COGNIS11+
For TutorsSign In
Return Home
PRIVACY_v1.3

Privacy Policy

Effective Date: August 2026 | Compliant with UK GDPR, UK ICO Children's Code & COPPA


1. Structural Privacy & Zero-Audio Retention

We operate under a strict Data Minimization framework engineered specifically for child users. Student spoken responses captured via browser hardware are processed in real-time solely to derive textual transcripts and evaluate mathematical reasoning models.

Raw audio files are never permanently stored, logged, or saved on disk. Audio streams pass through encrypted, transient memory buffers during transcription and are immediately discarded.

2. Verifiable Parental Consent (VPC) Architecture

In accordance with COPPA (§ 312.5) and the UK ICO Age Appropriate Design Code, cognis11.com enforces formal parental consent prior to initiating spoken 11+ diagnostic sessions:

  • Tier 1 (Paid Diagnostic Assessments): Verifiable Parental Consent is established via Stripe monetary payment card authorization. Credit card verification satisfies statutory requirements for verified adult consent.
  • Tier 2 (Free Diagnostic Assessments): Consent is established via the Email-Plus mechanism. Upon launching a session, an immediate direct notice is dispatched to the registered parent email via Resend outlining account creation, processing rules, and providing a direct one-click link to revoke consent and erase all student records.

3. Information We Retain

To construct student diagnostic reports, calculate reasoning velocity, and display progress over time, we store the following data elements in our encrypted database:

  • The registered parent/guardian authentication email address.
  • An optional student first name or parent-designated nickname.
  • Question step completion timing, selected multiple-choice answers, and problem scores.
  • Text transcripts of verbalized reasoning fragments alongside mapped cognitive error metrics (codes W1 through W9).
  • Immutable audit logs of parental consent timestamps and method type for regulatory verification.

4. Subprocessors & Enterprise Non-Training Guarantees

Data elements are routed exclusively to enterprise infrastructure providers bound by formal Data Processing Addendums (DPAs). We strictly prohibit all third-party providers from using student transcripts, voice data, or diagnostic inputs to train AI models.

SubprocessorFunctionData Privacy Guarantee
SupabaseEncrypted PostgreSQL Database & AuthAES-256 encryption at rest; SOC2 Type II certified.
NetlifyApplication Hosting & Edge DeliveryISO 27001 / GDPR compliant hosting enclaves.
Groq & AnthropicSTT Transcription & Reasoning AnalysisEnterprise Zero-Data Retention API terms; No AI Model Training.
StripePayment Processing & Parental VerificationPCI-DSS Level 1 compliant financial processor.
ResendParent Notice & Transactional EmailGDPR-compliant, encrypted email dispatch.

5. Cookies, Local Storage & Referral Attribution

cognis11.com uses strictly necessary operational cookies and browser local storage essential for user authentication (Supabase session tokens) and payment processing security (Stripe anti-fraud tokens).

When a visitor accesses cognis11.com via a partner referral link or enters a promo code, a small text identifier (cognis11_affiliate_code) is temporarily saved in browser local storage (localStorage). In compliance with UK PECR guidelines, this data is used exclusively for sales attribution and applying custom partner discount rates at checkout.

We do not run third-party advertising cookies, cross-site behavioral tracking scripts, or profiling pixels on our platform.

6. Right to Instant Data Erasure (GDPR Art. 17)

Parents retain continuous, complete data sovereignty under UK GDPR Article 17 (Right to Erasure) and COPPA:

  • Self-Serve Account Deletion: You can permanently wipe all student records, diagnostic transcripts, error scores, and profile attributes at any time directly via your Account Settings dashboard.
  • Manual Requests: Alternatively, you can email support@cognis11.com to request full manual data expulsion. Requests are executed within 48 business hours.

7. Data Controller Contact

If you have questions regarding our parental consent mechanisms, UK ICO compliance, or wish to exercise your statutory privacy rights, please reach out directly to our privacy desk:

Privacy & Compliance Office — cognis11.com
Email: support@cognis11.com