Privacy Policy

Last updated 28 September 2026

ClassPilot reads your Google Classroom coursework, prepares draft work with an AI model, and can put that draft into a Google Doc you own. This page lists exactly what it reads, what it keeps, who else sees it, and how to make it stop.

Who this applies to

ClassPilot is used by a student signing in with their own Google account. It reads the coursework assigned to that student. It does not read other students’ work, and it is not a tool for teachers or administrators to review a class.

Google account information

Signing in with Google gives ClassPilot your name, email address, profile picture URL, and the Google account identifier for your account. These come from the openid, email and profile scopes. They are stored so ClassPilot can recognise you on your next visit and address you by name.

Google Classroom data

ClassPilot reads, for the account that signed in:

  • Your active classes: name, section, subject heading, and the link back to Google Classroom. Requested with classroom.courses.readonly.
  • The published coursework in those classes: title, instructions, due date and time, work type, attached materials, and the link back to Google Classroom. Requested with classroom.student-submissions.me.readonly, which Google shows on the consent screen as “View your course work and grades in Google Classroom”.
  • The state of your own submission for each item, so ClassPilot can tell what is turned in and what is missing. Covered by the same scope.

ClassPilot does not read your grades beyond submission state, does not read your classmates’ work, does not request class rosters, and never writes to Google Classroom. It cannot submit an assignment for you. Teacher names are not collected, because reading them would require access to the whole class roster.

Google Drive and Google Docs

ClassPilot uses the drive.file scope only. It can open a file only if ClassPilot created it or you chose to share it with ClassPilot. It cannot see, browse, index, or search the rest of your Drive, and it never modifies or deletes anything it did not create.

When a coursework item has a file attached by the teacher, ClassPilot asks you to share that file with it using Google’s file picker. Once you pick it, ClassPilot reads the file’s name, type and link, and extracts text from Google Docs, PDFs, Word documents and plain text files to read the assignment. Until you share it, ClassPilot does not open the file and does not prepare work that depends on it.

When you ask ClassPilot to create a document, it creates a new Google Doc in your Drive and writes the draft into it. This uses the drive.file scope, which grants ClassPilot access only to files ClassPilot created or files you explicitly chose to share with ClassPilot. The document belongs to you. ClassPilot rewrites it only when you ask it to, and refuses if the document changed after ClassPilot last wrote to it, unless you confirm.

AI processing

To prepare draft work, ClassPilot sends the assignment title, instructions, the text extracted from attachments, and your class context to OpenAI, and stores the response. OpenAI processes this on ClassPilot’s behalf as a service provider. Attachment text is passed to the model as data rather than as instructions, so text inside an attachment cannot redirect what ClassPilot does.

Do not put anything in an assignment that you would not want sent to an AI provider. ClassPilot has no way to tell that a piece of coursework contains something sensitive.

Generated assignment content

The draft answers, the summary, the model’s raw response, the model name, and a count of tokens used are stored against your account. The token counts exist to enforce usage limits. Generated drafts stay until you delete the assignment or your account.

Authentication and session information

ClassPilot stores a session record and a session cookie so you stay signed in. It also stores the OAuth credentials Google issues: an access token, a refresh token, and an ID token. The refresh token is what allows the overnight check to run while you are not signed in.

These credentials are never sent to your browser. They are not part of the session object the app hands to the page, and they do not appear in any API response.

Where the data is stored, and how it is protected

Everything above is stored in a PostgreSQL database controlled by whoever operates this ClassPilot deployment. Google OAuth tokens are encrypted at rest with AES-256-GCM before they are written, under a key held in the server environment and never in the database, so a copy of the database alone does not yield a usable Google credential. Decryption happens on the server, immediately before a call to Google.

Tokens, API keys and session identifiers are stripped from error reports and logs. ClassPilot enforces per-user rate limits on the operations that reach Google and OpenAI. In production the app refuses to start unless its security configuration is complete.

No security measure is absolute. This section describes what ClassPilot does, not a guarantee of outcome.

Who else sees your data

ClassPilot does not sell your data. It does not share it with advertisers, data brokers, or any third party for their own purposes, and it is not used to build advertising profiles.

The only third parties involved are the ones needed to run the service:

  • Google, which provides sign-in and the Classroom, Drive and Docs data.
  • OpenAI, which processes assignment text to generate drafts.
  • The hosting and database provider chosen by whoever operates this deployment, which stores the data at rest.
  • Stripe, which processes subscription payments. ClassPilot never sees your card details.

Google API Services User Data Policy

ClassPilot’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the features described on this page, is never sold, is never used for advertising, and is not used to train generalised AI models. Human beings do not read your Google data except with your explicit permission, to resolve a specific problem you have reported, for security purposes, or where required by law.

Retention and deletion

Three different actions, with three different effects:

  • Sign out ends your ClassPilot session. Nothing is deleted, and the Google authorization deliberately stays in place so the overnight check keeps running.
  • Disconnect Google, in Settings, asks Google to revoke ClassPilot’s authorization, deletes the stored Google credentials, turns automation off, and ends your sessions. Your ClassPilot account and the work already generated are kept.
  • Delete account, in Settings, asks Google to revoke the authorization and then permanently deletes your account and everything stored against it: classes, assignments, extracted attachment text, generated drafts, automation settings, run history and notifications.

If Google cannot be reached at that moment, ClassPilot still deletes its own copy of your credentials and tells you so, so that a network failure never leaves a credential behind. You can always remove ClassPilot yourself at myaccount.google.com under Third-party apps.

Google Docs that ClassPilot created stay in your Drive after deletion. They are your files; ClassPilot has no way to reach them once the authorization is gone, and deleting them is up to you.

Children

ClassPilot is used with Google Classroom accounts, which may belong to minors. Where a Google Workspace for Education administrator controls the account, that administrator decides whether ClassPilot may access it, and can revoke that access at any time.

Changes to this policy

Material changes will be reflected in the “Last updated” date above. Continuing to use ClassPilot after a change means the updated policy applies.

Contact

Questions, requests about your data, and privacy complaints go to [email protected].

Privacy PolicyTerms of ServiceHome