Data & Training Policy
The Short Version
MHLE's current production policy is:
Customer and student content is used to provide requested services. It is not used to train MHLE's own general-purpose AI models and is not intentionally provided to third-party AI vendors for training their general-purpose models.
AI processing is necessary for AI-enabled features, but processing a request is different from using the request to train or improve a general-purpose model.
What "Processing" Means
When a user selects an AI feature, MHLE may send the content needed for that feature to a provider. For example:
- Note text may be sent for analysis or summarization.
- Document excerpts may be sent to generate study materials.
- Text fragments may be sent to create embeddings for semantic retrieval.
- Audio may be sent for transcription.
- Text may be sent to create speech audio.
- A factual claim or topic may be sent for verification.
The provider computes a result and returns it to MHLE. This is service processing performed on MHLE's behalf.
What "Training" Means
Training or fine-tuning changes a model using example data so that the model's future behavior is influenced by that data. Under this policy, MHLE does not use customer or student content to train a general-purpose model for MHLE or unrelated customers.
MHLE may use de-identified operational measurements—such as aggregate latency, error counts, feature adoption, or whether a user marked an answer helpful—to operate and evaluate the service. Such measurement must not be used to reconstruct user content or create an identifiable training dataset.
Third-Party AI Providers
MHLE uses provider business/API offerings and seeks terms or settings that restrict the use of API content for provider model training. Providers and applicable processing purposes are listed in the Subprocessor List.
Provider retention, security-review, and contractual status must be validated before this policy is marked Current. If a provider cannot meet MHLE's requirements for a data category, MHLE should disable that flow, limit the data sent, obtain appropriate authorization, or use another approved provider.
Student Data
Student data is processed only for authorized educational, security, support, legal, or contractual purposes. MHLE's policy prohibits:
- Training general-purpose AI models on identifiable student data.
- Selling student data.
- Using student data for targeted or behavioral advertising.
- Building advertising profiles from educational activity.
- Using institution-provided education records for an unrelated commercial purpose.
An institution may supply content for a specifically authorized educational analysis or model configuration. Any project that would constitute training or fine-tuning must be separately documented in the contract or DPA and reviewed for FERPA, COPPA, state student privacy, intellectual-property, consent, and security requirements before work begins.
Human Review and Evaluation Data
MHLE may maintain controlled evaluation sets to test accuracy, safety, and regressions. Evaluation material should be synthetic, public, licensed, or specifically authorized. Production customer content must not be copied into a reusable evaluation or training set unless Legal and Privacy approve the purpose and all required permissions are documented.
Feedback on an individual AI result may be used to investigate that result, provide support, or measure aggregate quality. Feedback does not authorize general-purpose model training.
Product Development Rules
Before introducing a new AI provider, model, fine-tuning process, or secondary data use, MHLE should document:
- The business and educational purpose.
- The data categories and users affected.
- Whether identifiable or student information is involved.
- The provider's retention, training, security, and subprocessor terms.
- The legal basis, customer instructions, and consent requirements.
- Data minimization, deletion, access, and incident-response controls.
- Evaluation, bias, safety, and human-oversight requirements.
- The user-facing notice or contract update required before launch.
Material changes must be reflected in the Privacy Policy, AI Transparency Statement, Subprocessor List, DPA, and product notices as applicable.
User and Customer Choices
Users may choose not to invoke optional AI functions, subject to the core functionality of their selected service. Institutions may contact MHLE to understand specific processing flows or request contractual configuration information.
The presence of an AI training preference in an account or administrative interface does
not override this policy or by itself authorize training. Any future opt-in program would
require a separate, clear description of the dataset, purpose, recipients, retention,
withdrawal process, and effect of consent.
Contact
- Privacy and training-use questions: contact details withheld pending approval
- Institutional processing questions: contact details withheld pending approval
- Contract terms: contact details withheld pending approval
Review Note
This document remains Draft pending validation of each provider's current API training and retention terms and formal approval by MHLE leadership and counsel.