Privacy Draft public

Privacy Policy

Version 3.0 Effective August 11, 2026 Last updated August 31, 2026
Draft review copy. This document has not been approved for publication. Its claims, effective date, and contact details remain subject to owner review.
## Controlling Privacy Notice

The complete controlling Privacy Policy is published at:

### [Read the MHLE Privacy Policy v3.0](/privacy)

The published policy identifies Cognitive Engine, Inc. as the operator of MHLE and was last
updated August 11, 2026. It should be reviewed in full before using the service.

This Trust Center record provides a concise index. If this record conflicts with the
published Privacy Policy, the published policy and applicable contract control.

## Topics Covered by the Published Policy

The Privacy Policy describes:

1. Information users provide, including account details and educational content.
2. Information collected automatically, including device, usage, security, and analytics
   information.
3. Processing by AI providers for analysis, embeddings, transcription, text-to-speech,
   generation, and verification features.
4. Purposes for processing information.
5. Retention and deletion practices.
6. Service providers and categories of disclosure.
7. Payments and subscription processing.
8. Study groups, social features, portfolios, playlists, and public sharing.
9. LTI, LMS, Google Classroom, and institutional data flows.
10. Automated engagement, health, friction, and AI-assisted educational features.
11. User rights under potentially applicable privacy laws.
12. Cookies and analytics.
13. Children's privacy, COPPA, FERPA, and state student privacy requirements.
14. Security, incident notification, policy changes, and contact details.

## Important AI Disclosure

AI-enabled features may send the content needed to perform a requested operation to an
approved AI provider. MHLE's current production policy is not to use customer or student
content to train general-purpose AI models. AI-generated material may contain errors and
should be reviewed before use.

See the [AI Transparency Statement](/trust/customer-assurance--ai-transparency-statement),
[Data & Training Policy](/trust/customer-assurance--data-training-policy), and
[Subprocessor List](/trust/subprocessors).

## Student and Child Privacy

When MHLE processes institution-managed education records, the institution determines the
authorized educational purpose and applicable FERPA basis. Accounts identified as belonging
to a child under 13 are subject to the applicable parental, guardian, or school authorization
controls.

Additional notices:

- [Student Data Transparency Notice](/docs/legal/student-data-transparency)
- [Children's Privacy Disclosure](/legal/coppa-disclosure)
- [Privacy FAQ](/trust/customer-assurance--privacy-faq)

## Rights and Requests

Depending on the relationship and applicable law, a user, parent, or customer may have rights
to access, correct, export, delete, restrict, object, or opt out of certain processing. MHLE
may verify identity and authority and may coordinate with an institution that controls an
education record.

Use available account/privacy settings or contact **contact details withheld pending approval**.

## Contacts

- Privacy and individual rights: **contact details withheld pending approval**
- Institutional compliance: **contact details withheld pending approval**
- Security: **contact details withheld pending approval**
- Contracts: **contact details withheld pending approval**

## Document Status Note

The canonical HTML policy is already published as version 3.0. This Markdown register copy
remains **Draft** until Legal confirms that its metadata, summary, contacts, and review date
match the approved controlling notice. It should then be promoted through the compliance
hub's audited status workflow.
Back to Trust Center