how Classi AI Private Limited ("Classi", "we", "us") collects, uses, and shares information when you visit our website or use the Classi platform and related services (the "Services").

1. Who we are

The Services are provided by Classi AI Private Limited. For privacy-related questions or requests, contact us at [email protected].

2. Roles: schools as Customer (Controller) and Classi as Processor

Classi is sold to schools and organizations ("Customer"). In most cases, the Customer determines what personal information is collected and how it is used in the Services. In those cases:

  • Customer acts as the "controller" (or equivalent) for Customer Data.
  • Classi acts as a "processor" (or "service provider") for Customer Data and processes it only to provide the Services.

When you interact with our public website (for example, you request a demo or contact support), Classi may act as a controller for that information.

3. Lawful basis (global)

We process personal information to provide the Services under our contract with the Customer (school/organization). We may also process data where necessary for our legitimate interests, such as securing the Services, preventing abuse, and improving reliability and performance. Where required, we rely on consent (or the Customer’s consent/authorization mechanisms) and honor changes as applicable.

4. Information we collect

The categories of information we may collect depend on how the Services are used and what the Customer configures.

  • Account and profile information: names, emails, role (student/teacher/admin/parent), usernames, and profile pictures (if added).
  • Educational records and activity: grades, feedback, submissions (including files/images), assignments, and related classroom data.
  • Communications: chat messages and support communications sent through the Services.
  • Parent/guardian information: parent/guardian names and email addresses where provided by the Customer.
  • Usage and device data: log data such as approximate device information, browser type, timestamps, and interactions with the Services.
  • Demo and sales inquiries: name, email, school/organization name, and any information you submit via our landing page or scheduling flow.

5. How we use information

  • Provide and operate the Services, including authentication, access control, and feature delivery.
  • Customer support, troubleshooting, and responding to inquiries.
  • Security and abuse prevention, including detecting fraud, misuse, and protecting accounts.
  • Improve the Services, including product analytics and performance monitoring.
  • Communications related to service updates, onboarding, and administrative messages.
  • Legal and compliance obligations, including responding to lawful requests.

6. AI features and model training

The Services may use AI to help analyze submissions, generate feedback, and provide insights. Classi does not use Customer Data to train AI models without the Customer's explicit approval. If a Customer enables an optional program that permits training or improvement using Customer Data, the terms for that program will be provided to the Customer in writing.

7. Sharing and subprocessors

We do not sell personal information. We share information only as needed to provide the Services, including with vendors and service providers ("subprocessors") acting on our behalf and subject to appropriate obligations.

Key subprocessors used for the Services include:

  • Google Cloud Platform (GCP) — hosting and infrastructure.

AI inference providers (to provide AI features):

  • OpenAI — As of March 2023, OpenAI does not use data submitted via its API to train or improve models unless the customer explicitly opts in. API data is retained for up to 30 days for abuse monitoring, then deleted. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). OpenAI is SOC 2 Type 2 certified. See: OpenAI API Data Usage.
  • Google Gemini (Vertex AI) — Google Cloud AI services do not use customer data to train Google's models. Customer data is processed only to provide the requested service and is not retained after generating responses. See: Google AI Data Governance.
  • Together AI — Together AI offers Zero Data Retention (ZDR). When ZDR is enabled (Classi enables this), data and outputs are not stored, retained, or used for model training. See: Together AI Terms of Service.
  • Groq — By default, Groq does not retain customer data for inference requests. Groq offers Zero Data Retention (ZDR). See: Groq: Your Data.

Note: AI provider policies may change. Classi monitors provider terms and selects providers committed to not using Customer Data for training.

The Services may also load third-party content and libraries that make network requests from your device (for example, to render math content, load fonts, or embed video).

  • YouTube / Google (embedded video player for demos, where enabled).
  • Google Fonts (for typography resources).
  • jsDelivr CDN and MathJax (to render mathematical notation).

8. Disclosures for legal, safety, and compliance reasons

We may disclose information if we believe in good faith that it is necessary to:

  • comply with applicable law, regulation, legal process, or lawful governmental requests;
  • enforce our agreements, policies, and terms of service;
  • detect, prevent, or address fraud, security, or technical issues;
  • protect the rights, property, or safety of Classi, our Customers, Authorized Users, or the public.

9. Corporate transactions

If Classi is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, information may be transferred as part of that transaction, consistent with applicable law and subject to appropriate protections.

10. Data residency and international transfers

Classi supports customer-configurable data residency options. Depending on the Customer's configuration and the locations of service providers, information may be processed in different regions. Where required, we use appropriate safeguards for cross-border transfers.

11. Data retention

Customer Data is retained for the duration of the Customer's contract and as instructed by the Customer. Upon contract termination (or at the Customer’s request), we will delete or return Customer Data within 30–90 days, unless a longer period is required by law or agreed in writing.

Backups: encrypted backup copies may persist for a limited period on access-controlled systems and are overwritten on a rolling basis. We do not use backup copies for active processing except to restore systems, and they are deleted in accordance with our backup retention schedules.

12. Billing and payment information

Classi is sold to schools and organizations and is billed directly to the Customer (for example, via invoice). We do not collect or store consumer credit card information for purchases of the Services through the website.

13. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls and encrypted connections in transit.

If we become aware of a personal data breach affecting Customer Data, we will notify the Customer without undue delay and cooperate on remediation.

14. Children and student users

Student accounts may be used by minors, including young students, when their school or organization provides access to the Services. The Customer is responsible for obtaining any required consents and providing notices to students and parents/guardians as required by applicable law and policy.

Customer administrators can request access, correction, or deletion of student data within the Services or by contacting us at [email protected].

15. Your rights and requests

If you are a student, parent, or educator using the Services through a Customer, requests related to Customer Data should typically be directed to your school or organization administrator. You may also contact Classi at [email protected].

  • Access to personal information.
  • Correction of inaccurate or incomplete information.
  • Deletion, where applicable and subject to the Customer’s instructions and legal requirements.
  • Restriction / objection to processing, where applicable.

16. Regional compliance notes

India (DPDP Act, 2023): Where applicable, we process personal data in accordance with the Digital Personal Data Protection Act, 2023, including implementing reasonable security safeguards and supporting requests through the Customer as controller.

United States (FERPA + COPPA): For student data handled on behalf of schools, we support a school-consent model where the school/organization authorizes use of the Services for educational purposes and manages required notices and consents.

17. Cookies and similar technologies

We may use cookies and similar technologies (including local storage and session storage) for functionality, security, and to understand usage.

  • Essential cookies: used to enable core functionality such as authentication and security-related features.
  • Self-hosted analytics: we use a session identifier stored in session storage and send event data to our backend.
  • Third-party embeds: embedded content (such as YouTube) may set cookies in accordance with the provider's policies.

18. No third-party rights

This Privacy Policy does not create rights enforceable by third parties.

19. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date above when changes are made.

© 2026 Classi. All rights reserved.
Privacy · Terms