Legal
Privacy Policy
How AI Challenge Portal collects, uses, shares, protects, and keeps information about the students, educators, administrators, and visitors who use it.
Draft for legal review
This text describes how the service actually works today and is prepared for review by counsel. Bracketed, highlighted items are facts the operator must supply or decisions counsel must confirm. It is not final until they are resolved and this notice is removed.
1. Who we are
AI Challenge Portal ("the Service") is a critical-thinking practice platform operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], trading as cognificance.com ("we", "us", "our"). The Service consists of the public documentation site at cognificance.com, the student portal, the management (admin) portal, and the application programming interface behind them.
Questions about this policy or your information can be sent through our contact form (choose the "Privacy" category) or to [PRIVACY EMAIL ADDRESS]. [COUNSEL: if the operator is established outside the EU/UK and serves EU/UK users, name the Article 27 representative(s) here, or confirm none is required. State whether a data protection officer is appointed; if not, say so.]
2. Scope and our role
This policy covers everyone who uses the Service: students and independent learners in the student portal; teachers, institution administrators, and platform administrators in the admin portal; and visitors to the documentation site, including people who use the public contact form.
- Institutional accounts. When a school, district, or other institution ("Institution") provides the Service to its students and staff, the Institution decides why and how their information is used. For those accounts we act as the Institution's service provider (a "processor" under the EU and UK GDPR, and a "school official" with a legitimate educational interest under the US Family Educational Rights and Privacy Act where it applies) and process information only on the Institution's instructions and under our agreement with it. The Institution's own privacy notice also applies, and requests about those records should go to the Institution first.
- Independent learners, visitors, and inquiries. For people who use the Service without an Institution, for documentation-site visitors, and for contact-form inquiries, we decide how information is used and are the "controller".
3. Information we collect
Information you or your Institution give us
- Account details: email address, display name, role (student, independent learner, teacher, institution administrator, or platform administrator), preferred language, and, where provided, date of birth. Students who sign up with a class code must give their date of birth.
- Institution and class details: Institution name and web domain, the Institutions and classes (rosters) you belong to, your enrollment dates, and the class join codes teachers create.
- Challenge work: the messages you write in a challenge conversation, the AI's replies, assignments and challenge templates, and the timing, progress, and turn counts of each session.
- Evaluations: scores, score dimensions, checkpoint progress, and written feedback produced for a session.
- Feedback you send us from inside the portals: category, optional rating, message, the page you sent it from, and the app version.
- Contact-form inquiries: name, email address, optional organization, category, and message.
- Teacher-authored content: challenge templates and the requests teachers make to the teacher assistant. Teacher-assistant conversations are not stored; each request is processed and discarded, and only a usage record is kept.
Information created when you use the Service
- Identity records: the identifier our sign-in provider assigns to your account, whether your account is active or deactivated, and when you last signed in where recorded. We do not store your password. If we create your account, our sign-in provider issues a one-time temporary password that is shown once to the administrator who creates it and that you must change at first sign-in.
- Legal acceptance records: which version of this policy and the Terms of Use you accepted, and when.
- Safeguarding and integrity records: any safeguarding flag or integrity pause raised on a session (see section 6), its reason, and reviewers' notes and decisions.
- Inquiry handling notes our staff add while answering a contact-form inquiry.
- In-app notifications sent to you and whether you have read them.
- Usage and audit records: for each AI request, the account and session it served, the model used, token counts, response time, and any error code (not the text of the conversation); and records of who opened a student's session report or safeguarding flag.
- Device and connection information: IP address, browser and device type, and request details, which our network and sign-in providers process to deliver pages, block attacks, and enforce rate limits.
- Technical logs: server logs and request traces used to run and secure the Service. They are keyed to internal identifiers and generally do not contain conversation text.
Information from third parties
- Your Institution, when it creates or manages your account.
- Our sign-in provider (Microsoft Entra External ID), which confirms your email address and sign-in.
- Cloudflare Turnstile, which tells us whether a contact-form submission passed its automated abuse check.
We do not ask for, and ask you not to enter, sensitive information such as health details, government identifiers, or financial information in challenge conversations.
