The account model
LexGrade accounts are individual. A student who uses LexGrade signs up directly, owns the account, and is the only person who can see their documents and grades. LexGrade has no roster, gradebook, or LMS integration: we receive no enrollment data or education records from any institution, and no instructor dashboard exists that could expose a student’s work to anyone else.
That means a student using LexGrade on their own initiative is a direct consumer of the service — the same posture as using a citation manager or a grammar checker. If your program wants a class, clinic, or institutional arrangement (and the data-processing terms that come with one), email hello@lexgrade.com — that is a conversation we want to have, not a checkbox we pretend to have.
What we store
- Name and email, plus a hashed password — never the plaintext.
- Submitted text — the motion or brief a student pastes or extracts, stored encrypted at rest so they can revisit their runs.
- Results — extracted citations with verification verdicts, and LexGrade Standard scores.
- Request metadata (IP address, user agent, timestamps) — used only for rate-limiting and security.
PDFs are read in the student’s browser; the file itself is never uploaded. Only the extracted text is sent, after an on-device screen for personal identifiers (see Redaction guidance).
Where the text goes
Two subprocessors receive document text, both solely to provide the service: Anthropic (the LexGrade Standard grade — API inputs retained ~30 days under its policy, and per that policy not used to train its models) and CourtListener / Free Law Project (citation verification against the public record). Citation checking alone never sends text to Anthropic. The full subprocessor list, with links to each policy, is in the Privacy Policy.
What we never do
Submitted text is never used for training, aggregation, or research without explicit opt-in. No model fine-tuning, no derived datasets, no sharing with researchers, no advertising, no sale of personal information. If any of that is ever offered, it will be an opt-in on a feature the student chooses — never a buried Terms update.
Deletion and export
Students delete their own data, without asking us. Deleting a run removes it from the account immediately; on our servers it is soft-deleted for a 30-day recovery window, then hard-deleted by a scheduled job. Deleting the account is immediate and skips the recovery window. A complete machine-readable export is one click on the profile page — useful if a clinic wants students to keep their own records past the course.
On FERPA
FERPA governs education records held by institutions and parties acting for them. LexGrade today acts for no institution — there are no institutional agreements, so a student’s LexGrade account is their own consumer record, not an education record we hold on a school’s behalf. We make no compliance certification on this page; if your review requires specific terms, that’s the hello@lexgrade.com conversation above.