Compliance & Safety
Last updated: 30 March 2026
MarkMate is designed with student safety and data privacy at its core. This page outlines how we meet the requirements of Australian privacy legislation, school data governance expectations, and ethical AI principles. It is intended for school leaders, IT coordinators, department reviewers, and parents assessing MarkMate for use in an educational setting.
At a Glance
| Database location | Sydney, Australia (Asia-Pacific) |
| Authentication provider | Clerk (SOC 2 Type II compliant) |
| AI provider | Anthropic (Claude API) |
| Encryption in transit | TLS 1.2+ (HTTPS) |
| Encryption at rest | AES-256 |
| Marketing/tracking cookies | None |
| Third-party analytics | Vercel Analytics (privacy-friendly, no cookies) |
| Student names sent to AI | No |
| AI training on student data | No (Anthropic API policy) |
| Data retention | 12 months, deletion available on request |
| Age requirement | Under-16 requires parental or school consent |
| Governing law | New South Wales, Australia |
1. Australian Privacy Act 1988
MarkMate operates in compliance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We collect only the minimum personal information necessary to provide the service:
- Account holders — name, email address, and role (student or teacher), collected via Clerk authentication
- Student submissions via teacher links — an optional first name only. No email, date of birth, or other identifiers are collected
- Assignment data — task notifications, rubrics, and submission text, used solely to generate feedback
We do not sell, share, or use personal information for advertising. Our full Privacy Policy details all collection, use, and disclosure practices.
2. Student Data Protection
Protecting student data is our highest priority. Here is how we handle it:
- No personal identifiers sent to AI — when student work is sent to the Claude API for analysis, no student names, email addresses, or other personal identifiers are included in the request. The AI only sees the rubric and the submission text.
- AI does not train on student data — Anthropic's API policy explicitly states that data sent via their API is not used to train their models.
- Database in Australia — all assignment and submission data is stored in a Neon Postgres database hosted in Sydney, Australia (Asia-Pacific region).
- No tracking cookies — we do not use marketing cookies, advertising trackers, or any third-party tracking scripts.
- Passwords never stored on our servers — authentication is handled entirely by Clerk. We never store or have access to user passwords.
- Data deletion on request — any user can request full deletion of their account and associated data by contacting support@markmate.education.
3. AI Transparency & Ethics
MarkMate uses AI to provide formative feedback, not to make final assessment decisions. We are transparent about how our AI works and its limitations:
- Formative only — MarkMate provides indicative feedback and grades to help students improve before final submission. It is not a replacement for teacher assessment.
- AI model — we use Anthropic's Claude (Sonnet model) via their commercial API. The model runs at temperature 0 for consistent, reproducible results.
- No hallucinated sources — MarkMate analyses student work against the rubric and task notification provided by the teacher. It does not generate, fabricate, or cite external sources.
- AI detection disclaimers — our integrity indicators (AI writing detection, source copying indicators, student similarity) are clearly labelled as indicators only, not proof. They are shown to teachers only and are never shown to students. We explicitly state they should never be used as sole evidence of academic dishonesty.
- Human-in-the-loop — MarkMate is designed to support teacher professional judgement, not replace it. Teachers review all feedback and make final decisions about grades and academic integrity.
4. Technical Security
- Encryption in transit — all data transmitted between users and our servers is encrypted using TLS 1.2+ (HTTPS).
- Encryption at rest — database content is encrypted at rest using AES-256 encryption.
- Authentication — managed by Clerk, which is SOC 2 Type II compliant. Supports Google sign-in and email/password.
- API security — all API keys are stored as encrypted environment variables on Vercel. They are never exposed to the client.
- SQL injection prevention — all database queries use parameterised queries via the Neon serverless driver.
- Access control — teachers can only view submissions for their own assignments. Students cannot access teacher-only features (AI detection, marking, dashboards).
5. Third-Party Services
MarkMate uses a small number of third-party services, each chosen for reliability, security, and compliance:
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Anthropic (Claude API) | AI marking and feedback generation | Rubric text + submission text (no names or identifiers) | United States |
| Clerk | User authentication | Name, email, sign-in method | United States (SOC 2 Type II) |
| Neon Postgres | Database | All application data | Sydney, Australia |
| Vercel | Hosting and deployment | Application code, request logs | Global CDN (Sydney edge) |
| Google Cloud Vision | Handwriting recognition (OCR) | Photos of handwritten work (no names) | Google Cloud |
6. Age Requirements & Consent
- Under 16 — individual student accounts require parental or guardian consent. Schools may provide consent on behalf of students under school-administered plans.
- Teacher-link submissions — when a teacher shares an assignment link, students can submit work without creating an account. Only an optional first name is collected.
- No social features — students cannot interact with each other, view other students' work, or communicate through the platform.
7. School Procurement & Approval
We understand that schools and education departments have formal processes for approving third-party tools. We are happy to:
- Complete your school or department's vendor assessment or data protection impact assessment (DPIA)
- Provide additional documentation for IT security reviews
- Participate in your organisation's Safe AI Ethics Assessment or equivalent evaluation
- Provide a Data Processing Agreement (DPA) for school plans
- Answer questions from your IT team, executive, or data protection officer
Contact support@markmate.education to begin the approval process for your school or department.
8. What MarkMate Does NOT Do
To be clear about our boundaries:
- We do not sell or share personal data with third parties for advertising or marketing
- We do not use tracking cookies or behavioural profiling
- We do not send student names or personal identifiers to the AI
- We do not allow the AI provider to train on student submissions
- We do not make final assessment decisions — all grades are indicative only
- We do not write or rewrite student work — the AI only provides feedback on what the student has written
- We do not enable communication between students or any social features
- We do not provide AI detection results to students — these are teacher-only
9. Accessibility
MarkMate is built to align with the Web Content Accessibility Guidelines (WCAG) 2.1 at Level AA. We test the main user journeys with the axe accessibility tool and with VoiceOver on macOS to make sure the site works for students and teachers who rely on keyboard navigation, screen readers, or other assistive technologies.
All form controls have programmatic labels, focus indicators are visible, and content uses semantic HTML with landmark regions (<nav>, <main>, <footer>). The student feedback page is the highest priority for accessibility because students with reading difficulties or visual impairments are exactly the users who benefit most from clear, structured AI feedback.
If you encounter an accessibility barrier on MarkMate, please email support@markmate.education — we treat accessibility issues as bugs and prioritise fixing them.
10. Related Policies
- Privacy Policy — full details on data collection, use, storage, and your rights
- Terms of Service — acceptable use, liability, and service terms
- Cookie Policy — details on the minimal cookies we use
Questions about compliance?
We're happy to work with your school, department, or IT team to meet your requirements.
Contact Us