4. How we use information and our legal bases
| Purpose | Information | Legal basis (EU/UK GDPR) |
|---|---|---|
| Create and run your account, route you to the right portal, and enforce role permissions | Account, institution, and identity records | Contract with you; for Institutional accounts, the Institution's instructions |
| Run challenges, generate AI replies, evaluate sessions, and show results to you and your educators | Challenge work, evaluations | Contract; Institution's instructions |
| Apply age ratings to challenges and the minimum-age rule for sign-up | Date of birth | Legitimate interest in protecting younger users and meeting age-based legal requirements [COUNSEL: name the specific obligation, e.g. COPPA, if relied on] |
| Safeguarding: detect and escalate possible risk to a student | Challenge work, safeguarding records | Legitimate interest in student welfare; where it applies, vital interests or the Institution's safeguarding duties. Disclosures about self-harm or abuse can be health data: [COUNSEL: Art. 9(2) condition, e.g. substantial public interest (safeguarding of children) under member-state or UK law] |
| Integrity: pause a session when a message tries to override the challenge rules, for review | Challenge work, integrity records | Legitimate interest in fair, secure assessment; Institution's instructions |
| Respond to inquiries and feedback | Inquiry and feedback records | Legitimate interest in answering you; steps you request before a contract |
| Security, abuse prevention, debugging, and capacity and cost tracking | Technical logs, usage and audit records, Turnstile result | Legitimate interest in a secure, reliable service |
| Record your acceptance of our legal terms | Legal acceptance records | Legal obligation and legitimate interest in proving agreement |
| Aggregate site measurement | Cookieless page-view and performance metrics | Legitimate interest in understanding site use |
We do not sell personal information, share it for cross-context behavioral advertising, show advertising in the Service, build marketing profiles of students, or use students' information for any purpose other than providing the educational Service and the purposes listed above. We do not make decisions that produce legal or similarly significant effects about anyone solely by automated means; AI evaluation scores are formative feedback that educators can review, together with the full conversation behind them.
Your right to object. Where we rely on legitimate interests, you can object at any time on grounds relating to your situation; see section 13.
Is the information required? An email address is needed to have an account, and a date of birth is needed to sign up with a class code, because we must confirm you are old enough to use the Service. Without them we cannot create the account. Other information is optional or created by your use of the Service.
5. AI processing
Challenges are conversations with AI models. When you take a turn, the challenge brief, its rules and criteria, and the conversation so far are sent to an AI model to produce the next reply, and to a separate evaluation model that tracks progress and scores the session. Your name and email address are not included in these requests, but whatever you type is sent as written, so please do not include personal details in your answers.
- Provider. AI models are run for us by Microsoft through Azure AI Foundry ("Models sold by Azure"). Under Microsoft's terms, prompts and responses are not used to train, retrain, or improve Microsoft's, OpenAI's, or any third party's models, and are not shared with the model's creator. [OWNER: keep the following sentence only if any production feature is routed through OpenRouter: "Some features may use models reached through OpenRouter, Inc., restricted to hosting providers that commit to zero data retention and no training."]
- Processing location. Our model deployments use Microsoft's "Global" deployment type, so a request may be processed in any Azure region where the model runs, including outside the European Economic Area. Data that Microsoft stores at rest stays in the Azure geography of our resource, [FOUNDRY RESOURCE GEOGRAPHY].
- Some providers store prompts. Not every AI provider discards a request once it has answered. Microsoft screens every request with automated content filters, and stores prompts and responses its systems flag as potentially abusive, in the Azure geography of our resource, where authorized Microsoft staff may review them under Microsoft's terms. Other model providers may keep prompts and responses for a limited period for abuse monitoring, safety, or troubleshooting under their own terms [OWNER: name any provider in section 8 that retains prompts, and its retention period]. A provider's copy is outside our control and is not removed when we erase your data (section 13); it is deleted on the provider's own schedule. This is another reason not to type personal details into a challenge.
- No training by us. We do not use conversations, evaluations, or teacher-assistant requests to train or fine-tune AI models.
