Cognity
    Product
    For Schools
    Overview
    All paths and Pioneer Program
    Curious Teachers
    Wanting to try AI, unsure how
    Scaling Schools
    Already using AI, want governance
    Inquiry-Led Schools
    Inquiry-based & international K-12
    For Corporate
    Overview
    AI competency and hiring for companies
    Cognity Recruit
    Authorship evidence for online screening
    AI Skill Assessment
    Measure how people collaborate with AI
    Workforce Upskilling
    Train teams to use AI safely and well
    OutcomesPricingSecurityAbout

    Cognity — Privacy Policy

    Effective Date: 2026-07-29 Last Updated: 2026-07-29


    1. Introduction

    CT Corp. ("Cognity," "we," "us," or "our") provides an AI-governance and transparency platform for education. This Privacy Policy explains what personal data we collect, how we use and share it, and the rights available to you. It applies to our websites, applications, and services (the "Service").

    We design the Service to make AI use in the classroom visible and accountable. That means we process data about how Students interact with AI. We describe that processing here.

    This Policy does not apply to third-party sites or services that link to or integrate with the Service; their own privacy notices govern.


    2. Our Role: Controller and Processor

    2.1 Institution-provisioned use. When a school, district, or other organization ("Institution") provisions the Service, the Institution is the controller (or, under FERPA, the party in control of education records) of Student personal data, and Cognity acts as a processor / service provider on the Institution's behalf. We process Student personal data only per the Institution's instructions, this Policy, and any Data Processing Agreement ("DPA"). The Institution is responsible for the lawful basis and required consents.

    2.2 Direct relationships. Where you interact with us directly (for example, an Educator signing up independently, website visitors, or account administrators), Cognity is the controller of that data as described in this Policy.


    3. Personal Data We Collect

    3.1 Account and profile data: name, email address, username, password (stored hashed), role (Educator/Student/admin), Institution affiliation, and, if provided, profile image and preferences. We minimize sensitive identifiers and do not require a mobile phone number.

    3.2 Institutional / roster data: class and section membership, grade level, and rostering identifiers provided by the Institution or via integrations (e.g., SSO, LMS, or rostering standards).

    3.3 Student work and AI-interaction data (core to the Service): - assignment content, drafts, revisions, and submissions; - prompts and messages exchanged with AI features (including Jello) and the AI Output returned; - Transparency Records — the record of how a Student worked with AI, including prompt history, revision timeline, and process metadata used to make AI use visible to Educators and to support process-based assessment; - rubric scores, feedback, and academic-integrity flags generated within the Service.

    3.4 Well-being Signal data (sensitive): indicators derived from Student interactions that may suggest distress or difficulty, surfaced to authorized Educators. Depending on jurisdiction, this may constitute a special category / sensitive personal data and is handled with additional safeguards (Section 8).

    3.5 Usage and technical data: IP address, device and browser information, access dates and times, pages and features used, and diagnostic logs.

    3.6 Cookies and similar technologies: as described in Section 13.

    3.7 Support and communications: information you provide when contacting us.

    3.8 Billing and payment data (paid plans): billing name and contact, plan and transaction records, and limited payment details. Payments are handled by Paddle (our Merchant of Record); we do not store full payment-card numbers.

    We collect this data when you use the Service, when an Institution or integration provides it, automatically through your use, and when you contact us.


    4. How We Use Personal Data (Purposes)

    We use personal data to:

    • provide the Service — create and manage accounts, generate assignments and rubrics, operate Jello, and produce Transparency Records and reports;
    • make AI use visible — record and display Student AI interactions to authorized Educators and the Institution to support academic integrity and process-based assessment;
    • operate the Well-being Signal — surface possible distress indicators to authorized Educators (Section 8);
    • secure the Service — authenticate users, prevent abuse and fraud, and maintain safety and integrity;
    • support and communicate — respond to inquiries and send service and administrative messages;
    • improve the Service — analyze aggregated or de-identified usage to develop features and improve quality, subject to Section 6;
    • comply with law — meet legal obligations and enforce our Terms.

    We do not sell personal data, do not serve third-party advertising in the Service, and do not use Student personal data for advertising or to build marketing or advertising profiles of Students.


    5. Legal Bases (GDPR / UK GDPR)

    Where GDPR or UK GDPR applies and Cognity is a controller, we rely on: performance of a contract; legitimate interests (e.g., securing and improving the Service, balanced against your rights); consent (where required, e.g., certain cookies or optional features); and legal obligation. Where Cognity is a processor for an Institution, the Institution establishes the legal basis. For special-category data (Section 8), an additional Article 9 condition (such as explicit consent or a substantial public-interest/safeguarding basis established by the Institution) is required.


    6. AI Processing and Model Training

    6.1 How AI processing works. To operate AI features, Content (including Student prompts and related material) is processed by our systems and by vetted AI/LLM sub-processors. We contractually restrict sub-processors from using your data for their own purposes.

    6.2 No sale; no advertising. We do not sell personal data and do not use Student personal data for third-party advertising.

