Student data

What we know about a student, and who can see it.

OpenVerdict for Education asks for as little as a class can work with. This page lists every piece of it, names who can read each one, and says how it gets deleted. It describes what the software does today, not what it may do later.

What we collect

There are two ways a student takes part, and they collect different things.

A one-off link

An instructor posts a link. The student opens it, types a first name, and goes straight to the case. That name is the only thing we ask for. There is no account, no password and no email address. The browser is given an anonymous session so the student can come back to their own work on that device, and an eight-character recovery code so they can pick it up on another one.

An enrolled class

The student signs in with an email address, either through a one-time sign-in link or through Google, and joins the class with a join code. They type the name their instructor will see. The email address is used to sign in and to send sign-in links. It is not shown to the instructor and it is not used for anything else.

We ask for no date of birth, no student ID number, no address, no phone number and no photograph. If a student types something into the name field that their institution treats as sensitive, such as a student ID, it is stored as typed, so instructors should ask for first names only.

What is stored, and who can read it

Every row below is protected in the database itself by row-level security, so a reader who is not on this list is refused by the database whatever the page asks for.

WhatWho can read it
The student's nameThe student, and the instructor of that class or assignment.It never appears on the public platform. On the floor the student is a juror number.
Email address (enrolled students only)The student. Our authentication provider holds it so sign-in works.Instructors see names, not email addresses. Students on a one-off link have no email with us at all.
The verdict: just or unjust, and how sure they wereEverybody, as a juror number. The instructor also sees it against the student's name.Votes are what make the public tally on a case. The link from a juror number to a real person exists only in the class roster.
Written reasoning and the answer to the other sideThe student and the instructor who set the assignment. Nobody else.This is coursework, and it is stored apart from the public vote for that reason.
Arguments posted on the caseEverybody, unless the assignment is marked private, in which case only the class.Arguments are signed with the juror number, not the student's name.
Marks, rubric scores and feedbackThe student and the instructor who gave them.
Extensions and the note attached to oneThe student and the instructor who granted it.
The recovery code for a seatThe student and the instructor of that assignment.
Page views: the path, the referring page, the window size and a random session idOpenVerdict administrators.First-party counting only. There is no advertising network, no third-party analytics script and no cross-site tracking.

What the public sees

  • A juror number, such as J-7761, and never a student's name.
  • Votes, counted into the tally on the case.
  • Arguments the student chose to post, unless the assignment is private.
  • Nothing else. Reasoning, marks, feedback, extensions and the roster are not public.

An instructor can tick Keep this class's arguments private when they assign a case. Arguments filed under that assignment are then readable only by the people on it, their classmates and the instructor. The rest of the platform carries on as normal, and the class's votes still count in the public tally.

What the instructor sees

The instructor who set an assignment sees, for their own students only: the name the student typed, the juror number that name maps to, whether they voted and what they voted, how sure they were, whether they changed their mind, what they wrote and which argument they answered, roughly how long they spent composing, whether the work arrived before the deadline, and any mark and feedback the instructor gave. They can export the same thing as a spreadsheet.

No instructor can see another instructor's class, and nobody can see a roster without owning it. That is enforced by the database, not by the page.

How long it is kept

Coursework is kept until somebody deletes it. There is no automatic expiry, because an instructor who has to defend a mark in March needs the work from October.

  • An instructor deleting an assignment or a class deletes everything it holds, at once.
  • A student asking to be forgotten deletes their account and everything they wrote, everywhere.
  • An anonymous session created by a one-off link that never joined anything and never voted holds no name and no coursework, so there is nothing in it that identifies anyone.
  • Page-view records are kept for site statistics and are not linked to a student's name.

How to delete it

The instructor. On the assignment page, Delete this assignment removes the assignment, its roster, the students' verdicts and reasoning on that case, the arguments filed under it, every mark and every extension. On the class page, Delete this class and all its data does the same for every assignment in the class and then the roster and the class itself. Both ask for a confirmation first and neither can be undone.

The student. Delete my account and everything I wrote, at the bottom of your record, removes the verdicts, the reasoning, the arguments, the marks, the extensions, the class memberships, the profile and the login itself. It takes effect immediately.

By email. Write to openverdictofficial@gmail.com and we will do it for you. We reply within five business days and act within thirty days. An institution can ask us to delete a whole class or a whole term the same way.

Who else touches the data

Four companies are involved in running the platform. Only the first two ever hold student data.

We will name any new subprocessor on this page before it starts handling student data.

Supabase
The database and the sign-in system. Hosted in the United States. This is where names, verdicts, reasoning and marks live.
Vercel
Hosting and the content network that serves the pages. It sees request logs, including IP addresses, as any web host does.
CourtListener
The public court-records service the case documents come from. It is read only. No student data is sent to it.
Zeffy
Donation processing for the charity. It has no part in the education layer and never sees a student.

We do not sell personal information, we do not rent it, we show no advertising, and we do not use student work to train anything.

FERPA

When a school or a college directs us to hold student records on its behalf, we act as a school official with a legitimate educational interest under the FERPA exception at 34 CFR 99.31(a)(1). In practice that means three commitments, and they are the whole of it:

  • We use student data only to provide the service the school asked for.
  • We do not redisclose it to anyone else, except to the subprocessors named above, which act only on our instructions.
  • The school keeps control. It can ask to see, correct or delete its students' records at any time, and we do it.

An instructor who uses the tool on their own initiative, without their institution directing us, is acting on their own account. That is fine, and most of our users start that way, but the FERPA school-official designation belongs to the institution and applies when the institution puts it in writing. See what your campus needs from us for the agreement we sign.

Questions

Write to openverdictofficial@gmail.com. A student, a parent, an instructor or a campus reviewer gets the same answer, and we reply within five business days. The general policy for the rest of the platform is the privacy policy; where the two differ for a classroom, this page governs.

Last updated September 19, 2026.