- Accuracy. AI output can be wrong. Evaluations are formative feedback for learning, not certified assessments, and educators can read the full conversation behind any score.
6. Safeguarding and integrity monitoring
To protect students, the AI is instructed to raise a safeguarding flag if a student discloses or suggests self-harm, abuse, or serious distress. When that happens:
- the session pauses and the student cannot continue it; a reviewer can release it, and a paused session that is not released is closed automatically about 24 hours after it started;
- for an assigned challenge, the teacher who created the assignment is notified in the app, with the reason, and the teacher and the Institution's administrators can review it;
- for a challenge an independent learner runs on their own, the flag goes to our platform administrators for review;
- reviewers record notes and a decision on the flag; the flag and its record remain after the session closes.
The AI also watches for messages that try to make it ignore its role or the challenge rules (for example, prompt injection). When that happens, the AI's reply is replaced with a notice and the session pauses for review by the student's teachers or our platform administrators, on the same timing as above.
Flags are produced by an AI model and can be wrong in both directions. The Service is not an emergency or crisis service and does not contact emergency services, parents, or guardians. Institutions remain responsible for their own safeguarding procedures. If you or someone else is in danger, contact local emergency services or a crisis line right away.
7. Who can see your information
- You can see your own sessions, reports, and results.
- Teachers in your Institution and teachers of your classes can see the sessions you start after you join their Institution or class, including transcripts, evaluations, and safeguarding and integrity records, whether the session came from their assignment, another teacher's assignment, or the challenge library. A teacher can also see every session on assignments they created.
- Your Institution's administrators can see accounts, memberships, sessions, and safeguarding flags within that Institution.
- Our platform administrators (a small number of our own personnel) can access all records to operate and support the Service, review independent-learner safeguarding flags, and respond to inquiries and feedback. Some access to student records, such as opening a session report or a safeguarding flag, is recorded in an access log.
- Service providers listed in section 8, only as needed to run the Service.
- Others when required: to comply with law, a court order, or a lawful request from authorities; to protect the safety of any person; to investigate fraud or security issues; or as part of a merger, acquisition, or sale of assets, in which case the recipient must honor this policy for information already collected [COUNSEL: confirm the change-of-control commitment, including any student-data restrictions under applicable state law].
8. Service providers and international transfers
We use the following providers to run the Service. Each processes personal information only on our instructions and under written terms.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting for the application, database, cache, backups, and logs | Helsinki, Finland (EU) |
| Microsoft Corporation - Entra External ID | Account sign-in, sign-in emails, and one-time codes | [ENTRA TENANT GEOGRAPHY] |
| [Google LLC - Sign in with Google, only if enabled in production] | Optional sign-in with a Google account; Google shares your name and email address with our sign-in provider | Global |
| Microsoft Corporation - Azure AI Foundry | AI model processing (see section 5) | Stored in [FOUNDRY RESOURCE GEOGRAPHY]; processed in any Azure region |
| Microsoft Corporation - Azure Key Vault and Storage | Holding the encryption keys that protect sign-in cookies (no user records) | Sweden (EU) |
| Cloudflare, Inc. | Network delivery, TLS encryption, firewall, and DDoS protection; hosting of the documentation site and student portal; Turnstile abuse checks on the contact form; cookieless Web Analytics | Global network |
| Google LLC - Google Fonts | Font files for the documentation site and admin portal (your browser sends its IP address to Google when it loads them) | Global |
| [OpenRouter, Inc. - only if used in production] | Routing to alternative AI models under zero-data-retention terms | United States; upstream hosts limited to [name them, e.g. DeepInfra, Novita] |
Some of these providers process information outside the country where you live, including in the United States. Where EU or UK personal data is transferred to a country without an adequacy decision, we rely on the provider's certification under the EU-US Data Privacy Framework (and its UK Extension) where available, or on the European Commission's Standard Contractual Clauses (with the UK Addendum) incorporated in the provider's data processing terms. You can ask us for more information about these safeguards. [COUNSEL: verify each provider's current transfer mechanism.]
9. Cookies and browser storage
We use only storage needed to run the Service or to remember a setting you chose. We do not use advertising or cross-site tracking cookies.
| Where | What | Purpose | Duration |
|---|---|---|---|
| Admin portal | Sign-in cookies (.AspNetCore.Cookies, .AspNetCore.OpenIdConnect.Nonce.*, .AspNetCore.Correlation.*) | Keep you signed in and protect the sign-in exchange | Session, or until sign-out |
| Admin portal | Anti-forgery cookie (.AspNetCore.Antiforgery.*) | Prevent cross-site request forgery | Session |
| Student portal | Sign-in tokens in browser storage | Keep you signed in | Until they expire or you sign out |
| Student portal | "Enter sends message" preference; a class join code held only until sign-up finishes | Remember your setting; complete joining a class | Until cleared; end of browser session |
| Documentation site and admin portal | Light or dark theme preference | Remember your choice | Until cleared |
| Contact form | Cloudflare Turnstile | Tell people from automated abuse | Set by Cloudflare |
| All sites | Cloudflare Web Analytics | Aggregate, cookieless page-view and performance measurement | No cookie is set |
| Documentation site | Cloudflare bot-detection script, which may set a Cloudflare security cookie [OWNER: confirm cookie name, e.g. __cf_bm, or block the script with a CSP] | Distinguish people from bots | Set by Cloudflare (typically 30 minutes) |
You can clear cookies and browser storage in your browser settings; you will then need to sign in again and re-select preferences. [COUNSEL: confirm that no consent banner is required for the strictly necessary and preference storage listed, under the ePrivacy Directive and UK PECR.]
10. How long we keep information
| Information | How long |
|---|---|
| Accounts, challenge work, evaluations, and safeguarding records | For as long as the account exists, including while it is deactivated, or as long as the Institution directs. After a verified deletion request, or when an Institution's agreement ends and it asks us to, we erase them within [30] days as described in section 13, except where we must keep them by law. |
| Contact-form inquiries and their handling history | Deleted automatically 2 years after the inquiry is closed |
| In-app feedback | Deleted automatically 2 years after the item is closed |
| Technical logs and traces | Up to 30 days |
| Database backups | 14 days, on a rolling basis |
| AI usage records, access audit records, and legal acceptance records | For the life of the account. These records hold no text and no contact details; after erasure they remain linked only to the anonymous placeholder account, as evidence of usage and of what was agreed |
Erased or deleted information may remain in database backups for up to 14 days and in technical logs for up to 30 days, until they expire.
11. Security
We protect information with measures appropriate to its sensitivity, including:
- encryption in transit between your browser and our network (TLS);
- servers that accept no direct inbound internet traffic, reached only through an encrypted tunnel behind a web application firewall;
- sign-in through Microsoft Entra External ID, so we never store your password;
- role-based permissions, separation of each Institution's data, and access logging for key student records;
- request rate limits, content security policies, and automated abuse checks;
- restricted administrative access and secrets kept out of source code.
No system is completely secure. If we learn of a breach affecting your personal information, we will notify you, your Institution, and regulators as required by law. [OWNER: before launch, consider encrypting the database disk and backups and storing backups off the server; this text deliberately does not claim encryption at rest.]
12. Children and students
- Not for children under 13. The Service is not designed for, directed to, or offered to children under 13, and we do not knowingly collect personal information from them. The Service refuses any sign-up or administrator-created account whose date of birth shows the person is under 13, and Institutions must not give access to children under 13. If we learn that an account belongs to a child under 13, we will deactivate it at once, erase its personal information as described in section 13, and tell the Institution where there is one. If you believe a child under 13 is using the Service, please contact us.
- Students in Institutions. Student information is used only to provide the educational Service to the Institution. We do not use it for advertising, sell it, or build profiles for non-educational purposes. Parents, guardians, and eligible students can ask the Institution to review, correct, or delete education records; we help the Institution respond.
- Teenagers. Users under 18, or under the age of majority where they live, should use the Service only with the permission of a parent, guardian, or their Institution. Some challenges carry age ratings and are shown only to users who meet them.
