Legal

Privacy Policy

How AI Challenge Portal collects, uses, shares, protects, and keeps information about the students, educators, administrators, and visitors who use it.

Draft for legal review

This text describes how the service actually works today and is prepared for review by counsel. Bracketed, highlighted items are facts the operator must supply or decisions counsel must confirm. It is not final until they are resolved and this notice is removed.

1. Who we are

AI Challenge Portal ("the Service") is a critical-thinking practice platform operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], trading as cognificance.com ("we", "us", "our"). The Service consists of the public documentation site at cognificance.com, the student portal, the management (admin) portal, and the application programming interface behind them.

Questions about this policy or your information can be sent through our contact form (choose the "Privacy" category) or to [PRIVACY EMAIL ADDRESS]. [COUNSEL: if the operator is established outside the EU/UK and serves EU/UK users, name the Article 27 representative(s) here, or confirm none is required. State whether a data protection officer is appointed; if not, say so.]

2. Scope and our role

This policy covers everyone who uses the Service: students and independent learners in the student portal; teachers, institution administrators, and platform administrators in the admin portal; and visitors to the documentation site, including people who use the public contact form.

3. Information we collect

Information you or your Institution give us

Information created when you use the Service

Information from third parties

We do not ask for, and ask you not to enter, sensitive information such as health details, government identifiers, or financial information in challenge conversations.

4. How we use information and our legal bases

PurposeInformationLegal basis (EU/UK GDPR)
Create and run your account, route you to the right portal, and enforce role permissionsAccount, institution, and identity recordsContract with you; for Institutional accounts, the Institution's instructions
Run challenges, generate AI replies, evaluate sessions, and show results to you and your educatorsChallenge work, evaluationsContract; Institution's instructions
Apply age ratings to challenges and the minimum-age rule for sign-upDate of birthLegitimate interest in protecting younger users and meeting age-based legal requirements [COUNSEL: name the specific obligation, e.g. COPPA, if relied on]
Safeguarding: detect and escalate possible risk to a studentChallenge work, safeguarding recordsLegitimate interest in student welfare; where it applies, vital interests or the Institution's safeguarding duties. Disclosures about self-harm or abuse can be health data: [COUNSEL: Art. 9(2) condition, e.g. substantial public interest (safeguarding of children) under member-state or UK law]
Integrity: pause a session when a message tries to override the challenge rules, for reviewChallenge work, integrity recordsLegitimate interest in fair, secure assessment; Institution's instructions
Respond to inquiries and feedbackInquiry and feedback recordsLegitimate interest in answering you; steps you request before a contract
Security, abuse prevention, debugging, and capacity and cost trackingTechnical logs, usage and audit records, Turnstile resultLegitimate interest in a secure, reliable service
Record your acceptance of our legal termsLegal acceptance recordsLegal obligation and legitimate interest in proving agreement
Aggregate site measurementCookieless page-view and performance metricsLegitimate interest in understanding site use

We do not sell personal information, share it for cross-context behavioral advertising, show advertising in the Service, build marketing profiles of students, or use students' information for any purpose other than providing the educational Service and the purposes listed above. We do not make decisions that produce legal or similarly significant effects about anyone solely by automated means; AI evaluation scores are formative feedback that educators can review, together with the full conversation behind them.

Your right to object. Where we rely on legitimate interests, you can object at any time on grounds relating to your situation; see section 13.

Is the information required? An email address is needed to have an account, and a date of birth is needed to sign up with a class code, because we must confirm you are old enough to use the Service. Without them we cannot create the account. Other information is optional or created by your use of the Service.

5. AI processing

Challenges are conversations with AI models. When you take a turn, the challenge brief, its rules and criteria, and the conversation so far are sent to an AI model to produce the next reply, and to a separate evaluation model that tracks progress and scores the session. Your name and email address are not included in these requests, but whatever you type is sent as written, so please do not include personal details in your answers.

