Privacy & your data

You own your learning record. This page explains, in plain language, what we store, who can see it, and the switches you control — no legalese, no dark patterns.

What you own

Learning history, skill graph overlay, evidence vault, cognitive profile, goals, memory, sharing permissions, and your credentials (subject to issuer semantics). Export and deletion are self-service, not support tickets.

Manage export & deletion in your Vault

Consent & minors

The platform may be used by students of any age, so consent adapts to age and region instead of assuming one universal threshold. Guardian or sponsor flows exist only where law or product policy requires them, and paying for someone never grants access to their private learning content.

By default we disclose the minimum: private tutor logs are not exposed to parents, schools, or employers, connected-source permissions are granular, and every consent decision is versioned and auditable.

Data dividend — always opt-in

Private OnlyAnonymous ImprovementResearchPublic Knowledge

Contribution starts at Private Only. If you choose to opt in further — Anonymous Improvement, Research Contribution, or Public Knowledge Contribution — value returns transparently through credits, revenue share, or reputation. Consent is revocable and stops future use.

One honest limit: contributed data already absorbed into trained model weights cannot be retroactively removed unless the underlying technique supports it. We say exactly which is which rather than over-promising.

What we can and cannot see

Sensitive data is encrypted at rest with selective disclosure and scoped access grants. We do not claim impossible “zero knowledge”: this page and your Vault document precisely what remains visible to the platform and what does not.

docs/security/review.md · docs/privacy/review.md

Delete your account

Deleting revokes every share link, EVS token and credential, crypto-shreds your vault encryption keys, erases memory entries and anonymizes your identity. Billing records are retained. This cannot be undone — export your data first.

Download your portable identity package first.