Privacy Policy

Version 1.1 · Last updated 5 August 2026

Effective date: 3 June 2026 · Angus Southwood (ABN: 31 670 821 812) trading as Markflow

Overview

Markflow is an AI-assisted marking tool built for teachers. This policy explains what data we collect, how we use it, who we share it with, and what rights you have. Markflow is operated by a sole trader based in Western Australia, Australia. Our primary legal framework is the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where teachers outside Australia use Markflow, we apply the same standards to their data.

Who This Policy Covers

Markflow's direct users are teachers. Teachers create accounts, set up assessments, and upload student work. Students are never direct users of Markflow — they do not create accounts or interact with the product. This policy covers data relating to both teachers (account holders) and students (whose work teachers upload).

Teacher Responsibilities

Teachers are solely responsible for ensuring they have the appropriate authority, consent, or legal basis required by their school and applicable law before uploading any student data to Markflow. Markflow acts only as a data processor on the teacher's behalf and accepts no liability for data uploaded without proper authority.

Before using Markflow, teachers should ensure their use is consistent with their school's data governance policies and any applicable student privacy obligations in their jurisdiction.

Data We Collect

Teacher account data

  • Name and email address (via Google sign-in or magic link)
  • School name
  • Subscription status and billing history
  • Usage data (assessments created, credits used, last active)

Assessment and class data

  • Class names, year groups, and student rosters (first name, last name)
  • Assessment names, types, questions, and marking rubrics
  • Uploaded files including question papers, marking keys, and student submissions
  • Marks, scores, feedback comments, and flags generated during marking

Technical data

  • Authentication tokens and session data
  • Standard server logs (IP address, browser type, request timestamps)

We do not collect passwords. Authentication is handled via Google SSO or email magic link only.

How We Use Your Data

  • To provide the Markflow marking and feedback service
  • To process AI-assisted marking and generate feedback comments
  • To manage your account, subscription, and credits
  • To communicate with you about your account or the service
  • To improve the reliability and performance of Markflow

We do not use your data or student data for advertising, and we do not sell data to third parties.

AI Processing — Third Party Services

When a teacher initiates an AI marking run, student submission content is transmitted to the following third party services for processing:

  • Anthropic (Claude API) — used to analyse student work, suggest marks, generate reasoning, and draft feedback comments.
  • Google Cloud Vision — used to extract text from handwritten student submissions via optical character recognition (OCR).
At the time of writing, both Anthropic's and Google's API terms of service confirm that data submitted via their APIs is not used to train or improve their AI models. We recommend reviewing Anthropic's privacy policy (https://www.anthropic.com/legal/privacy) and their data retention policy for API customers (how long Anthropic stores data), and Google Cloud's data processing terms (https://cloud.google.com/terms/data-processing-addendum) and Vision API data usage FAQ (how Google uses Vision API data) for the most current commitments, as these may change.

Separately from model training, Anthropic's API applies a default data retention window of up to 30 days for safety and abuse-monitoring purposes, even though this data is not used to train their models. Markflow does not currently have a Zero Data Retention agreement with Anthropic (which would eliminate this window entirely) — this is noted here for transparency and may change in future.

Student submission data is transmitted to these services only during an active AI marking run and is not stored by Markflow beyond what is needed to display results to the teacher.

Product Analytics

Markflow uses PostHog for product analytics and session replay to help improve usability, reliability, and the overall teacher experience.

Only teacher account data is sent to PostHog, including identity (name/email), in-app navigation, and feature usage. Student names, student work, and marks are never sent to PostHog.

Session replay recordings mask all input field content by default.

PostHog is hosted in the United States. For current details, see PostHog's privacy policy (https://posthog.com/privacy).

Google Classroom

Teachers can optionally connect their Google Classroom account to import class rosters and student submission files directly into Markflow, instead of uploading files manually. This is a one-time connection per teacher, managed via Google OAuth.

When connected, Markflow requests read-only access to course, roster, and coursework submission data (to browse classes and assignments), and Google Picker's file-selection scope (to let you choose which student files to import — Markflow only ever accesses files you explicitly select via the picker, not your wider Google Drive). Markflow does not request access to student email addresses.

Imported files and roster data are used solely to populate assessments and match student submissions within Markflow. This data is not shared with any third party beyond the AI processing described above. You can disconnect Google Classroom access at any time via your Google Account permissions.

Google Classroom data is handled in accordance with Google's API Services User Data Policy.

Data Storage and Security

All Markflow data is stored in Supabase, with our primary database located in the Sydney, Australia region. This means your data and student data remains in Australia.

  • Row-level security — teachers can only access their own data
  • Private storage buckets for uploaded files
  • Encrypted connections (HTTPS/TLS) for all data in transit
  • Authentication via Google OAuth or email magic link — no passwords stored

In the event of a data breach likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.

Data Retention and Deletion

Self-service account deletion is coming soon. In the meantime, teachers can request full account deletion — including class rosters, student names, assessment data, uploaded files, marks, and feedback — by emailingprivacy@markflow.com.au. We will complete all deletion requests within 30 days as required by the Australian Privacy Principles.

Standard server logs may be retained for up to 90 days for security and debugging purposes.

Your Rights

Under the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of your data
  • Lodge a complaint about how we have handled your data

To exercise any of these rights, contact us atprivacy@markflow.com.au. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) atoaic.gov.au.

Cookies and Tracking

Markflow uses session cookies to keep you signed in. We also use PostHog, a product analytics service, to understand how teachers use Markflow and to record session replays (with all input field content masked) to help us identify usability issues. PostHog only tracks teacher account activity — your logged-in identity (name/email) and how you navigate and use the product. It never receives student names, student work, marks, or any other student data. PostHog is hosted in the United States. We do not use advertising cookies or third party tracking pixels, and we do not display advertisements.

Changes to This Policy

We may update this policy from time to time. When we make significant changes, we will notify teachers via email or an in-app notice. Continued use of Markflow after a policy update constitutes acceptance of the revised policy.

Contact

For any privacy-related questions, requests, or complaints: