Privacy
Draft
public
Privacy Policy
Version 3.0
Effective August 11, 2026
Last updated August 31, 2026
Draft review copy.
This document has not been approved for publication. Its claims, effective date, and contact details remain subject to owner review.
## Controlling Privacy Notice The complete controlling Privacy Policy is published at: ### [Read the MHLE Privacy Policy v3.0](/privacy) The published policy identifies Cognitive Engine, Inc. as the operator of MHLE and was last updated August 11, 2026. It should be reviewed in full before using the service. This Trust Center record provides a concise index. If this record conflicts with the published Privacy Policy, the published policy and applicable contract control. ## Topics Covered by the Published Policy The Privacy Policy describes: 1. Information users provide, including account details and educational content. 2. Information collected automatically, including device, usage, security, and analytics information. 3. Processing by AI providers for analysis, embeddings, transcription, text-to-speech, generation, and verification features. 4. Purposes for processing information. 5. Retention and deletion practices. 6. Service providers and categories of disclosure. 7. Payments and subscription processing. 8. Study groups, social features, portfolios, playlists, and public sharing. 9. LTI, LMS, Google Classroom, and institutional data flows. 10. Automated engagement, health, friction, and AI-assisted educational features. 11. User rights under potentially applicable privacy laws. 12. Cookies and analytics. 13. Children's privacy, COPPA, FERPA, and state student privacy requirements. 14. Security, incident notification, policy changes, and contact details. ## Important AI Disclosure AI-enabled features may send the content needed to perform a requested operation to an approved AI provider. MHLE's current production policy is not to use customer or student content to train general-purpose AI models. AI-generated material may contain errors and should be reviewed before use. See the [AI Transparency Statement](/trust/customer-assurance--ai-transparency-statement), [Data & Training Policy](/trust/customer-assurance--data-training-policy), and [Subprocessor List](/trust/subprocessors). ## Student and Child Privacy When MHLE processes institution-managed education records, the institution determines the authorized educational purpose and applicable FERPA basis. Accounts identified as belonging to a child under 13 are subject to the applicable parental, guardian, or school authorization controls. Additional notices: - [Student Data Transparency Notice](/docs/legal/student-data-transparency) - [Children's Privacy Disclosure](/legal/coppa-disclosure) - [Privacy FAQ](/trust/customer-assurance--privacy-faq) ## Rights and Requests Depending on the relationship and applicable law, a user, parent, or customer may have rights to access, correct, export, delete, restrict, object, or opt out of certain processing. MHLE may verify identity and authority and may coordinate with an institution that controls an education record. Use available account/privacy settings or contact **contact details withheld pending approval**. ## Contacts - Privacy and individual rights: **contact details withheld pending approval** - Institutional compliance: **contact details withheld pending approval** - Security: **contact details withheld pending approval** - Contracts: **contact details withheld pending approval** ## Document Status Note The canonical HTML policy is already published as version 3.0. This Markdown register copy remains **Draft** until Legal confirms that its metadata, summary, contacts, and review date match the approved controlling notice. It should then be promoted through the compliance hub's audited status workflow.