Privacy Policy

Effective July 16, 2026

Skyline is an AI-assisted grading service operated by Silvia Inc. ("Silvia," "we," "us"). This policy explains what we collect, why we use it, who can receive it, how long we keep it, and the choices available to schools, teachers, students, and families.

We do not sell student personal information, use student work for targeted advertising, or use student work to train general-purpose AI models. Skyline is intended for school-authorized educational use, with teacher oversight.

1. Scope and roles

This policy applies to the Skyline website, teacher dashboard, grading service, integrations, family grade links, and support interactions. It does not govern third-party services that a customer chooses to connect, except for the data Silvia sends to or receives from those services.

For student education records, the school or district generally determines why and how the records are used, and Silvia processes them to provide the contracted service. For teacher account, billing, security, and business administration data, Silvia determines the processing described here.

Use by an individual teacher does not by itself establish that Silvia is a FERPA "school official." That status depends on the school's annual notice, legitimate educational interest criteria, direct control, contract, and other applicable requirements.

2. Information we collect

Teacher and organization information

  • Name, email address, authentication identifiers, and profile settings.
  • School, district, courses, grade levels, and organization memberships.
  • Rubrics, answer keys, assignment instructions, grading scales, and policies.
  • Connected-service configuration and limited integration identifiers.
  • Subscription status, invoices, and transaction metadata; card details are handled by Stripe.

Student and educational information

  • Student names or roster identifiers supplied by the teacher or an authorized integration.
  • Scans, photographs, PDFs, revisions, and extracted text from student work.
  • Course, assignment, rubric, score, criterion-level evidence, and feedback information.
  • AI grade suggestions, confidence signals, verification results, and teacher decisions.
  • Teacher overrides, approval history, calibration samples, and LMS posting status.

Technical, support, and security information

  • IP address, browser and device type, timestamps, route activity, and session events.
  • Operational logs, error types, queue status, audit events, and security alerts.
  • Support messages and attachments a user chooses to send.

Please do not upload Social Security numbers, medical records, financial account information, disciplinary files, full special-education records, or other information not necessary to grade the assignment.

3. Sources of information

We receive information from teachers and administrators, school-authorized integrations, student work uploaded by authorized users, families using a teacher-created private link, authentication and payment providers, and the device used to access the service.

4. How we use information

  • Provide grading tools: extract work, compare it with the rubric, generate evidence-based suggestions, and present them for teacher action.
  • Carry out teacher choices: save edits, process approvals, post final grades to connected systems, create exports, and generate print packets or private family links.
  • Improve a teacher's experience: use that teacher's prior overrides conservatively to calibrate future suggestions for the same teacher. Calibration does not independently make a grade eligible for auto-posting.
  • Operate and secure Skyline: authenticate users, enforce tenant boundaries, prevent abuse, recover stuck jobs, diagnose failures, and maintain audit records.
  • Administer the relationship: provide support, communicate material service or policy changes, manage subscriptions, and meet legal obligations.
  • Develop the product: use aggregate or de-identified operational information that is not reasonably linkable to a student. We do not use identifiable student work to train general-purpose AI models.

5. Student data commitments

  • We use student data only to provide, secure, support, and legally operate the educational service requested by the school or teacher.
  • We do not sell or rent student data.
  • We do not use student data for behavioral advertising, targeted advertising, or building a commercial profile unrelated to school purposes.
  • We do not permit a subprocessor to use student data for its own advertising or general-purpose model training.
  • We do not knowingly contact students for marketing.
  • We limit external AI requests to the content needed for grading and use an opaque student identifier instead of a student name where the workflow permits.

6. AI and automated processing

Anthropic and, when configured, an OCR provider process selected assignment content to produce transcription, scoring, and feedback outputs. AI outputs are probabilistic and may be incomplete or wrong. Skyline provides confidence and verification signals and routes uncertain work to review.

Auto-post is off by default. A teacher may opt in and set a confidence bar. Low-confidence, hard-to-read, or failed-verification work is designed to stay in review. Auto-post is an administrative workflow choice, not a guarantee of accuracy, and teachers and schools must monitor its use.

Automated decision-making. Skyline uses automated processing to propose scores, confidence signals, and draft feedback. These are proposals, not final decisions: a teacher reviews the work and is the final authority on every grade. Skyline is designed so that a grade with a legal or similarly significant effect is not produced by solely automated means without meaningful human review. Where the GDPR, UK GDPR, or a similar law applies, an individual may request human review of, express their point of view on, or contest an outcome influenced by automated processing, through the controlling school or by contacting us at privacy@silviaai.dev.

