Privacy Policy
Effective Date: August 2026 | Compliant with UK GDPR, UK ICO Children's Code & COPPA
1. Structural Privacy & Zero-Audio Retention
We operate under a strict Data Minimization framework engineered specifically for child users. Student spoken responses captured via browser hardware are processed in real-time solely to derive textual transcripts and evaluate mathematical reasoning models.
Raw audio files are never permanently stored, logged, or saved on disk. Audio streams pass through encrypted, transient memory buffers during transcription and are immediately discarded.
2. Verifiable Parental Consent (VPC) Architecture
In accordance with COPPA (§ 312.5) and the UK ICO Age Appropriate Design Code, cognis11.com enforces formal parental consent prior to initiating spoken 11+ diagnostic sessions:
- Tier 1 (Paid Diagnostic Assessments): Verifiable Parental Consent is established via Stripe monetary payment card authorization. Credit card verification satisfies statutory requirements for verified adult consent.
- Tier 2 (Free Diagnostic Assessments): Consent is established via the Email-Plus mechanism. Upon launching a session, an immediate direct notice is dispatched to the registered parent email via Resend outlining account creation, processing rules, and providing a direct one-click link to revoke consent and erase all student records.
3. Information We Retain
To construct student diagnostic reports, calculate reasoning velocity, and display progress over time, we store the following data elements in our encrypted database:
- The registered parent/guardian authentication email address.
- An optional student first name or parent-designated nickname.
- Question step completion timing, selected multiple-choice answers, and problem scores.
- Text transcripts of verbalized reasoning fragments alongside mapped cognitive error metrics (codes W1 through W9).
- Immutable audit logs of parental consent timestamps and method type for regulatory verification.
4. Subprocessors & Enterprise Non-Training Guarantees
Data elements are routed exclusively to enterprise infrastructure providers bound by formal Data Processing Addendums (DPAs). We strictly prohibit all third-party providers from using student transcripts, voice data, or diagnostic inputs to train AI models.
| Subprocessor | Function | Data Privacy Guarantee |
|---|---|---|
| Supabase | Encrypted PostgreSQL Database & Auth | AES-256 encryption at rest; SOC2 Type II certified. |
| Netlify | Application Hosting & Edge Delivery | ISO 27001 / GDPR compliant hosting enclaves. |
| Groq & Anthropic | STT Transcription & Reasoning Analysis | Enterprise Zero-Data Retention API terms; No AI Model Training. |
| Stripe | Payment Processing & Parental Verification | PCI-DSS Level 1 compliant financial processor. |
| Resend | Parent Notice & Transactional Email | GDPR-compliant, encrypted email dispatch. |
5. Cookies, Local Storage & Referral Attribution
cognis11.com uses strictly necessary operational cookies and browser local storage essential for user authentication (Supabase session tokens) and payment processing security (Stripe anti-fraud tokens).
When a visitor accesses cognis11.com via a partner referral link or enters a promo code, a small text identifier (cognis11_affiliate_code) is temporarily saved in browser local storage (localStorage). In compliance with UK PECR guidelines, this data is used exclusively for sales attribution and applying custom partner discount rates at checkout.
We do not run third-party advertising cookies, cross-site behavioral tracking scripts, or profiling pixels on our platform.
6. Right to Instant Data Erasure (GDPR Art. 17)
Parents retain continuous, complete data sovereignty under UK GDPR Article 17 (Right to Erasure) and COPPA:
- Self-Serve Account Deletion: You can permanently wipe all student records, diagnostic transcripts, error scores, and profile attributes at any time directly via your Account Settings dashboard.
- Manual Requests: Alternatively, you can email support@cognis11.com to request full manual data expulsion. Requests are executed within 48 business hours.
7. Data Controller Contact
If you have questions regarding our parental consent mechanisms, UK ICO compliance, or wish to exercise your statutory privacy rights, please reach out directly to our privacy desk:
Privacy & Compliance Office — cognis11.com
Email: support@cognis11.com