    6.3 Model training. We do not use Student personal data to train third-party foundation models. We do not use Student personal data to train our own general-purpose AI models except where expressly authorized by the Institution and permitted by law, and we prefer aggregated or de-identified data for any product-improvement or model work. We contractually require AI sub-processors to exclude Institution/Student data from training their models.

    6.4 Automated processing. AI Output, flags, and Well-being Signals are decision-support only; they do not produce legal or similarly significant effects without human review. Educators make the final determinations affecting Students.


    7. Sharing and Disclosure

    We share personal data only as needed:

    • With the Institution and authorized Educators — Transparency Records, submissions, scores, and Well-being Signals are visible to authorized Educators and administrators of the relevant Institution, consistent with their configuration and role.
    • With Sub-processors — AI/LLM providers, cloud hosting, analytics, and support tools that process data on our behalf under contract. We publish a current, versioned sub-processor list at https://cognity.it/sub-processors that names the AI/LLM providers that process Student prompts and Content, with each provider's purpose and location; you may subscribe to change notifications there. AI sub-processors are contractually barred from using your data to train their models (Section 6).
    • With our payment provider (Merchant of Record) — for paid plans, Paddle acts as Merchant of Record and, as such, is an independent controller of billing and tax data for the transaction. Their handling of payment data is governed by their own privacy notices.
    • For legal reasons — to comply with law, valid legal process, or to protect rights, safety, and the security of users and the public.
    • Corporate transactions — in a merger, acquisition, or asset sale, subject to continued protection of personal data.

    We do not otherwise disclose personal data to third parties without the required consent or legal basis.


    8. Well-being Signal — Handling of Sensitive Data

    Because Well-being Signals may reveal information about a Student's mental or emotional state, we treat them as sensitive:

    • access is restricted to Educators/staff authorized by the Institution;
    • the Institution is responsible for establishing the legal basis (e.g., explicit consent or a safeguarding/substantial-public-interest basis) and for its safeguarding response;
    • the Signal is decision-support only and is not a diagnosis, medical service, or emergency/crisis-monitoring service; it may produce false positives and negatives and must not be relied upon to detect or prevent harm;
    • we apply additional access controls and shorter or configurable retention where feasible.

    9. Children's and Students' Privacy

    The Service is used by minors in educational settings. Students do not self-register: they access the Service through a teacher-provided class code or by connecting an existing school-managed account (for example, Google Classroom). Student participation is therefore mediated by the teacher/Institution, which provides the required authorization or consent. Requirements vary by jurisdiction:

    • United States — COPPA: For Students under 13, we rely on the Institution/Educator to provide, or to obtain from parents, the consent required by COPPA before Student personal information is collected, under COPPA's school-authorization framework. Institutions must make this Policy available to parents and retain consent records.
    • United States — FERPA and state laws: For education records, Cognity acts as a "school official" with a legitimate educational interest under the Institution's control, and complies with applicable state student-privacy laws (e.g., SOPIPA-type restrictions on advertising, selling data, and profiling).
    • EEA/UK — GDPR: The applicable age of digital consent ranges from 13 to 16 by country; where a child is below that age, consent/authorization is provided by the holder of parental responsibility or by the Institution as controller.
    • Other jurisdictions: We follow applicable local requirements for minors' data.

    If we learn that we collected a child's personal data without the required authorization, we will delete it promptly.


    10. International Data Transfers

    We may transfer and store personal data in countries other than yours, including where our infrastructure and sub-processors operate. Where required, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful mechanisms.

    Because Cognity is operated by a company established in the Republic of Korea, transfers of personal data outside Korea are disclosed in accordance with the Korean Personal Information Protection Act ("PIPA"). The table below identifies each overseas recipient, and the authoritative, versioned list — including the names of the AI/LLM providers that process student prompts and content — is maintained at https://cognity.it/sub-processors (see Section 7). The two are kept consistent.

    Overseas transfer of personal data (PIPA disclosure):

    Recipient Country Items transferred Recipient's purpose Transfer date & method Retention period
    Google LLC (Gemini API, paid tier) United States Prompts, submissions, AI output AI generation, tutoring, and evaluation (Jello, project/rubric/image generation) Continuously, via encrypted network transmission (API) upon use Until service purpose is fulfilled or account deletion; then deleted
    Amazon Web Services, Inc. United States (EU region available when selected) All service data Hosting, storage, security Continuously, via encrypted network transmission upon use Duration of the service contract
    Google Analytics (Google LLC) United States Usage & technical data Product analytics Continuously, via encrypted network transmission upon use Per Google Analytics retention settings
    Paddle.com Market Ltd (Merchant of Record) United Kingdom Billing name & contact, transaction data Sale of record, billing, tax collection/remittance Upon purchase, via encrypted network transmission As required by law/accounting

    Legal basis for transfer. Overseas transfer is necessary to perform the Service — sending prompts to the AI provider is intrinsic to how Cognity works. On this basis, and because the required disclosures are provided in this Policy and in the Terms you accept when you begin using the Service, we do not request separate consent for the overseas transfer, as permitted under PIPA's contract-necessity provision. This basis is not consent and therefore cannot be "withdrawn" while you use the Service; if you do not want your data transferred as described, the Service cannot be provided to you. For personal data from the EEA/UK, the transfer is additionally safeguarded by Standard Contractual Clauses (or another valid mechanism); the PIPA basis and the GDPR safeguard operate together, not as alternatives. A copy of the safeguards is available on request at cognity@ctcorp.ai.