6. Safeguarding and integrity monitoring

To protect students, the AI is instructed to raise a safeguarding flag if a student discloses or suggests self-harm, abuse, or serious distress. When that happens:

The AI also watches for messages that try to make it ignore its role or the challenge rules (for example, prompt injection). When that happens, the AI's reply is replaced with a notice and the session pauses for review by the student's teachers or our platform administrators, on the same timing as above.

Flags are produced by an AI model and can be wrong in both directions. The Service is not an emergency or crisis service and does not contact emergency services, parents, or guardians. Institutions remain responsible for their own safeguarding procedures. If you or someone else is in danger, contact local emergency services or a crisis line right away.

7. Who can see your information

8. Service providers and international transfers

We use the following providers to run the Service. Each processes personal information only on our instructions and under written terms.

ProviderPurposeLocation
Hetzner Online GmbHServer hosting for the application, database, cache, backups, and logsHelsinki, Finland (EU)
Microsoft Corporation - Entra External IDAccount sign-in, sign-in emails, and one-time codes[ENTRA TENANT GEOGRAPHY]
[Google LLC - Sign in with Google, only if enabled in production]Optional sign-in with a Google account; Google shares your name and email address with our sign-in providerGlobal
Microsoft Corporation - Azure AI FoundryAI model processing (see section 5)Stored in [FOUNDRY RESOURCE GEOGRAPHY]; processed in any Azure region
Microsoft Corporation - Azure Key Vault and StorageHolding the encryption keys that protect sign-in cookies (no user records)Sweden (EU)
Cloudflare, Inc.Network delivery, TLS encryption, firewall, and DDoS protection; hosting of the documentation site and student portal; Turnstile abuse checks on the contact form; cookieless Web AnalyticsGlobal network
Google LLC - Google FontsFont files for the documentation site and admin portal (your browser sends its IP address to Google when it loads them)Global
[OpenRouter, Inc. - only if used in production]Routing to alternative AI models under zero-data-retention termsUnited States; upstream hosts limited to [name them, e.g. DeepInfra, Novita]

Some of these providers process information outside the country where you live, including in the United States. Where EU or UK personal data is transferred to a country without an adequacy decision, we rely on the provider's certification under the EU-US Data Privacy Framework (and its UK Extension) where available, or on the European Commission's Standard Contractual Clauses (with the UK Addendum) incorporated in the provider's data processing terms. You can ask us for more information about these safeguards. [COUNSEL: verify each provider's current transfer mechanism.]

9. Cookies and browser storage

We use only storage needed to run the Service or to remember a setting you chose. We do not use advertising or cross-site tracking cookies.

WhereWhatPurposeDuration
Admin portalSign-in cookies (.AspNetCore.Cookies, .AspNetCore.OpenIdConnect.Nonce.*, .AspNetCore.Correlation.*)Keep you signed in and protect the sign-in exchangeSession, or until sign-out
Admin portalAnti-forgery cookie (.AspNetCore.Antiforgery.*)Prevent cross-site request forgerySession
Student portalSign-in tokens in browser storageKeep you signed inUntil they expire or you sign out
Student portal"Enter sends message" preference; a class join code held only until sign-up finishesRemember your setting; complete joining a classUntil cleared; end of browser session
Documentation site and admin portalLight or dark theme preferenceRemember your choiceUntil cleared
Contact formCloudflare TurnstileTell people from automated abuseSet by Cloudflare
All sitesCloudflare Web AnalyticsAggregate, cookieless page-view and performance measurementNo cookie is set
Documentation siteCloudflare bot-detection script, which may set a Cloudflare security cookie [OWNER: confirm cookie name, e.g. __cf_bm, or block the script with a CSP]Distinguish people from botsSet by Cloudflare (typically 30 minutes)

You can clear cookies and browser storage in your browser settings; you will then need to sign in again and re-select preferences. [COUNSEL: confirm that no consent banner is required for the strictly necessary and preference storage listed, under the ePrivacy Directive and UK PECR.]

