Privacy Policy

Last updated: September 2026

Overview

CommentCraft is built with school privacy in mind. We designed the service so that the least possible information leaves your device. This policy explains what we collect, why, and how we protect it.

1. What we do not collect

  • No student records are stored on our servers. Information you enter (student name, grade, performance level, notes) is transmitted to generate a draft comment or email and is not retained after the request completes.
  • Generated comments and emails are not logged or saved by CommentCraft. Only you see the output.
  • We do not create profiles of students.
  • We do not sell data to advertisers or third parties.

2. What we do collect

Account information

When you purchase access, Paddle (our payment processor) collects your email address and payment details. Kingshire Education receives only your email address, which is used to verify your access. We store it in our database (Neon Postgres) with your plan and expiry date. We do not store your payment card details.

Operational logs — no analytics

We do not run analytics. There is no page-view tracking and no third-party analytics script on either site. Our servers keep content-free operational logs for reliability: a request ID, a one-way-hashed account identifier, the request type, outcome, timing, and size. These logs never contain student names, anything you type into the form, or generated text.

Local storage

The app stores your access status and a roster of student presets in your browser's local storage. This data never leaves your device — it is not transmitted to our servers.

3. How we use your data

  • Your email is used only to verify that you have a valid paid account.
  • We do not use your email to send marketing messages without your consent.
  • We may contact you with important service updates (e.g. pricing changes, downtime).

4. Third-party services

CommentCraft uses the following third-party services:

  • OpenAI — generates draft comments and emails. The details you enter are sent to OpenAI's API to produce the draft, subject to OpenAI's Privacy Policy and its API terms, which state that data sent to the API is not used to train OpenAI's models.
  • Paddle — payment processing, as merchant of record. Paddle handles all payment data. See Paddle's Privacy Policy.
  • Vercel — hosting and serverless functions. Our functions run in Vercel's United States region; generation requests are passed from there to OpenAI's API. See Vercel's Privacy Policy.
  • Google Sign-In — how we verify who is generating. Signing in with Google is required for the free monthly comments (it is how your monthly count is kept) and can also unlock purchased access. We receive only your email address and Google account identifier. See Google's Privacy Policy.

5. Data retention

Your email address and access record are retained while your access is active, and afterwards for support and record-keeping. We do not currently delete purchase records on an automatic schedule. You may request deletion at any time by emailing us, and we will remove your records.

6. Your rights

Depending on where you are located, you may have rights to access, correct, or delete the personal data we hold about you. To exercise any of these rights, email support@kingshire.org.

7. Children's privacy

CommentCraft is a tool for teachers, not students. We do not knowingly collect personal information directly from children. Student-identifiable information entered into the tool is processed only to generate a draft and is not retained.

For school technology departments

The questions IT reviewers ask us most, answered plainly:

  • Is student information stored? No. Details entered into the form are processed transiently to generate a draft and are never written to our database or our logs. The optional student roster lives only in the teacher's browser.
  • Is student information used to train AI models? Generation requests are processed by OpenAI's API, whose terms state that API data is not used to train its models. We do not train anything ourselves.
  • How long is anything retained? Nothing student-related is retained by us. For the purchasing teacher we keep an email address and access expiry date (see Data retention above).
  • Who processes the generated text? Our serverless functions on Vercel (United States region) send the request to OpenAI's API and return the draft to the teacher's browser. This is a teacher productivity tool — students never use it and it collects nothing from them.
  • Should teachers use full student names? First names are sufficient, and many schools prefer them.

8. Changes to this policy

We may update this Privacy Policy as the service evolves. We will post changes here with an updated date. Material changes will be communicated to active users by email.

9. Contact

Questions about privacy? Email support@kingshire.org.