See our Safety and Responsible AI Policy for the controls, prohibited uses, and reporting process.

7. When we disclose information

We may disclose information only as follows:

  • Service providers: hosting, database, storage, AI/OCR, error monitoring, authentication, payment, and support providers that process information for defined service purposes.
  • School-authorized integrations: Google Classroom, Aeries, or another connected system, limited to the data and actions authorized by the customer.

Google Workspace APIs (Classroom and Drive).When a teacher connects Google Classroom, Skyline accesses Classroom courses, rosters, coursework, and student submissions as authorized by the teacher. Skyline also accesses the contents of student submission files stored in Google Drive on a read-only basis, solely to download and grade the specific attachments on the assignment being graded. We do not access the user's wider Drive, and we do not use Google user data for advertising.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

  • School or district administrators: where the organization controls the account, course, or records and the disclosure is authorized.
  • Legal and safety: when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or respond to lawful process. Where permitted, we will direct education-record requests to the school.
  • Business transactions: during a merger, financing, acquisition, or sale, subject to confidentiality protections and continued limits on student-data use.

Current infrastructure providers include Supabase, Vercel, Railway, Anthropic, Sentry when configured, Stripe for billing, and Mathpix when OCR is enabled. Contract terms, regions, and provider availability can change. Schools may request the current subprocessor list and applicable contractual commitments before providing student data.

8. FERPA and school records

FERPA applies to educational agencies and institutions that receive applicable federal funds. A school may disclose education records to a contractor under the school-official exception only when the legal requirements are met, including legitimate educational interest, direct control over use and maintenance, and limits on redisclosure.

When Silvia is engaged under an appropriate school or district agreement, we process education records for the specified educational function and do not use them for an unauthorized purpose. The school remains responsible for its FERPA notices, record determinations, parent or eligible-student rights, and choice of disclosure authority. Districts needing a DPA or FERPA addendum should contact privacy@silviaai.dev before uploading student records.

Official resource: U.S. Department of Education FERPA resources

9. Children and COPPA

Skyline teacher and administrator accounts are intended for authorized adults. Skyline also provides school-authorized student workspaces for an educational purpose. A student signs in with a school account and joins a class using a teacher-issued code; the workspace is limited to classwork, submissions, due dates, and teacher-finalized results. Teachers may also upload work or create a time-limited family link.

For a school-authorized educational service, a school may in appropriate circumstances authorize collection from children under 13 on behalf of parents. That authorization is limited to the educational context and does not permit commercial uses. Silvia remains responsible for the duties that apply to it as an operator; we do not transfer all COPPA responsibility to a teacher or school.

If we learn that personal information was collected directly from a child outside a valid school-authorized context, we will investigate and delete or obtain legally sufficient consent as required. Parents should first contact the school about a student record and may also contact us.

Official resource: Federal Trade Commission COPPA guidance

10. Your privacy rights, legal bases, and choices

Student education records are normally handled through the school, which controls the record and must verify the requester's authority; we assist the school as required by contract and law. The rights below otherwise apply according to your residence and the law that covers a given processing activity. We will not discriminate or retaliate against anyone for exercising a privacy right.

Legal bases for processing (EU / UK GDPR)

Where the EU or UK GDPR applies, we rely on one or more of these legal bases:

  • Contract: to provide Skyline to the account holder or school and administer the subscription.
  • Legitimate interests: to secure the service, prevent abuse, maintain audit records, provide support, and calibrate suggestions for the same teacher, balanced against individual rights and freedoms.
  • Consent: where we request it, such as certain non-essential cookies or optional features; consent may be withdrawn at any time without affecting prior processing.
  • Legal obligation: to comply with law, tax, and record-keeping duties.

For student education records, the school or district is the data controller and determines the purposes and legal basis; Silvia acts as a processor on the school's documented instructions.

Rights for individuals in the EEA, UK, and Switzerland

Subject to legal conditions and exemptions, you may: access your personal data; correct inaccurate data; erase data; restrict or object to processing, including profiling; receive a portable copy of data you provided; and withdraw consent. You may also lodge a complaint with your local data protection supervisory authority (in the EEA, your national authority; in the UK, the Information Commissioner's Office). Organizations that require a data processing agreement should contact us before uploading personal data.

