1. Data we collect
To operate an AI-personalized academy, we collect the following:
- Account data — name, email, role, and authentication details, including whether multi-factor authentication is enabled.
- Learning data — enrollments, lesson progress, quiz and exam results, lab sessions and commands, CTF attempts, submissions, and certificates.
- Skills & profile data — your skill ratings, goals, learning style, pace, streak, and self-described strengths and gaps.
- AI interaction data — conversations with agents, the messages within them, and safety flags raised during those interactions.
- Billing data — subscription plan, interval, and payment records (card details are handled by our payment processor, not stored by us).
- Operational logs — audit logs, lab alerts, and safety incidents needed to keep the platform secure and lawful.
2. Student memory
To personalize your training, our AI agents maintain a per-student memory store — durable notes about your goals, recurring mistakes, preferred pace, and progress. This memory is what lets a trainer pick up where you left off and adapt to how you learn. Student memory is scoped to your account only. You can view and delete individual memory entries at any time from your profile settings, and deleting an entry removes it from future agent context.
3. Cross-student isolation
Your data is isolated from other learners. Agents can only access the context of the student who made the request — no agent can read another student’s conversations, grades, memory, or progress. In institutional accounts, managers see aggregate and cohort-level analytics but not private conversation content. This isolation is enforced at the data layer, not merely by policy.
4. How we use your data
- To personalize lessons, recommendations, and difficulty to your skills matrix.
- To grade assessments and issue verifiable certificates.
- To supervise labs and enforce safety and legal boundaries.
- To provide support, process billing, and secure the platform.
We do not sell your personal data, and we do not use your private lab or conversation content to train third-party models.
5. AI processing & transparency
Instruction, grading, lab supervision, and certification are performed by AI agents. Decisions are recorded so they can be explained and appealed. See our AI transparency policy for details.
6. Your rights & deletion
You can:
- Access and update your profile and learning data.
- Delete individual student-memory entries at any time.
- Request full account deletion, which removes your personal data and memory (records we must keep for legal, security, or credential-verification reasons — such as issued certificate serials and audit logs — are retained as noted below).
- Export your learning records.
7. Retention
We keep account and learning data for as long as your account is active. After deletion, personal data and student memory are removed within a reasonable period. Certificate verification records, safety incidents, and audit logs are retained longer where required to preserve the integrity of issued credentials and to meet legal and security obligations. Lab sessions are ephemeral and their environments are destroyed after the session ends.
8. Security
We use isolation, access controls, audit logging, and optional multi-factor authentication to protect your data. Labs run in disconnected networks so training activity cannot reach systems outside the environment.
9. Contact
Privacy questions or deletion requests can be sent through our contact page.