You keep student data private by checking how an AI tool collects, stores and uses information before you upload any student work. Ask where data is hosted, whether it trains models on your inputs, who can access it, how long it is retained, and whether it meets your school's privacy obligations.
What counts as student data when you use an AI tool?
Student data is any information that can identify a student or reveal something about them, including the work itself. That covers obvious identifiers like names, class lists and student IDs, but also essays, exam responses, photos of handwritten work, grades, wellbeing notes and even the prompts you type describing a student. An AI tool can capture all of this the moment you paste or upload it.
It helps to treat the content of student work as personal information, not just the metadata attached to it. A Year 9 narrative or a Biology response can reveal a student’s identity, beliefs, health or home circumstances. Under the Australian Privacy Principles that kind of information deserves careful handling, so the safest assumption is that anything a student produces may be sensitive.
Which questions should you ask before uploading student work?
Ask a short, consistent set of questions about how the tool handles data before any student work goes near it. The aim is to understand the full lifecycle of the information, that is, collection, storage, use, access and deletion, rather than trusting a reassuring marketing line. If a provider cannot answer these clearly in writing, treat that as a warning sign.
Keep the list somewhere you can reuse it, because the same questions apply to every new tool a colleague suggests. Vendors change their terms, so it is worth re-checking whenever a product adds AI features or updates its privacy policy.
- Does the tool use my inputs to train or improve its AI models, and can I opt out?
- Where is the data stored and processed, and is it hosted in Australia or under equivalent protection?
- Who can access the data, whether staff, subcontractors or third parties, and under what controls?
- How long is data retained, and how do I request deletion?
- Does the provider meet the Australian Privacy Principles and my school or system's requirements?
Does the AI tool train its models on what you upload?
Some AI tools do train on what you upload, which is why this is the single most important question to resolve first. Training can absorb student work into a model you no longer control. Many consumer AI services reserve the right to use submitted content to improve their systems unless you turn that off, while some enterprise and education products contractually promise not to train on customer data at all.
Look for explicit wording rather than vague reassurance. Phrases such as “we do not use your data to train our models”, or a clear enterprise data-processing agreement, are what you want to see. If the only privacy information is a generic consumer policy, assume your inputs may be used for training and avoid uploading identifiable student work.
Where is student data stored, and who can see it?
Student data may be stored anywhere from Australian servers to overseas data centres, so you need to find out where a tool hosts it, who can access it and how long it is kept. Those three factors decide most of your real-world risk. Cloud AI tools often process data offshore, which can raise cross-border disclosure questions under the Privacy Act and some state education policies, so Australian or contractually protected hosting reduces that concern.
Access matters as much as location. Ask whether provider staff or subcontractors can read your content, whether access is logged, and whether the data is encrypted in transit and at rest. Retention is the final piece: a trustworthy tool tells you how long it keeps inputs and gives you a clear way to delete them.
How can you reduce risk without banning AI outright?
The most effective everyday protection is data minimisation: give the tool only what it genuinely needs to do the job. You rarely need a student’s full name for an AI tool to help draft feedback, so removing or replacing identifying details cuts your exposure sharply while keeping the benefit.
Combine minimisation with a few simple habits and you can use AI responsibly rather than avoiding it entirely.
- Remove or pseudonymise names and other identifiers before uploading, wherever the tool does not need them.
- Prefer tools your school or system has already approved and vetted.
- Use accounts tied to your school rather than personal logins, so data stays within managed systems.
- Avoid pasting sensitive details such as health, wellbeing or disciplinary notes into general AI tools.
What role do school policies and consent play?
Your school or education system sets the rules, so start there rather than making an individual call. Most departments and dioceses maintain approved-software lists, procurement checks and privacy assessments precisely so teachers do not have to evaluate every vendor alone. Using an approved tool means someone has already reviewed its data handling against policy.
Consent and transparency also matter. Parents and students are generally entitled to know how their information is used, and some uses may require notification or consent under school policy. When in doubt, talk to your privacy officer, IT team or leadership before adopting a new AI tool for class work.
How can a purpose-built marking tool keep you in control?
A purpose-built marking tool keeps you in control by working from your own rubrics, success criteria and comment banks, and by keeping you as the reviewer of every suggestion. Designing privacy in as the default, rather than something you have to police, limits both what the tool needs from you and what ever leaves your control.
JeddAI, built in Australia, drafts feedback and marking aligned to your criteria while you review and edit before anything reaches a student. Choosing a tool built for schools, with clear data handling and teacher oversight, lets you save marking time without giving up control of student work. You can Get started with JeddAI and weigh its data practices against the questions above.
| What to check | Lower-risk sign | Higher-risk sign |
|---|---|---|
| Model training | States it does not train on your inputs, or offers a clear opt-out | Reserves the right to use your data to train, with no opt-out |
| Data hosting | Hosted in Australia or under a data-processing agreement | Unclear location, or offshore with no stated safeguards |
| Access controls | Encryption plus logged, limited staff access | No detail on who can read your content |
| Retention and deletion | Documented retention period and a way to delete data | No retention information or deletion option |
| Fit for schools | Designed for education and on approved-tools lists | Generic consumer app with a consumer privacy policy |
Frequently asked questions
Is it OK to paste student work into a free AI chatbot?
Generally no, unless you have removed identifying details and confirmed the service does not train on your inputs. Free consumer tools often reserve the right to use submitted content, so treat them as unsuitable for identifiable student work.
Does removing names make student work fully anonymous?
Not always. Writing style, specific details or context can still identify a student, so pseudonymising reduces risk but does not eliminate it. Pair it with a tool that has strong data-handling commitments.
Do I need parental consent to use an AI marking tool?
It depends on your school or system's policy and how the tool handles data. Check with leadership or your privacy officer, since some uses require notification or consent while approved tools may already be covered.
Why does the Privacy Act matter for AI tools in schools?
The Privacy Act 1988 and the Australian Privacy Principles govern how personal information is collected, stored, used and disclosed. They apply to student data you put into AI tools, which is why hosting, access and cross-border disclosure matter.
Are school-approved AI tools automatically safe?
Approval means someone has vetted the tool against policy, which is far safer than choosing your own. You should still apply data minimisation and follow any conditions attached to the approval.
Get started with Jeddle
Jeddle gives teachers and students instant, syllabus-aligned feedback powered by JeddAI.
Looking for study material? Browse Jeddle's Australian-English subject resources, or explore more articles on AI in Education.