Privacy

Privacy notice

Plain-language summary of the data CyberLab handles for schools, teachers and students.

Draft for review. This document is a working draft for a prototype and has not been reviewed by legal counsel. It is not a binding agreement and does not claim any compliance certification. Last updated 29 September 2026.

Who this applies to

CyberLab is provided to schools. The school is responsible for deciding which students and staff use the platform and for the lawful basis of that use. CyberLab processes personal data on the school’s instructions.

What we collect

Account details: name, school email address, role and class membership.

Learning activity: lab attempts, answers, scores, hint usage, time on task and AI tutor messages sent within a lab.

Technical data needed to operate the service, such as session identifiers and basic request logs.

We do not collect home addresses, phone numbers, precise location, biometric data or payment details from students.

How data is used

To run labs, record progress, and let teachers review and grade their own students’ work.

To show school administrators aggregate usage for their own school.

Student data is not sold, and is not used for advertising or to build marketing profiles.

AI tutor

The in-lab tutor gives hints about the current simulated scenario. In this prototype, tutor responses are pre-written and no messages are sent to an external AI provider.

If a model-backed tutor is introduced, this page will be updated first to name the provider, what is sent, and how long it is kept. Students should not type personal information into the tutor.

Who can see it

Students see their own work. Teachers see the classes they teach. School administrators see their own school. A small number of platform staff can access data to provide support, and that access is intended to be logged.

Data is shared with infrastructure providers only as needed to host the service.

Retention

Data is kept while the school’s subscription is active. Retention periods after a school leaves are still being defined and will be published here before any production launch.

Export and deletion

Signed-in users can submit data export and deletion requests from “Your data” in the app. Student requests are routed to the school administrator, who confirms them on the school’s behalf.

Parents or guardians should contact the school directly, since the school controls student accounts.

Contact

Questions about this policy can be sent through your school administrator, or via the demo request form on our homepage.