- EU and UK students. Where the Service is used by an Institution, the Institution determines the legal basis for processing students' data. We do not rely on a child's own consent for any processing. [COUNSEL: confirm GDPR Art. 8 and UK Age Appropriate Design Code position for independent learners aged 13-17.]
13. Your rights and choices
Depending on where you live, you may have the right to:
- know what personal information we hold about you and get a copy;
- correct inaccurate information;
- delete your information;
- receive your information in a portable format;
- object to, or ask us to restrict, certain processing;
- withdraw consent where we rely on it, without affecting earlier processing;
- not be treated differently for exercising these rights;
- complain to a data protection authority, such as your local EU supervisory authority or the UK Information Commissioner's Office.
What deletion does. When we act on a deletion request, we erase your personal data rather than only closing the account, and the erasure cannot be undone: the account cannot be restored, and to use the Service again you would sign up as a new user. We delete your sign-in account with our sign-in provider (Microsoft keeps a deleted sign-in account recoverable for 30 days, then removes it permanently). We replace your name, email address, and date of birth with placeholders. In challenges you ran on your own, we replace the conversation text, evaluation narratives and rationales, and checkpoint notes with "[erased]" and end any challenge still in progress. In team challenges, we erase the messages you wrote but keep your teammates' messages and the team's shared answers and scores, which are their work too; AI-written team summaries that may quote you are removed. We also erase your safeguarding reasons and reviewer notes, feedback, contact-form inquiries and any purchase contact details sent from your email address, delete your own notifications and any data exports that include you, remove links to a learning-management system, and remove your name and quoted details from notifications sent to your teachers. What remains is de-identified: scores, dates, counts, and the anonymous placeholder account that records such as class enrollments, AI usage counts, and legal acceptances still point to, so that totals and other users' records stay accurate. Copies held by AI providers (section 5), backups, and logs (section 10) expire on their own schedules. [COUNSEL: confirm that the retained de-identified records are acceptable under Art. 17 and state student-privacy deletion duties, given that an Institution may still know which placeholder belonged to which student.]
Who can erase an account. If you are an independent learner, you can erase your own account at any time from Options > Delete your account in the student portal, confirming with your account email address. An Institution's administrators can erase the accounts of their own students and teachers when the Institution receives a deletion request; an account that also belongs to another Institution, and administrator accounts, are erased by us on request so that no Institution erases data another one controls. Every erasure is recorded in an access log.
How to ask. If your account belongs to an Institution, contact the Institution first; we will forward any request we receive to it and help it respond. Otherwise, use our contact form with the "Privacy" category or write to [PRIVACY EMAIL ADDRESS]. We will verify your identity, normally by confirming the request from the email address on the account, and respond within the time the law requires (generally one month in the EU and UK, 45 days in US states). You can change your preferred language in the student portal; ask us or your Institution to change other account details. An authorized agent may act for you with written permission that we can verify.
14. Additional notices for US residents
- Categories collected (last 12 months): identifiers (name, email, account identifiers); education information (challenge work and evaluations); internet activity limited to use of the Service; age (date of birth); and sensitive information limited to account sign-in, which is handled by our sign-in provider. Sources, purposes, and recipients are described in sections 3, 4, 7, and 8.
- No sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising, and have not done so in the last 12 months. We do not knowingly sell or share the information of consumers under 16.
- Student privacy laws. We comply with applicable state student-privacy laws, such as California's Student Online Personal Information Protection Act, by using student information only for school purposes and not for targeted advertising or non-educational profiling.
- Do Not Track and Global Privacy Control. We do not track you across sites, so there is nothing for these signals to switch off.
[COUNSEL: confirm which state comprehensive privacy laws (e.g., CCPA/CPRA thresholds) actually apply to the operator, and whether a separate state-specific notice is needed.]
15. Changes to this policy
We will post any change on this page and update the version and date above. If a change is material, we will tell you in the Service and ask you to review and accept the new version the next time you sign in, and we will tell Institutions in advance where our agreement with them requires it.
16. Contact us
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Privacy questions: contact cognificance.com or [PRIVACY EMAIL ADDRESS].