Privacy Policy
Version 1.1 · Last updated 5 August 2026
Effective date: 3 June 2026 · Angus Southwood (ABN: 31 670 821 812) trading as Markflow
Overview
Markflow is an AI-assisted marking tool built for teachers. This policy explains what data we collect, how we use it, who we share it with, and what rights you have. Markflow is operated by a sole trader based in Western Australia, Australia. Our primary legal framework is the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where teachers outside Australia use Markflow, we apply the same standards to their data.
Who This Policy Covers
Markflow's direct users are teachers. Teachers create accounts, set up assessments, and upload student work. Students are never direct users of Markflow — they do not create accounts or interact with the product. This policy covers data relating to both teachers (account holders) and students (whose work teachers upload).
Teacher Responsibilities
Before using Markflow, teachers should ensure their use is consistent with their school's data governance policies and any applicable student privacy obligations in their jurisdiction.
Data We Collect
Teacher account data
- Name and email address (via Google sign-in or magic link)
- School name
- Subscription status and billing history
- Usage data (assessments created, credits used, last active)
Assessment and class data
- Class names, year groups, and student rosters (first name, last name)
- Assessment names, types, questions, and marking rubrics
- Uploaded files including question papers, marking keys, and student submissions
- Marks, scores, feedback comments, and flags generated during marking
Technical data
- Authentication tokens and session data
- Standard server logs (IP address, browser type, request timestamps)
We do not collect passwords. Authentication is handled via Google SSO or email magic link only.
How We Use Your Data
- To provide the Markflow marking and feedback service
- To process AI-assisted marking and generate feedback comments
- To manage your account, subscription, and credits
- To communicate with you about your account or the service
- To improve the reliability and performance of Markflow
We do not use your data or student data for advertising, and we do not sell data to third parties.
AI Processing — Third Party Services
When a teacher initiates an AI marking run, student submission content is transmitted to the following third party services for processing:
- Anthropic (Claude API) — used to analyse student work, suggest marks, generate reasoning, and draft feedback comments.
- Google Cloud Vision — used to extract text from handwritten student submissions via optical character recognition (OCR).
Separately from model training, Anthropic's API applies a default data retention window of up to 30 days for safety and abuse-monitoring purposes, even though this data is not used to train their models. Markflow does not currently have a Zero Data Retention agreement with Anthropic (which would eliminate this window entirely) — this is noted here for transparency and may change in future.
Student submission data is transmitted to these services only during an active AI marking run and is not stored by Markflow beyond what is needed to display results to the teacher.
Product Analytics
Markflow uses PostHog for product analytics and session replay to help improve usability, reliability, and the overall teacher experience.
Only teacher account data is sent to PostHog, including identity (name/email), in-app navigation, and feature usage. Student names, student work, and marks are never sent to PostHog.
Session replay recordings mask all input field content by default.
Google Classroom
Teachers can optionally connect their Google Classroom account to import class rosters and student submission files directly into Markflow, instead of uploading files manually. This is a one-time connection per teacher, managed via Google OAuth.
When connected, Markflow requests read-only access to course, roster, and coursework submission data (to browse classes and assignments), and Google Picker's file-selection scope (to let you choose which student files to import — Markflow only ever accesses files you explicitly select via the picker, not your wider Google Drive). Markflow does not request access to student email addresses.
Imported files and roster data are used solely to populate assessments and match student submissions within Markflow. This data is not shared with any third party beyond the AI processing described above. You can disconnect Google Classroom access at any time via your Google Account permissions.
Google Classroom data is handled in accordance with Google's API Services User Data Policy.
Data Storage and Security
All Markflow data is stored in Supabase, with our primary database located in the Sydney, Australia region. This means your data and student data remains in Australia.
- Row-level security — teachers can only access their own data
- Private storage buckets for uploaded files
- Encrypted connections (HTTPS/TLS) for all data in transit
- Authentication via Google OAuth or email magic link — no passwords stored
In the event of a data breach likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.
Data Retention and Deletion
Self-service account deletion is coming soon. In the meantime, teachers can request full account deletion — including class rosters, student names, assessment data, uploaded files, marks, and feedback — by emailingprivacy@markflow.com.au. We will complete all deletion requests within 30 days as required by the Australian Privacy Principles.
Standard server logs may be retained for up to 90 days for security and debugging purposes.
Your Rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion of your data
- Lodge a complaint about how we have handled your data
To exercise any of these rights, contact us atprivacy@markflow.com.au. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) atoaic.gov.au.
Cookies and Tracking
Markflow uses session cookies to keep you signed in. We also use PostHog, a product analytics service, to understand how teachers use Markflow and to record session replays (with all input field content masked) to help us identify usability issues. PostHog only tracks teacher account activity — your logged-in identity (name/email) and how you navigate and use the product. It never receives student names, student work, marks, or any other student data. PostHog is hosted in the United States. We do not use advertising cookies or third party tracking pixels, and we do not display advertisements.
Changes to This Policy
We may update this policy from time to time. When we make significant changes, we will notify teachers via email or an in-app notice. Continued use of Markflow after a policy update constitutes acceptance of the revised policy.
Contact
For any privacy-related questions, requests, or complaints: