Privacy Policy
Version 3.1Last Updated: August 20, 2026
ⓘ This policy has been updated for launch. New disclosures include: all four AI providers, institutional/LTI data sharing, partner and referral attribution, public share links, study group visibility, parent portal access, and breach notification commitments. Please read Sections 3, 6, 10, 11, and 12 for details.
1. Introduction
Multi-Headed Learning Engine ("MHLE," "we," "us," or "our") is operated by Cognitive Engine, Inc. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Please read this Privacy Policy carefully. By using the Service, you consent to the collection and use of information in accordance with this policy. The privacy contact for all matters in this policy is privacy@mhle.app.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, password (hashed), and profile details
- Content: Notes, courses, uploaded documents (PDFs, images, audio), and other materials you submit
- Payment Information: Billing details processed through Stripe (we do not store full credit card numbers)
- Communications: Feedback, support requests, and correspondence with us
2.2 Information Collected Automatically
- Usage Data: Features used, actions taken, timestamps, and session information
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP address, access times, pages viewed, and referring URLs
- UTM and Referral Attribution: Only after you affirmatively allow optional browser analytics, we record UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) and referral codes with a browser visitor ID. You can withdraw that choice at any time; withdrawal deletes the browser identifier and its anonymous attribution history. We do not link pre-consent browsing to an account or share individual attribution records with partners — see §6.4 for details.
2.3 Information from Third Parties
- Authentication providers if you sign in through third-party services (e.g., Google OAuth)
- Payment status from Stripe
- LMS course context, user identity, and role information when you access MHLE via an LTI 1.3 launch from a connected Learning Management System (see §6.5)
- Google Classroom course and roster information when an instructor connects their Classroom account (see §6.6)
3. Third-Party AI Processing
IMPORTANT DISCLOSURE: To provide our AI-powered features, we transmit your content to third-party AI service providers. The providers we currently use, and what each is used for, are:
| Provider | What we use it for | Their Privacy Policy |
|---|---|---|
| OpenAI, L.L.C. | Multi-perspective note analysis, wicked-problem simulations, general text generation | openai.com/privacy |
| Anthropic, PBC | Learning artifact generation (study plans, concept summaries, synthesis documents) | anthropic.com/legal/privacy |
| Google LLC (Gemini) | Multimedia analysis, audio transcription, image processing, epistemology tagging | policies.google.com/privacy |
| Perplexity AI, Inc. | Internet-grounded fact verification (Weekly Pulse feature) | perplexity.ai privacy |
When your content is processed by any of these providers:
- It is transmitted securely via encrypted connections
- Your content is not used to train our models or provider models through our production API use, subject to the providers' applicable API and retention terms
- For administrative retention and email-copy workflows, we send only minimized aggregate account activity; direct identifiers, note titles, course titles, and learning content are excluded from those prompts
- Third-party providers may retain data temporarily for processing and abuse prevention per their own policies
4. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the Service
- Process your content through AI analysis features
- Manage your account and subscription
- Send transactional emails (account verification, password reset, billing)
- Respond to support requests and communications
- Monitor and analyze usage patterns to improve features
- Detect, prevent, and address technical issues and abuse
- Measure marketing effectiveness and calculate partner/ambassador commissions using UTM and referral attribution data
- Comply with legal obligations
5. Data Retention
Account Data: Retained while your account is active and for 18 months after your subscription ends or account becomes inactive, for backup, legal compliance, and potential dispute resolution purposes.
Content: Your notes, courses, and uploaded materials are retained until you delete them or close your account. After account closure, content is retained for the 18-month retention period, after which you may request export within 30 days of account termination.
AI Processing: Content sent to AI providers is processed in real-time and not permanently stored by us after processing is complete.
Usage Logs: Retained for up to 12 months for analytics and security purposes.
Legal Holds: In the event of pending litigation, legal disputes, or regulatory investigations, we may retain your data beyond the standard retention period until the matter is resolved, as required by law.
6. Data Sharing and Disclosure
We may share your information as described below. We do NOT sell your personal information to third parties.
