Developed under license from Carnegie Mellon University

Privacy & Data Handling

Last updated 2026-08-10 · Draft for review

This is a plain-language draft written from how the system works, for review before launch. It is not legal advice and will be superseded by the final privacy policy.

This page explains, in plain language, what Atlas AI Academy (the "platform") collects when you take an assessment, why, which third parties it is shared with, how long it is kept, and your rights. It is a pre-launch draft written from how the system actually behaves — not a substitute for the final, lawyer-reviewed privacy policy.

1. What we collect

  • Account: name, email, country/region, password (stored only as a secure hash — we never see the plaintext).
  • Optional profile: role, industry, education, age range, AI experience; and a voluntary disability self-ID (sensitive; a "prefer not to say" option is always available).
  • Assessment data: your answers, scores, per-question timing, results and certificates.
  • Proctoring data (formal exams only, and only after your explicit consent): screen-share frames/screenshots, camera frames, an identity photo, and integrity signals (e.g. tab switches, whether a face is detected, answer pacing).
  • Technical: IP address (rate limiting + recording consent), browser/device info, error diagnostics.
  • Payment: handled by Lemon Squeezy; we do not store your card number.

2. Why we collect it

  • To deliver and score your assessment, and issue and verify certificates.
  • For remote proctoring and exam-integrity review (formal exams only).
  • To provide accessibility accommodations (e.g. extra time). Disability status is used only for accessibility support and aggregate reporting — never for scoring or certification.
  • For aggregate, anonymised research — only if you opt in to research participation; declining does not affect your use.
  • For account security, anti-cheating, and troubleshooting.

3. Sensitive data & consent

Before any screen or camera capture begins, remote proctoring first obtains your explicit, provable consent (we record the version and time). Disability and accommodation requests are voluntary and never used in scoring. Research participation is opt-in.

4. Who can see it

  • Proctoring frames and integrity flags are visible only to reviewers (admins / your organization’s leaders), served via time-limited signed links, and every reveal is written to an audit log.
  • The identity photo on a certificate is shown only to signed-in verifiers, never in the public verification result.
  • Your report is yours; the integrity summary sent to reviewers is not shown to other ordinary users.

5. Third parties (sub-processors)

  • Supabase — database and file storage (including proctoring media, in a private bucket).
  • Render / Vercel / Cloudflare — backend hosting / frontend hosting / CDN and security.
  • Lemon Squeezy — payment processing.
  • Resend — transactional email (e.g. verification codes, result notices).
  • Anthropic — scoring of open-ended answers: your free-text responses are sent to Anthropic’s model to be graded against a rubric. Please do not include personal information you don’t want shared in free-text answers.
  • Sentry — error monitoring (only when enabled).
  • These services may process data outside your country/region.

6. Retention & deletion

  • Assessment records: you can delete individual records yourself in Profile → History.
  • Certificates: retained to support long-term verification (certificates are valid for 3 years).
  • Proctoring media (recordings/screenshots/identity photo): automatically deleted about 90 days after the exam (both the stored files and the database records); an identity photo on a certificate is kept for the certificate’s validity and purged when the certificate is revoked.
  • Account deletion: you can permanently delete your account and all associated data yourself in Profile → Settings (password confirmation required); organization owners must transfer or delete their organization first.

7. Your rights

You may access, correct, and delete your personal data, withdraw consent you have given, and object to certain processing. Most information is editable directly on your profile; for other requests, email us and we will respond within a reasonable time.

8. How we protect data

  • Encryption in transit (HTTPS).
  • Proctoring media stored privately, reachable only via time-limited signed links.
  • Passwords stored only as secure hashes; sessions use server-revocable tokens.
  • Role-based access control + audit logging of sensitive-data access.

9. Contact

For privacy questions or to exercise your rights, contact privacy@atlas-ai.academy. The platform is developed under license from Carnegie Mellon University; see the attribution notice for content copyright.

Atlas AI Academy · Developed under license from Carnegie Mellon University