Privacy
This is a small, independent teaching pilot run within a university department, intended for formative study support. It is not an official Uppsala University service, is not approved by or affiliated with Uppsala University, and holds no data-protection certification. This page describes, in plain language, how the service currently works. It is a description of practice, not legal advice, and it may change as the service changes.
Teachers
Teachers create an account with an email address and password. A teacher's name (or display name) and email address are personal data. We store that email address, a display name, the role of the account, and simple activity timestamps such as when the account was last used. Teacher accounts are not anonymous: the person who runs and supports this pilot (the service administrator) can see teacher account information.
This account data is used to:
- authenticate sign-in and manage the account;
- tie each course, activity and material to its owner, so one teacher's material stays separate from every other teacher's;
- operate the pilot and provide support when something goes wrong;
- keep an eye on stored volume and prevent abuse of the service.
Teachers can only see their own courses, activities and material.
Course material
When a teacher attaches a file, the text is currently read from it inside the teacher's own browser. The extracted text and basic details about it (a label, file type, size and status) are then stored on our side so the activity works across devices and sessions. Original uploaded files are not stored as files.
Teachers are responsible for the material they attach: for being entitled to use it for this teaching purpose, and for not including confidential information, sensitive personal data, student work, or anything else that should not be processed through this service. Before creating an activity a teacher has to confirm this.
Who can see stored course material
- Stored course material is private to the teacher account that created it and is not made available to other teachers.
- Students are tutored from it, but are not given the uploaded source files and have no interface for browsing or reading the stored course text.
- The service administrator can see teacher account information and the operational metadata needed to run and support the pilot — teacher name and email, course and activity names, material labels, status, size and processing errors. The administrator interface does not provide ordinary access to read the stored extracted course text.
- The material is processed automatically by hosting, database and AI infrastructure as necessary to provide the service, so we do not claim that nobody can access it in any circumstance.
Deleting course material
A teacher can delete any of their own activities or a whole course at any time from the teacher portal. Deleting an activity also deletes the text stored from its material; deleting a course deletes the course together with every activity and material under it. Deletion is permanent. When the administrator deletes a teacher account, its courses, activities and materials are deleted with it under the current architecture. Ordinary backups or provider logs may persist for a short period outside the application database.
You are interacting with an AI system
This service is an artificial-intelligence system. The questions, the assessments of answers, the explanations and the feedback are generated by an AI language model, not written or reviewed by a teacher in advance. Output can be incomplete, unclear or wrong, and it is not a grade, an assessment decision or professional advice. We state this openly so that everyone using the service knows they are talking to a machine; this reflects the transparency expectation in Article 50 of the EU AI Act. We do not claim any form of blanket or certified compliance with that Act or with any other law.
AI processing
To run a tutoring session, relevant course text and the current conversation are sent to an external AI service that generates the questions and feedback. That means a third-party processor is involved in providing the service. The specific providers used may change during the pilot.
Course material and tutoring prompts are processed to provide the service. Under the service configuration used for this pilot, customer content is not used to train the service providers' AI models. This is a statement about model training only. It is not a claim that nothing is processed, transmitted or temporarily retained: providing the service necessarily involves sending content to processors, who may retain it briefly for operational purposes such as delivering the response, abuse prevention and troubleshooting.
What we process, and why
In short, the categories of data and the purposes they serve are:
- Teacher account data (email address, display name, account role, sign-in and last-active timestamps) — to let staff sign in, to keep each teacher's material separate from other teachers', and to operate the pilot.
- Teaching content (extracted course text and basic file details such as label, type, size and processing status) — to make a tutoring activity work across devices.
- Tutoring interaction content (course text and the running conversation) — sent to an AI provider to generate the next question and the feedback.
- Anonymous operational counters (that an activity was started or completed, when, which activity, rough measures such as a question count) — to see whether the service is being used and working.
- Contact enquiries (name, email address, any affiliation, subject and message) — to read and answer what you sent.
We do not use any of this for advertising, profiling of students, or automated decisions about a person's education, employment or access to services.
Students
Students remain anonymous. No student account is required, students are never asked to identify themselves, and nothing links a session to a person. Student answers, conversation transcripts and the tutor's internal picture of what a student knows are currently not stored on our side — they exist only for the duration of the session in the student's browser and in the AI request that produces the next question. Teachers cannot see student answers, results or a learning profile.
We do record small anonymous counters for operating the service, such as that an activity was started or completed, when, which activity it was, and rough measures like a number of questions. These counters are not linked to a person. The application does not intentionally store IP addresses or device fingerprints in its own database, and does not use them to identify or profile students. Hosting, database and AI providers may however keep ordinary security and access logs of their own, which can include technical details such as IP addresses, as part of running any internet service.
Contact & feedback form
If you write to us through the contact & feedback form, we keep what you send — your name, email address, any affiliation and your message — in order to read it, reply to it and follow it up during the pilot. There is currently no outbound email provider configured, so messages are stored for the person running the pilot, who reads them and replies manually.
Where data is processed
The service runs on third-party hosting, database and AI infrastructure, so those providers process data on our behalf as part of delivering it. Some of these processors may process data outside your own country or outside the EEA, subject to the safeguards that apply to their services. We cannot promise that all processing stays in one country.
Keeping and deleting data
Teacher accounts, courses, activities and stored course text are kept while the account is in use in the pilot. A teacher can permanently delete their own activities, their stored material text, or a whole course with everything under it. The service administrator can delete a teacher account, which removes that teacher's courses, activities and materials with it. Contact and feedback messages are kept while they are relevant to answering and following up. Anonymous operational counters may be kept in aggregate.
Your requests
If you want to know what we hold about you, have it corrected, or have it deleted, write to us through the contact & feedback page and we will handle it as best we can within the limits of a pilot service. Depending on where you live, you may also have rights under local data protection law, which this page does not replace or limit. In the EEA and the UK those rights typically include access, correction, deletion, restriction, objection and data portability, and you may also lodge a complaint with the competent data-protection supervisory authority in your country.
Still to be settled
This is a pilot and some formal details are deliberately not stated here yet, because they have not been established: the legal entity acting as data controller, the lawful basis relied on for each purpose, any data-protection contact or representative, and the written processor arrangements behind the service. This page is written for use in a small departmental teaching pilot on that basis. Formal review — together with the institutions involved, and in line with the requirements of the university and department where it is used — is needed before the service is deployed more broadly, opened to the public, or used commercially. Until then, please treat this page as a description of current technical practice rather than a complete legal notice.