    Regional data storage (enterprise option). Under a separate enterprise agreement, an Institution may request that its data be stored in servers located in a specified region (for example, the EU). Please note that regional storage does not by itself guarantee that all AI processing occurs in that region: certain AI/LLM providers process requests only in specific locations. Currently, AI generation is performed via the Google Gemini API, which processes requests in the United States, so prompts are transmitted to the United States even where other data is stored in another region. We will describe the available storage regions and the corresponding AI-processing locations in the enterprise agreement.


    11. Data Retention

    We retain personal data only as long as needed for the purposes described, for the duration of the Institution's or your relationship with us, and as required by law. Institutions may configure retention and request deletion or return of Student data. On account deletion or contract termination, we delete or de-identify personal data without undue delay, except for limited backups (deleted on a rolling basis) and data we must retain by law. Well-being Signal data is retained for the shortest practicable period.

    Deletion methods: electronic records are erased using non-recoverable methods; any paper records are shredded or incinerated.


    12. Security

    We implement administrative, technical, and physical safeguards appropriate to the risk, consistent with the security requirements of Korea's Personal Information Protection Act (PIPA) and Article 32 of the GDPR. These include:

    • an internal management plan and designated responsibility for personal-data protection;
    • access-rights management and access control — individual credentials, least-privilege access, and intrusion-prevention systems;
    • encryption of personal data in transit and at rest, including passwords and unique identifiers;
    • retention and periodic review of access (connection) logs;
    • anti-malware protection and timely patching;
    • physical security controls for systems that store personal data;
    • backups and disaster-recovery measures; and
    • confidentiality obligations and periodic security training for personnel.

    Enhanced access restrictions and shortened retention apply to sensitive data such as Well-being indicators. We periodically test and update these measures. No system is perfectly secure, and we are not responsible for losses caused by a user's failure to safeguard credentials or by circumstances beyond our reasonable control. We maintain an incident-response process and will notify affected parties and regulators of a personal-data breach where required by law.


    13. Cookies and Analytics

    We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. We use analytics tools (for example, Google Analytics); information generated may be processed on the provider's servers, potentially outside your country, under Section 10 safeguards. You can control non-essential cookies through your browser settings or our cookie controls where provided; disabling some cookies may limit functionality. For Student accounts, we minimize non-essential tracking and do not use cookies for third-party advertising.


    14. Your Rights

    Subject to applicable law, you may have rights to: access, correct, delete, or receive a portable copy of your personal data; restrict or object to processing; and withdraw consent. Where GDPR/UK GDPR applies, you also have the right to lodge a complaint with a supervisory authority. Where US state consumer-privacy laws apply, you may have rights to access, delete, correct, and opt out of "sale"/"sharing" and certain profiling (note: we do not sell Student data or use it for targeted advertising).

    How to exercise: Students and parents should ordinarily direct requests to their Institution, which controls Student data; we will assist the Institution. For data where Cognity is the controller, contact cognity@ctcorp.ai. We will verify your identity and respond without undue delay and within the statutory period (for example, within one month under the GDPR; access within 10 days under Korea's PIPA). These rights cover all personal data we hold about the individual — including AI prompts, drafts, transparency records, and, where applicable, well-being indicators — which we can retrieve, export, or delete on a per-user basis.


    15. Data Protection Contacts

    Privacy Officer (개인정보 보호책임자, required under PIPA): 유재상 (Jaesang Yoo), R&D Center / CTO Email: support@classting.com

    Company: CT Corp., 9F, 511 Seolleung-ro, Gangnam-gu, Seoul, Korea (US: 301 N. Market St., Ste 1410, Wilmington, DE 19801) General privacy inquiries: cognity@ctcorp.ai

    You may also contact your local data protection authority.


    16. Changes to This Policy

    We will post changes here and, for material changes affecting your rights, provide notice at least 14 days in advance (or as required by law) through the Service or by other reasonable means. The "Last Updated" date reflects the current version.


    Cognity

    Accountability in every step of learning

    Product

    • Product
    • For Schools
    • For Corporate
    • Outcomes
    • Security

    Company

    • About
    • Get started
    • cognity@ctcorp.ai
    • LinkedIn

    © 2026 Cognity. All rights reserved.

    Terms of ServicePrivacy Policy

    HQ: 9F, 511 Seolleung-ro, Gangnam-gu, Seoul, Korea

    US: 301 N. Market St. Ste 1410, Wilmington, DE 19801