Last updated: March 25, 2026
This Privacy Policy (“Policy”) governs the privacy practices of Legend (“Company,” “we,” “us,” or “our”) regarding the collection and use of information through our website, Chrome extension, and related services (collectively, the “Service”).
Legend is deeply committed to protecting the privacy and security of our users’ personal information, especially student data. This Privacy Policy outlines our privacy-first approach, which is designed to comply with the Family Educational Rights and Privacy Act (FERPA), the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada, and other applicable data protection laws.
At Legend, privacy is a core product principle. We believe that student data belongs to students and their educational institutions, not to us. We collect only what is necessary to deliver and improve the Service, use it only for appropriate educational and operational purposes, and do not use identifiable student work for advertising or to build behavioral profiles.
By default, we do not use identifiable student work to train generalized AI models. If we use data to improve our Service or models, we will rely on de-identified and/or aggregated information, as described in Section 3.3.
Legend collects minimal personal information necessary for account creation and authentication. We collect only:
We do not collect unnecessary personal data, track users across websites, build advertising profiles, or request additional permissions beyond those required for authentication and core functionality. We do not sell or rent your personal information to third parties.
We may use trusted service providers (such as authentication or infrastructure providers) to support the Service, as described in Section 4, but they are not permitted to use your personal information for their own marketing purposes.
Legend processes student-submitted assignments exclusively for educational purposes, such as grading assistance, feedback, and progress tracking under the control of the teacher and/or school.
Student names and other identifiers may be stored within a teacher’s account for ease of use, but are never used for advertising, sold, or shared with third parties for their own commercial purposes.
By design:
Collected personal information is used exclusively for:
We do not use personal information for third-party advertising or for selling data to advertisers or data brokers.
Student-submitted content is used primarily for:
Legend does not:
We may retain student data as reasonably necessary to support teacher and school use of the Service, comply with legal obligations, and maintain reliable operations, subject to the controls described in Section 5.2.
To continue improving Legend while respecting student privacy, we may use de-identified and/or aggregated data derived from use of the Service. When we do so:
We do not attempt to re-identify individuals from de-identified or aggregated data. Where required by law or by our agreements with schools or districts, we will obtain appropriate consents or authorizations before using data in this manner.
Legend does not sell or rent user or student data to third parties.
We may share information only in the following limited circumstances:
We maintain a strict no-third-party-advertising policy on our platform. We do not share user or student data with advertising networks or data brokers.
When teachers submit assignments for grading, the text content may be transmitted to third-party API providers, including AI model providers such as OpenAI, for processing.
Our intent and practice are that:
API providers’ own privacy policies govern their internal handling of data, but our agreements and configurations are designed to ensure that your data is not used to identify your students or for unrelated commercial purposes.
Legend uses Google OAuth to authenticate users. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
Legend implements technical, administrative, and physical security measures designed to protect your information, including:
While no system can be guaranteed 100% secure, we continually work to enhance our security posture.
We retain data only for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, and maintain reliable operations.
For student-related data:
Backups may persist for a limited technical retention period before being overwritten, but we do not use deleted data for active operations.
Data is stored in secure, SOC 2 Type II–certified data centers located in the United States and Canada. We do not transfer data outside of these regions except:
Users (teachers) have the right to:
To exercise these rights, contact us at privacy@legend.org. We will respond to requests within 30 days or as required by applicable law.
Schools, as FERPA-defined “Educational Institutions,” maintain primary control over student data. Legend acts as a “School Official” under FERPA, processing student data only at the direction of the school and for legitimate educational purposes.
Parents or eligible students should direct requests to review, correct, or delete student records to their school. Upon receiving direction from the school, Legend will assist in fulfilling such requests within a reasonable time (typically within 30 days), consistent with our technical capabilities and legal obligations.
Teachers may choose to publish rubrics to Legend’s shared rubric library to help other educators. This is entirely optional and separate from student data:
We clearly indicate when content will be shared with other users and give teachers control over what they publish.
Legend is designed for use by educational institutions and teachers, not for direct sign-up by children.
We do not knowingly collect personal information directly from children under 13. All student data is provided or managed by educational institutions and teachers in accordance with their own legal obligations (including FERPA and, where applicable, COPPA).
If you believe we have inadvertently collected information directly from a child under 13 without appropriate consent, please contact us at privacy@legend.org, and we will take steps to investigate and, where appropriate, delete such information.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements.
If we make material changes, we will:
For changes that materially expand how we use or share personal or student data (for example, new categories of de-identified data use), we will provide additional notice and, where required by law or agreement, obtain appropriate consent or authorization.
Your continued use of the Service after the effective date of an updated Policy constitutes your acceptance of the changes. If you do not agree with the updated Policy, you should discontinue use of the Service and may request deletion of your account.
If you are accessing or using the Service from within Canada, this Privacy Policy shall be governed by and construed in accordance with the laws of the Province of Ontario and PIPEDA, without regard to its conflict of laws principles.
If you are accessing or using the Service from within the United States, this Privacy Policy shall be governed by and construed in accordance with the laws of the State of Delaware and applicable U.S. federal laws, including FERPA, without regard to conflict of laws principles.
Local laws may provide additional rights or protections; where applicable, we will respect those rights.
For any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact our Privacy Team: privacy@legend.org