Privacy Policy

ValidBound LLC · SpeechGradebook · Last updated: July 24, 2026

ValidBound LLC (“ValidBound”, “we”, “us”) operates SpeechGradebook, our AI-assisted speech evaluation platform for educational use, and related ValidBound services. This policy describes how we collect, use, and protect information when you use SpeechGradebook at speechgradebook.com and related services. Our company site is validbound.com.

Information we collect and use

When you use SpeechGradebook, we store account and usage data necessary to provide the service. This includes:

All data is stored in secure, encrypted databases (Supabase) and is used solely to operate the application, enforce role-based access controls, maintain FERPA-compliant audit logs, and provide the evaluation services you request.

Student data and FERPA compliance

SpeechGradebook is designed to comply with the Family Educational Rights and Privacy Act (FERPA) and your institution's data protection policies. Student video, audio, transcripts, and grading metrics may constitute protected education records. When ValidBound processes those records for an institution, ValidBound acts as a “School Official” with a legitimate educational interest under 34 CFR Part 99, solely to provide the contracted services. We implement multiple safeguards to protect student educational records.

No public AI training by sub-processors

In the default hosted configuration, evaluations use the SpeechGradebook Model via our backend proxy and do not send student media to consumer LLM APIs (such as OpenAI, Anthropic, or Google Gemini). ValidBound does not use student voice recordings, video streams, transcripts, or rubric results to train public third-party models. Inference sub-processors process content to deliver the evaluation job, not to add it to public training corpora. ValidBound may use deidentified and aggregate data to improve SpeechGradebook’s own private models and product features; those exports omit student and instructor names as fields (spoken names inside transcripts are not automatically scrubbed).

Data isolation and pilot wind-down

Institutional tenants are logically isolated (roles and row-level security). Higher education departments can manage, archive, and request deletion of student data. Within thirty (30) days after a pilot or contract expires—unless the institution transitions to a continuing commercial agreement—ValidBound will archive or delete student video/audio recordings and gradebook data associated with that engagement through operational procedures (not an automatic product job), subject to any earlier export requested by the institution. See also the Higher Education Pilot Addendum.

Consent management

For institutional course use, instructional processing of student education records (grading and course management) is part of normal educational operation of the service under the institution’s authorization. Evaluation materials are stored in hosted systems for instructional use by the instructor and authorized unit administrators. SpeechGradebook also supports per-student consent records for ValidBound secondary / product-improvement use:

Consent decisions that are recorded include timestamps and are retained for audit integrity.

Access controls and role-based permissions

Access to student data is strictly controlled through comprehensive role-based access controls enforced at multiple levels:

All access is:

Access controls are designed to follow the principle of least privilege, ensuring users can only access the minimum data necessary for their role.

Audit logging

SpeechGradebook records access to student evaluation data in application audit logs to support FERPA-oriented review. Logged events typically include:

Institution admins can review compliance-oriented logs in-product (Settings → Admin → Compliance where enabled). Logs are retained for operational and compliance review. Not every UI interaction is guaranteed to generate a log entry; logging coverage is an active control we continue to harden.

Data storage and security

Student data for the hosted product is stored primarily in Supabase (authentication, PostgreSQL, and object storage), with application hosting and model inference on additional U.S.-region subprocessors as described below. Controls include:

Hosted evaluation data is encrypted at rest (AES-256) and in transit (HTTPS/TLS).

Data retention and deletion

Retention follows institutional agreements and product controls:

Contact ValidBound for institution-specific retention commitments in a DPA or order form.

Broader data use and third parties

Subject to this Privacy Policy, student consent choices, and any institution agreement:

We do not sell student education records. Any additional third-party disclosure beyond subprocessors and the uses above would require applicable legal basis and, where required, institutional agreement.

Third-party services

SpeechGradebook’s hosted product uses subprocessors to operate the service. Typical providers include:

The default hosted evaluation path uses the SpeechGradebook Model via our backend proxy. It does not send student media to consumer third-party LLM APIs (such as OpenAI, Anthropic, or Google Gemini). If an institution configures a non-default evaluation path that uses another provider, that provider’s privacy terms apply to that usage.

When instructors send consent requests via their own email client, message content may transit that instructor’s email provider (for example institutional mail, Gmail, or iCloud). Those providers are not ValidBound subprocessors for the hosted product; they are chosen by the instructor or institution.

A current subprocessor summary for institution reviewers is published in our documentation: Subprocessors and data locations. Additional security and questionnaire materials are listed under Trust & security.

Your rights and choices

Student rights under FERPA

Under FERPA, students have the right to:

Practice users who link to a course can view their own linked instructor evaluations in Practice. Roster-only students without a Practice account do not have a general student gradebook login; they may request inspection or correction of education records through their instructor or institution under institutional FERPA policies.

Consent management

Where instructors distribute consent links, students can record consent or decline through that flow. Affirmative consent gates ValidBound LLM / R&D exports; instructional storage and instructor/admin use continue regardless. Consent request emails may be sent from the instructor’s email client (mailto) or, when configured, by SpeechGradebook server SMTP. Recorded decisions are retained for audit integrity.

Data access and deletion

Instructors and administrators can access, export, and delete student data through the application's administrative functions. Access and deletion actions are logged where those workflows emit audit logs; not every UI interaction is guaranteed to generate a log entry.

Security vulnerability reporting

To report a suspected security vulnerability or data incident, use our contact form and select Security / vulnerability report. Do not include student education records in the report unless strictly necessary to demonstrate the issue. Details: Incident response and contact · SECURITY.md.

Questions and concerns

For questions about your data, this privacy policy, or FERPA compliance, please contact:

If you believe your FERPA rights have been violated, you may file a complaint with the U.S. Department of Education's Family Policy Compliance Office.

Institution reviewers

IT security and procurement reviewers can start with:

Related: Terms of Service · Higher Education Pilot Addendum · Report a security issue · Coaching Agreement

← Back to SpeechGradebook