California and other US state privacy rights (CCPA/CPRA and similar)

In the past 12 months we have collected the following statutory categories of personal information for the business purposes described in Sections 2-4: identifiers (name, email, account and roster identifiers); customer and education records; internet or network activity (log, route, and session events); coarse location inferred from IP address; audiovisual information (images, scans, or PDFs of student work); professional or school information (role, school, district); and inferences (AI grade suggestions and confidence signals). The only sensitive personal information we handle is account log-in credentials, which we use solely to provide the service and do not use to infer characteristics; we therefore do not use or disclose sensitive personal information for purposes that would trigger a separate right to limit.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. Because there is no sale or sharing, there is nothing to opt out of; where applicable we also honor recognized opt-out preference signals such as Global Privacy Control.

Subject to verification and exemptions, you have the right to know and access, delete, and correct your personal information; to opt out of any sale or sharing (not applicable, as noted); to limit the use of sensitive personal information; and to be free from discrimination or retaliation for exercising these rights. You may use an authorized agent, who must provide proof of authority. You may appeal a denied request.

How to exercise your rights

Send requests to privacy@silviaai.dev (student-record requests go through the school). We verify identity, authority, account ownership, and jurisdiction before acting, and we respond within the period the applicable law requires, generally within 45 days under the CCPA and one month under the GDPR, each extendable with notice where permitted.

Official resource: California Attorney General privacy rights information

Official resource: EU General Data Protection Regulation overview

11. Retention and deletion

  • Teacher account and configuration data is kept while the account is active and for the limited period needed to close the account, resolve disputes, prevent fraud, and meet legal obligations.
  • Student work, grade decisions, and assignment records are kept until the authorized user deletes them, the account is closed, or the controlling school agreement requires deletion.
  • Audit and security records may be retained longer when needed for grade disputes, security investigations, contractual obligations, or law.
  • Billing records are retained by Silvia and Stripe as required for tax, accounting, fraud prevention, and legal compliance.
  • Residual copies may remain temporarily in encrypted backups or provider recovery systems and are not returned to active use except for disaster recovery.

A verified account-deletion request will be completed within the period stated in the applicable contract or required by law. If no period applies, our operational target is 30 days for active systems. We may retain a minimal record of the request and information that law requires us to keep.

12. Security safeguards

We use layered administrative, technical, and organizational safeguards appropriate to the service, including HTTPS, managed encryption at rest, authenticated sessions, row-level database access policies, teacher-scoped queries, server-only service credentials, signed expiring links, audit logs, dependency scanning, restricted browser permissions, cross-site mutation checks, and privacy-filtered error monitoring when configured.

No internet service can guarantee absolute security. Users must protect their accounts, use school-approved devices and networks, avoid unnecessary sensitive data, and promptly report suspected compromise to security@silviaai.dev.

13. Security incidents

We maintain an incident-response process to validate, contain, investigate, remediate, document, and learn from suspected incidents. If an incident affects personal information, we will notify affected customers and regulators as required by applicable law and contract, without unreasonable delay after sufficient investigation. A DPA may establish a more specific timeline.

Notices will describe the incident to the extent known, affected information, steps taken, recommended protective actions, and a contact for questions. We will not delay a legally required notice merely to complete every aspect of an investigation.

14. Access, correction, export, and requests

  • Teachers can edit grade suggestions and feedback, export assignment data, and review audit activity in the product.
  • Schools may request access, correction, export, restriction, or deletion for records they control.
  • Students and parents should contact the school first for education-record requests. We will support the school's verified request.
  • Direct requests may be sent to privacy@silviaai.dev. We may verify identity, authority, account ownership, and jurisdiction before acting.

An authorized agent must provide proof of authority. We may deny or limit a request where an exemption applies, fulfillment would adversely affect another person's rights, or we cannot reasonably verify the request. We will explain the basis and any available appeal process.

15. International data transfers

Skyline is currently designed for United States schools. Information may be processed in the United States and other locations where approved providers operate.

When personal data from the EEA, the UK, or Switzerland is transferred to the United States or another country that has not received an adequacy decision, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, an adequacy decision where one applies, or another lawful mechanism, supplemented by additional safeguards where needed. A customer that requires a specific hosting region or a particular transfer mechanism must confirm availability with Silvia before use.

16. Changes and contact

We may update this policy as the service, providers, or law changes. We will post the revised date and provide additional notice for material changes when required. We will not materially expand the use of previously collected student data without the authorization required by law and the controlling school agreement.

Privacy requests: privacy@silviaai.dev
Security reports: security@silviaai.dev
General support: team.silviaai@gmail.com