Home / Student data & privacy
How we handle student data.
Most of the people using this programme are children. This page sets out what we collect, why, who can see it, how long we keep it, and the standards we designed against — in plain language first, and in the documents your data protection lead will want underneath.
Version 1.0 draft · Last reviewed September 2026
In one paragraph
Eight things that are always true.
Whatever country you are in and whichever door you came through, these hold.
What we collect
Every field, and the reason it exists.
If a field is not in this table, we do not collect it.
| Data | Why we need it | Who can see it | Kept for |
|---|---|---|---|
| Name | To show a teacher and the learner whose record it is | Learner, their teachers, school admins, guardian | Life of the account |
| School / guardian-approved email | Sign-in and Google Classroom sync | Learner, school admins | Life of the account |
| Year group / age band | Age-appropriate defaults and correct level placement | Teachers, school admins | Life of the account |
| Class and school | Class dashboards, leaderboards and reports | Teachers, school admins | Life of the agreement |
| Foundations Challenge result | The baseline every later report measures against | Learner, teachers, guardian | Life of the account |
| Mastery-check scores and answers | Progress, feedback on wrong answers, grade sync | Learner, teachers, guardian | Life of the account |
| Submitted code and artefacts | Rubric marking and the evidence attached to credentials | Learner, teachers, our moderators on request | Life of the account |
| Lesson activity (which lesson, when, how long) | Resume where you left off; "who is stuck" flags for teachers | Learner, teachers | 12 months, then aggregated |
| Community posts (13+ only, optional) | Peer help. First name or handle only; moderated | Other learners in the same community | Until deleted by the learner |
| Support tickets | Fixing the problem the learner wrote in about | Our support team, the school's named contact | 24 months |
Home address · date of birth beyond an age band · photographs or webcam · precise location · biometric data · browsing outside the platform · advertising identifiers · anything about health, ethnicity, religion or family circumstances. There is no proctoring camera and there never will be.
Individuals and institutions — two sets of rules
Who is responsible for what.
Through a school
The school is the controller; we are the processor. The school decides who is enrolled, what the leaderboard shows, which reports are produced and when data is deleted. We do only what the data processing agreement says.
Consent for under-13s in the US is given by the school on the parent's behalf, as COPPA allows for educational use; the school tells parents through its usual notices, and we give it the wording. In Europe the school's public-task or contract basis applies, and we support it with a completed DPIA template.
Every school gets a named data contact on our side, a sub-processor list, and 30 days' notice before any change to it.
Signing up on your own
We are the controller, and the age gate is real. At sign-up we ask for an age band, not a date of birth. Under 13 (or the higher threshold your country sets, up to 16) the account is created only once a parent or guardian has approved it by email — a method proportionate to the low risk of the service, in line with IEEE 2089.1.
A guardian can be attached to any under-18 account and sees the same progress record the learner does. Community access is off until 13 and can be kept off by the guardian.
Adults get the same minimum-data policy. There is nothing on the professional track that we would not be comfortable showing a school.
Standards & regulation
What we designed against, and what it means in practice.
Alignment is a claim about how the product is built, not a badge. For each standard below, the right-hand line says what it actually changed in the platform.
Country-specific requirements beyond these — for example India's DPDP Act rules on children's data, or Australia's Privacy Act — are mapped in the agreement for each school's jurisdiction. Ask your data contact for the mapping table.
Assessment data specifically
What the scores are used for — and not.
Assessment data is the most sensitive thing we hold about a child, because it says something about them. So the rules around it are tighter than for the rest.
- Scores are used to give the learner feedback, to show teachers and guardians progress, and to issue credentials. That is the complete list.
- Mastery checks are auto-marked; the marking is rule-based and explained per question. No score is produced by a model a teacher cannot inspect.
- A teacher can override any automated mark. The override is recorded and wins.
- Leaderboards rank progress made, never raw scores, and are controlled by the school — named, anonymous or off. Off by default under 13.
- Cohort-level, de-identified outcomes (never fewer than 20 students) may be used to improve the curriculum and to report on the programme. A school can opt out of even that.
- Credentials carry the evidence the learner chooses to attach and nothing about how they compared with anyone else.
Your rights, and how to use them
| You are | You can | How |
|---|---|---|
| A school | Access, export, correct, restrict or delete any record; audit us; end the agreement | Admin dashboard, or your named data contact |
| A parent or guardian | See your child's record, ask for correction or deletion, withdraw consent | Through the school, or the guardian view on a direct account |
| A learner | See everything held about you, download it, correct it, delete your account, keep your credentials | Settings → Your data, or by email |
Every request is acknowledged within two working days and answered within 30 days. If we get it wrong, you can complain to your national data protection authority, and we will tell you which one.
Website visitors — GDPR privacy notice
If you only ever visit this website.
The sections above cover learners and schools on the platform. This section is the formal notice for anyone who reads aininjas.com or sends us a form, as required by the EU and UK General Data Protection Regulation.
Who is responsible
Neuralpath Dynamics Inc (trading as AI Ninjas), 19 Zirkel Ave, Piscataway, NJ 08854, United States, is the data controller for this website. Contact: privacy@aininjas.com.
What we collect, and why
| When you | We process | Purpose & lawful basis | Kept for |
|---|---|---|---|
| Visit any page | Server logs: IP address, browser type, pages requested, time | Security, fault-finding and abuse prevention — legitimate interest (Art. 6(1)(f)) | Up to 30 days, by our hosting provider |
| Accept analytics cookies | Pseudonymous usage data via Google Analytics 4 (page views, approximate location, device type). IP addresses are truncated. | Understanding which pages are useful — consent (Art. 6(1)(a)); nothing is set until you accept | Up to 14 months, then aggregated |
| Send an enquiry, pilot request, partner enquiry or “notify me” form | The details you type: name, email, organisation, role, country, message | Answering you and, for schools, arranging a pilot — steps before a contract (Art. 6(1)(b)) and consent for the follow-up you asked for | Up to 12 months after our last exchange, or until you ask us to delete it |
| Enrol on the platform | Handled on our learning platform, which has its own notice shown at sign-up | Performing the contract with you (Art. 6(1)(b)) | See platform notice and the learner sections above |
We do not sell personal data, do not use it for advertising, and do not make automated decisions about you.
Who else sees it
Only the processors we need to run the site: our web host (which stores server logs), our email provider (which delivers form submissions to our inbox), and — only if you consent — Google Ireland Ltd for analytics. Google may transfer analytics data to the United States under the EU–US Data Privacy Framework and standard contractual clauses. We do not share form submissions with anyone outside AI Ninjas and Neuralpath Dynamics.
International transfers. Neuralpath Dynamics Inc is based in the United States, so anything you send through this website is stored and read there. For visitors in the EU, EEA and UK we rely on standard contractual clauses (and the UK addendum) to protect that transfer, and you have the same rights over your data as set out below regardless of where it is held.
Cookies
One strictly necessary cookie-like entry (stored in your browser, named ainj_consent) remembers your cookie choice for 12 months. Google Analytics cookies (_ga, _ga_*) are set only after you accept analytics. The full list, and how to change your mind, is on the cookie policy; you can also reopen the banner from “Cookie settings” in the footer.
Your rights
Under the GDPR you can ask us to: tell you what we hold about you and give you a copy; correct it; delete it; restrict or object to how we use it; hand it to you in a portable format; and withdraw consent at any time without affecting what was done before. Email privacy@aininjas.com. We acknowledge within two working days and answer within one month, free of charge.
If you think we have handled your data unlawfully you can complain to your data protection authority — in the UK the Information Commissioner’s Office, in the EU the authority for your country (listed by the European Data Protection Board). We would rather you told us first so we can put it right.
Children
This website’s forms are intended for adults: teachers, parents, professionals and partners. If you are under 16 please ask a parent, guardian or teacher to contact us on your behalf. Student accounts on the platform are covered by the sections above, including parental and school controls.
Changes
This notice was last updated on . If we change what we collect or why, we will update this page and, where the change is material, tell registered users by email.
Documents
For your data protection lead.
Data processing agreement
Processor terms, sub-processors, breach notice, return-and-erase, audit rights.
DPIA template
Pre-filled for the platform; the school completes its own context and risk rating.
Security overview
Hosting regions, encryption, access control, logging, retention schedule and backup.
Standards mapping
IEEE 2089, IEEE 2089.1, COPPA, FERPA, GDPR / UK AADC, and country addenda — control by control.
None of these is behind a form. If a document you need is not here, ask — the person who needs it is usually forwarding it to a colleague.
Questions your data protection lead has?
Put them to a person. The data contact joins the discovery call whenever a school asks.