10. How long we keep information

InformationHow long
Accounts, challenge work, evaluations, and safeguarding recordsFor as long as the account exists, including while it is deactivated, or as long as the Institution directs. After a verified deletion request, or when an Institution's agreement ends and it asks us to, we erase them within [30] days as described in section 13, except where we must keep them by law.
Contact-form inquiries and their handling historyDeleted automatically 2 years after the inquiry is closed
In-app feedbackDeleted automatically 2 years after the item is closed
Technical logs and tracesUp to 30 days
Database backups14 days, on a rolling basis
AI usage records, access audit records, and legal acceptance recordsFor the life of the account. These records hold no text and no contact details; after erasure they remain linked only to the anonymous placeholder account, as evidence of usage and of what was agreed

Erased or deleted information may remain in database backups for up to 14 days and in technical logs for up to 30 days, until they expire.

11. Security

We protect information with measures appropriate to its sensitivity, including:

No system is completely secure. If we learn of a breach affecting your personal information, we will notify you, your Institution, and regulators as required by law. [OWNER: before launch, consider encrypting the database disk and backups and storing backups off the server; this text deliberately does not claim encryption at rest.]

12. Children and students

13. Your rights and choices

Depending on where you live, you may have the right to:

What deletion does. When we act on a deletion request, we erase your personal data rather than only closing the account, and the erasure cannot be undone: the account cannot be restored, and to use the Service again you would sign up as a new user. We delete your sign-in account with our sign-in provider (Microsoft keeps a deleted sign-in account recoverable for 30 days, then removes it permanently). We replace your name, email address, and date of birth with placeholders. In challenges you ran on your own, we replace the conversation text, evaluation narratives and rationales, and checkpoint notes with "[erased]" and end any challenge still in progress. In team challenges, we erase the messages you wrote but keep your teammates' messages and the team's shared answers and scores, which are their work too; AI-written team summaries that may quote you are removed. We also erase your safeguarding reasons and reviewer notes, feedback, contact-form inquiries and any purchase contact details sent from your email address, delete your own notifications and any data exports that include you, remove links to a learning-management system, and remove your name and quoted details from notifications sent to your teachers. What remains is de-identified: scores, dates, counts, and the anonymous placeholder account that records such as class enrollments, AI usage counts, and legal acceptances still point to, so that totals and other users' records stay accurate. Copies held by AI providers (section 5), backups, and logs (section 10) expire on their own schedules. [COUNSEL: confirm that the retained de-identified records are acceptable under Art. 17 and state student-privacy deletion duties, given that an Institution may still know which placeholder belonged to which student.]

Who can erase an account. If you are an independent learner, you can erase your own account at any time from Options > Delete your account in the student portal, confirming with your account email address. An Institution's administrators can erase the accounts of their own students and teachers when the Institution receives a deletion request; an account that also belongs to another Institution, and administrator accounts, are erased by us on request so that no Institution erases data another one controls. Every erasure is recorded in an access log.

How to ask. If your account belongs to an Institution, contact the Institution first; we will forward any request we receive to it and help it respond. Otherwise, use our contact form with the "Privacy" category or write to [PRIVACY EMAIL ADDRESS]. We will verify your identity, normally by confirming the request from the email address on the account, and respond within the time the law requires (generally one month in the EU and UK, 45 days in US states). You can change your preferred language in the student portal; ask us or your Institution to change other account details. An authorized agent may act for you with written permission that we can verify.

14. Additional notices for US residents

[COUNSEL: confirm which state comprehensive privacy laws (e.g., CCPA/CPRA thresholds) actually apply to the operator, and whether a separate state-specific notice is needed.]

15. Changes to this policy

We will post any change on this page and update the version and date above. If a change is material, we will tell you in the Service and ask you to review and accept the new version the next time you sign in, and we will tell Institutions in advance where our agreement with them requires it.

16. Contact us

[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Privacy questions: contact cognificance.com or [PRIVACY EMAIL ADDRESS].