Qalami

How Qalami handles your pupils’ data

Version notice-2026-08.2

Who is responsible for what

The school is responsible for the pupil data — for deciding that an assessment happens, for the relationship with parents, and for the records that result. They are the school’s records, not ours.

We process that data on the school’s instructions, to mark the work the school uploads and give it back. We do not use it for anything else, we do not sell it, and we do not use it to train AI models.

What we hold

  • Photographs of the pages teachers upload — pupils’ handwritten work.
  • What was written on them, transcribed, so the marking can quote the evidence.
  • Pupil names and, if the school adds them, pupil numbers.
  • Marks, per-criterion judgements, written feedback, and class reports — some of which name individual pupils when they group them for support.
  • Teacher names and email addresses.

We do not ask for parent contact details, addresses, dates of birth, or photographs of faces.

Signing in with Google

Teachers may sign in with a Google account instead of an emailed link. When they do, we receive their email address and name from Google, and nothing else. We ask for no access to Gmail, Drive, Contacts, Calendar or any other Google service, and we cannot read them.

The email address identifies the teacher and matches them to their school. It is stored alongside their name in the teacher record described above, is deleted when the school is deleted, and is never sold, shared for advertising, or used to train AI models.

Who can see it

Only the school’s own teachers. The database enforces this row by row, so one school cannot read another’s data even in principle, and the same applies between teachers.

The scans live in private storage. They are never on a public address — a page is served through a link that expires within the hour.

How long we keep it

  • Scans: 90 days from the day the teacher approves the marking. The image has done its job by then; keeping it longer only adds risk. Papers reopened for a query keep their scans until the query is settled.
  • Marks, feedback and reports: kept while your school is using the service. This is the part a school actually uses across terms. They are deleted when your school leaves — see below — and we will delete them sooner whenever you ask.
  • Billing records are kept as financial records. They contain no pupil data at all — token counts and costs only.

We intend to add an automatic 3-year limit on marks and reports, so that assessment records expire on their own rather than waiting to be asked for. That is not built yet, so today they are kept until your school asks us to remove them or until your school leaves. We would rather say that than describe a deletion that does not happen.

When something is deleted, the images go with it. Deleting a class, a pupil or a paper removes the scans from storage in the same operation.

Who else is involved

  • Anthropic — the pages and the rubric are sent to its models to produce the draft marking, and the results come back to us.
  • Supabase — hosts the database, the sign-in accounts and the image storage.
  • Resend — delivers the sign-in emails. It handles a teacher’s email address and never touches pupil work.

Nobody else receives this data.

A person always decides the mark

Nothing the AI produces is final. Every paper is a draft until a teacher reviews it and approves it, and the system records who accepted or changed each mark. The AI does not make a decision about a pupil on its own.

If the school stops using the service

Access becomes read-only rather than disappearing. Everything already marked stays readable, and the school can export the lot — every record and every scan — for 90 days. After that we delete it.

Asking for a copy, or for deletion

The school can ask for a complete export at any time, and can ask us to delete everything. Deletion covers the scans, the marks, the reports and the sign-in accounts, and we keep a dated record that it happened — with no pupil data in it.

What this is, and what it is not

This is a plain account of what the software does, and accepting it records that someone at the school was shown it. It is not a signed data processing agreement. If your school needs one — and many will, particularly for a formal procurement — ask us and we will provide one for your legal advisers to review.

Getting in touch

For a copy of your data, a deletion request, a data processing agreement, or anything else in this notice, write to [email protected].

See also the terms of service.

Privacy notice — Qalami