Legal
Privacy Policy
Last updated: April 15, 2026. Rigorous Reasoning is an education platform and we take the privacy of learner and instructor data seriously. This policy explains what we collect, why, and what control you have over it.
1. Data we collect
We collect the minimum data required to run the Service:
- Account data: display name, email address, hashed password, role (student or instructor), and email verification status.
- Learning data: responses you submit to lesson activities, scores, AI-generated feedback, and progress indicators (units started, lessons completed, mastery status).
- Course data: course enrollments, assignment completion, and gradebook rollups visible to your instructor.
- Billing data: for paid plans, Stripe handles payment information. We store only a Stripe customer ID and subscription status — we do not store card numbers.
- Operational logs: error reports via Sentry, limited to stack traces and non-identifying debug context.
2. How we use data
We use data to: (a) deliver the curriculum and feedback you requested; (b) show your progress on your own dashboard; (c) show instructor dashboards scoped to their own enrolled students; (d) process billing; (e) diagnose platform errors. We do not sell personal data. We do not share learning data with advertisers.
3. AI processing
Activity responses may be sent to a third-party AI provider to generate feedback. The provider processes the submission on our behalf and under a data processing agreement that prohibits using submissions to train their models. Submissions are not retained by the provider beyond what is needed to return a response.
4. Instructor visibility
When you join a course via a class join code or instructor enrollment, that instructor can see your display name, email, completion percentages, and average scores for assignments they created. They cannot see your work in other courses or your private study activity.
5. Data retention
Account and learning data are retained while your account is active. You can request deletion by contacting support. Upon account deletion, personal identifiers are removed within 30 days. Anonymized aggregate data may be retained for product analytics.
6. Your rights
You can: (a) view your account and progress data via your dashboard; (b) export your submissions by contacting support; (c) correct your display name and email through account settings; (d) request deletion of your account. Users in jurisdictions with applicable data protection laws (GDPR, CCPA, etc.) have additional rights that we will honor upon verified request.
7. Children and FERPA
See our FERPA Statement for information about how we handle educational records and institutional data protection commitments.
8. Security
Passwords are hashed using industry-standard algorithms. Session cookies are HTTP-only and secure. All traffic is encrypted in transit. Database access is restricted to platform servers.
9. Contact
Privacy questions, data access requests, and deletion requests can be sent to privacy@rigorousreasoning.com.