Privacy Policy
Effective date: July 7, 2026
1. Overview
Button.AI is an AI writing-feedback service used by graduate writers and, in some cases, deployed by educational institutions for their students. This policy explains what we collect, how AI processing works, who can see student work, how long we keep data, and how deletion works. We do not sell personal data and we do not run advertising.
2. What We Collect
- Account data: name, email address, a bcrypt-hashed password (we never store plaintext passwords), and your role (student, faculty, coach, or admin).
- Content you create: documents you write or upload (including DOCX files), scan results and findings, scores, coaching-chat transcripts, and coach comments.
- Class data (when you join a class): enrollment, assignment bindings, and the visibility settings your institution configures.
- Operational data: scan usage counts, technical logs, and — only if error monitoring is enabled — crash reports. We do not use third-party advertising trackers.
3. How AI Processing Works
When you run a scan, request coaching, or use other AI features, the relevant document text and context are transmitted securely to Anthropic, our AI provider, and processed by Claude models to generate feedback. Under the API terms we operate on, Anthropic does not use these inputs or outputs to train its models. We store the resulting feedback with your document; we do not use your writing to train models of our own.
4. Student Education Records (FERPA)
When Button.AI is used through a school, college, or university, documents and feedback connected to coursework may constitute education records under the Family Educational Rights and Privacy Act (FERPA). In those deployments we act as a service provider to the institution — the kind of “school official” role FERPA contemplates — and we:
- process education records only to provide the Service to the institution;
- do not disclose them to third parties except the subprocessors listed below;
- do not use them for advertising or model training;
- support institutional requests to access, correct, or delete student records.
Students at institutional deployments should direct FERPA requests to their institution, which controls the records; we will assist the institution in fulfilling them.
5. Who Can See Your Work
By default your documents are visible only to you. If you join a class, your institution’s faculty — and coaches they assign — may see your work, scores, and feedback according to the visibility policy configured for that class or assignment. Faculty and administrators of your class can always see class work; per-item visibility toggles control what coaches and students see. Administrators of the Button.AI service can access data as needed for support and security.
6. Retention
- Documents, scan reports, and coaching history: retained for as long as your account is active, so you can track progress across drafts.
- Transient scan-progress records: deleted automatically after 7 days.
- Operational usage and diagnostic logs: deleted automatically after approximately 90 days.
7. Deletion
You can delete your account at any time from Settings, or by calling the account-deletion endpoint while signed in. Deletion is immediate and cascades: your scan history, scan progress, usage records, documents, and annotations are permanently removed along with your user record. Institutional administrators can additionally request deletion of records for their students.
8. Security
- All traffic is encrypted in transit (TLS).
- Passwords are hashed with bcrypt; we cannot read them.
- Access is enforced per-request by role- and ownership-based authorization, with database-level row security as defense in depth.
- Service credentials are held server-side only and never shipped to the browser.
9. Subprocessors
- Vercel — application hosting and delivery.
- Supabase — database and storage.
- Anthropic — AI analysis of submitted text (Section 3).
- Resend — transactional email (invitations, verification, resets).
- Sentry — error monitoring, when enabled.
- Stripe — payment processing for paid plans, when enabled. We never see or store full card numbers.
10. Children
The Service is designed for graduate and professional education and is not directed to children under 13. We do not knowingly collect personal information from children under 13; if we learn we have, we will delete it.
11. Changes
We will post updates to this policy here and, for material changes, notify you in the app or by email before they take effect.
12. Contact
Privacy questions or requests: jeremiahmwolf@gmail.com.