6.1 Third-Party Processors
We share data with the following categories of service providers to operate the Service:
| Provider / Category | Function | What they receive |
|---|---|---|
| AI Providers (OpenAI, Anthropic, Google, Perplexity) | Content analysis and generation (see §3) | Note content, uploaded documents; no payment or billing data |
| Stripe, Inc. | Payment processing and subscription management | Billing information; no note content or AI outputs. Stripe Privacy |
| Replit / Cloud Infrastructure | Application hosting, database hosting, compute (US-East region) | All application data stored in our database and file storage |
| Mailjet (Sinch) | Transactional email delivery (account verification, password reset, billing, consent emails) | Recipient email address and email content. Mailjet Privacy |
6.2 Legal Requirements and Business Transfers
- Legal Requirements: When required by law, court order, or governmental authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity subject to the same privacy protections
6.3 Study Groups and Social Features
If you participate in a study group or social learning feature within MHLE:
- Other members of your group can see content you post or share within that group (notes, comments, and shared artifacts)
- Group chat messages are stored in our database and are accessible to all current group members
- Instructors or administrators designated as group admins can view group content and member activity within the group
- Your display name and profile are visible to other group members; your email address is not shared
- Leaving a group does not automatically delete messages or content you previously posted
6.4 Partner and Referral Attribution
MHLE operates a partner and ambassador referral program. When you sign up via a referral or partner link:
- We record the UTM parameters and referral code from your signup link and store them in your account record
- This attribution is used to calculate commissions or credit owed to the referring partner or ambassador under their Ambassador Agreement
- We share only aggregate or anonymized conversion data with partners — for example, "your referral link generated 12 new signups this month." We do not share your name, email address, or any individual personal data with partners
- Partners receive no information about your learning activity, content, or subscription details beyond the existence of a conversion event
6.5 LTI and LMS Data Sharing
MHLE supports LTI 1.3 integration with Learning Management Systems (LMS) such as Canvas, Blackboard, Moodle, and others. When your institution connects an LMS to MHLE:
- Data received from the LMS at launch: your name, email address, LMS user ID, course context (course name and ID), and your role in the course (student or instructor)
- Grade passback: If an instructor configures grade passback, MHLE will transmit grade or completion data for specific assignments back to the LMS on the instructor's behalf
- Data controller relationship: Your institution is the data controller for education records exchanged via LTI. MHLE acts as a processor on the institution's instructions. The institution's own privacy policies and FERPA obligations govern the LMS-side data
- Connecting an LMS is an administrator or instructor action; students cannot initiate or modify LTI connections
- For institutional customers, the Data Processing Agreement at /docs/legal/dpa governs this data exchange
6.6 Google Classroom Integration
Instructors may connect MHLE to Google Classroom. When connected:
- MHLE reads course names, enrolled student email addresses, and assignment information from Google Classroom via the Google Classroom API, solely to provision classrooms and enrollments in MHLE
- MHLE may write back assignment completion or grade data to Google Classroom if an instructor enables this feature
- This integration is subject to Google's privacy policy and your institution's Google Workspace terms
- Instructors may disconnect the integration at any time from the MHLE integration settings panel
6.7 Public Share Links and Portfolios
MHLE allows you to publish content via a public share link. When you activate a share link:
- The linked content (notes, artifacts, or portfolio entries) becomes accessible to anyone who has the link, without requiring authentication
- Shared pages are marked
noindexso they are not indexed by search engines, but they are technically public — anyone with the link can view the content - You control which content is shared and can revoke a share link at any time from your settings; after revocation, the link immediately becomes inaccessible
- You are responsible for ensuring that content you share via a public link does not violate FERPA, copyright, or any other legal obligation
- MHLE does not display your email address or account details on public share pages
6.8 Parent Portal Access
A verified parent or guardian of a minor student may access the MHLE Parent Portal. Through the portal, a verified parent can see:
- Their child's account profile (display name, enrollment status)
- Summary engagement data (recent activity, learning health score, streak information)
- Enrollment in classrooms and study groups
- Parental consent records associated with the account
Parent portal access is scoped strictly to the child's own account. Parents cannot view other students' data. Access is granted only after the parental consent workflow is completed and the parent's identity is verified. Parents can contact privacy@mhle.app to request FERPA-compliant access to the full education record for their child.
7. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption of data in transit (TLS 1.2+)
- Encryption of data at rest (AES-256)
- Secure password hashing (bcrypt)
- Role-based access controls and authentication
- Regular security assessments and automated vulnerability scanning
- Annual third-party penetration testing
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Breach Notification: In the event of a confirmed data breach that poses a material risk to your rights, we will notify affected users within 72 hours of confirming the breach for high-severity incidents. For institutional customers, breach notification obligations are further specified in the Data Processing Agreement.
8. Your Rights and Choices
Depending on your location, you may have the following rights:
All Users:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and associated data
- Export: Download your content in a portable format (within 30 days of account termination)
GDPR Rights (EU/EEA Users):
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
CCPA Rights (California Users):
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale of personal information (we do not sell data)
- Right to non-discrimination for exercising privacy rights
To exercise these rights, contact us at privacy@mhle.app
9. Cookies and Tracking Technologies
We use the following cookies and tracking technologies when you use the Service:
-
Session Cookie (
session): A temporary cookie that keeps you logged in while your browser is open. It is deleted when you close your browser. -
Authentication Token (
auth_token): A JSON Web Token (JWT) stored as a cookie that identifies your account on return visits. It expires after 24 hours and is required to access protected pages. -
Visitor Tracking Cookie (
visitor_id): An optional unique ID set only after you affirmatively allow browser analytics. We use it to understand how visitors find and navigate our site. If you later withdraw consent, we remove the identifier and erase its anonymous attribution history; pre-consent browsing is never linked to your account.
No third-party advertising cookies: We do not use any cookies from ad networks, social media trackers, or cross-site tracking services.
10. Automated Profiling and Behavioral Monitoring
Added in Version 2.0 — July 26, 2026
MHLE uses automated systems to analyze your learning activity while you use the Service. This section explains each system in plain language so you understand what is collected and why.
10.1 Learning Health Score
Our system automatically calculates a "Learning Health Score" (0–100) for each enrolled student every day. The score is based on four things we count automatically: how many notes you have written (up to 20 points), how many times you have used AI analysis features (up to 30 points), how recently you were active (up to 25 points), and the results of your gap analysis (up to 25 points). The score is grouped into three color bands — Emerald (80–100), Amber (50–79), and Rose (0–49).
This score is visible to your enrolled instructors and organization administrators so they can identify students who may need support.
What this means for you: Your instructors can see a daily number summarizing how engaged you are — they use it to decide who to check in with, not to grade you.
10.2 Friction Detection
MHLE automatically watches for three patterns in your usage that suggest you may be stuck or confused: (1) loading the same page three or more times in four hours without taking any action, (2) creating a note but not running an AI analysis within 60 minutes, and (3) bouncing off a feature page in under 30 seconds three or more times in a week. When a pattern is detected, an internal "friction alert" is created and shown to administrators so they can offer help.
What this means for you: If you appear stuck, the system flags it for your support team — the goal is to get you help faster, not to penalize you.
10.3 AI Analysis of Instructor Observations
When an instructor writes an observation about you (for example, in an org classroom), that text may be sent to a third-party AI provider (OpenAI, Anthropic, or Google Gemini) to generate a structured summary, suggested next steps, or impact scores. The analysis is used to help instructors track student progress more consistently. The same third-party AI protections from Section 3 apply: your data is not used to train AI models.
What this means for you: Notes your instructor writes about you may be automatically summarized by AI to help them support you more effectively.
10.4 Cross-Session Visitor Tracking
As described in Section 9, we set a visitor_id cookie before you create an account. This ID is stored in our database and linked to your page views, the marketing content you read, and the traffic source that brought you to the site (for example, a Google search or a referral link). When you sign up, we connect your pre-signup browsing history to your new account. We use this data to measure how well our marketing is working and to improve our onboarding experience.
What this means for you: We remember what you looked at before you created an account, and we tie that history to your account when you sign up.
10.5 Middle School Brain State Collection
For students using the Middle School (ms_early / ms_late) persona, our learning engine may collect self-reported emotional and focus states — such as how energized or distracted a student feels before a learning session. This data is used only to personalize the learning experience for that student in real time and to surface aggregate trends to educators (no individual student is identified in aggregate reports). Middle school accounts require parental or guardian consent before this data is collected (see Section 2 and the parental consent process at registration).
What this means for you: Middle school students may be asked how they feel before a session, and that answer influences what content they see — parents or guardians must approve this before it starts.
11. Automated Decision-Making
Added in Version 2.0 — July 26, 2026
Some of MHLE's features use automated analysis to surface recommendations, alerts, or scores (as described in Section 10). It is important to understand the limits of this automation:
- Automated systems assist instructors — they do not replace human judgment. No automated score or alert by itself determines a grade, an enrollment decision, or any other consequential outcome. All such decisions are made by human instructors or administrators who review automated data alongside other information.
- You can ask about automated data. If you believe an automated score or flag about you is incorrect, you may contact us at privacy@mhle.app to request a review.
- Scores are advisory. The Learning Health Score and friction alerts are tools to prompt a conversation — they are not permanent records of your academic performance.
12. Children's Privacy, FERPA, and State Education Laws
COPPA (Children Under 13)
MHLE supports accounts for users under 13 in compliance with the Children's Online Privacy Protection Act (COPPA). Before a child's account becomes active, a parent or legal guardian must provide verifiable parental consent by clicking a time-limited link sent to the parent email address supplied at registration. The child's account remains in a pending state — and cannot create notes, upload files, or use AI features — until that consent is verified.
What we collect from children
- Display name and date of birth (used only to determine COPPA applicability)
- Study notes, uploaded documents, and audio recordings
- Emotional energy / brain state
(
ms_last_brain_state) — a self-reported label (e.g., "focused", "tired") selected before each study session. Used only to adjust AI pacing and tone; never used for marketing. - Learning interests
(
ms_interests) — subject tags chosen during onboarding. Used only to suggest relevant study content; never shared with advertisers. - Usage events (features used) for service improvement
- IP address at registration and standard server logs
We do not sell, share, or use children's data for advertising or commercial profiling. Emotional-state and interest data is stored in isolated database columns and is never included in any third-party analytics export.
Parent and guardian rights
- Review: Request a copy of all personal information collected about your child — email privacy@mhle.app with subject "COPPA Review Request".
- Delete: Request deletion of your child's account and all associated data — email the same address with subject "COPPA Deletion Request".
- Refuse or withdraw consent: You may withdraw consent at any time by contacting us; this will deactivate the child's account.
For the complete COPPA disclosure, visit /legal/coppa-disclosure. The registered operator of MHLE for COPPA purposes is Cognitive Engine, Inc.
FERPA (Educational Institutions)
When MHLE is contracted by a school or district, MHLE acts as a "school official" with a legitimate educational interest under FERPA (20 U.S.C. § 1232g). In this context:
- The institution is the data controller for student education records; MHLE processes those records only on the institution's behalf and instructions
- MHLE does not re-disclose education records except as permitted by FERPA
- Students and parents may exercise FERPA rights through their institution's FERPA officer or by contacting privacy@mhle.app
See also the Student Data Transparency Notice for a full plain-language description of student data handling.
Georgia SDPAT and Other State Education Privacy Laws
MHLE complies with the Georgia Student Data Privacy, Accessibility, and Transparency Act (O.C.G.A. § 20-2-666 et seq.) for institutions operating under Georgia state law. MHLE also monitors and works to comply with applicable student privacy laws in other states where we operate. For Georgia-specific disclosures, see the Student Data Transparency Notice at /docs/legal/student-data-transparency.
13. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. All data at rest is stored in US-East region infrastructure. For transfers from the EEA or UK, we rely on Standard Contractual Clauses (SCCs) as described in our Data Processing Agreement. By using the Service, you consent to the transfer of your information to these countries.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service. For paid or institutional accounts, we will provide at least 30 days' advance notice of material changes by email. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact us at:
- Privacy: privacy@mhle.app
- Support: support@mhle.app
- Compliance / Institutional inquiries: compliance@mhle.app
- Legal: legal@mhle.app