Customer Assurance Draft public

Privacy FAQ

Version 0.9 Last updated August 24, 2026
Draft review copy. This document has not been approved for publication. Its claims, effective date, and contact details remain subject to owner review.

General Questions

What is MHLE?

Multi-Headed Learning Engine (MHLE) is an educational technology platform operated by Cognitive Engine, Inc. It provides note analysis, learning tools, collaboration features, institutional dashboards, and AI-assisted educational content.

Where is the complete Privacy Policy?

The controlling public notice is the MHLE Privacy Policy. The policy currently identifies itself as version 3.0 and describes the data collected, processing purposes, sharing, retention, user rights, children's privacy, and contact information.

What information does MHLE collect?

Depending on the features used, MHLE may process:

  • Account information such as name, email address, organization, role, and date of birth.
  • Student or user content such as notes, uploaded documents, images, audio, course information, portfolios, study-group content, and instructor observations.
  • AI-generated analyses, summaries, embeddings, assessments, and learning artifacts.
  • Usage and device information such as page activity, feature events, IP address, browser information, and authentication or security logs.
  • Subscription and billing identifiers. Payment-card details are handled by the payment provider rather than stored directly by MHLE.
  • Institutional records such as classrooms, enrollments, pacing guides, standards, outcomes, and authorized LMS or Google Classroom data.

The exact categories depend on the user's role, subscription, age, institutional configuration, and chosen features.

Why does MHLE use this information?

MHLE uses information to provide and secure the service, personalize educational support, perform requested AI functions, manage accounts and subscriptions, support instructors and organizations, facilitate permitted collaboration, respond to support and legal requests, measure reliability, and comply with applicable obligations.

Artificial Intelligence

Does MHLE send content to AI providers?

Yes. When a user requests an AI-enabled feature, MHLE may send the content needed for that feature to one or more providers listed in the Subprocessor List. Examples include note text for analysis, audio for transcription, text for speech synthesis, or document excerpts for generation and retrieval.

Is customer or student content used to train AI models?

MHLE's current production policy is no. MHLE does not use customer or student content to train its own general-purpose model and configures provider API use for business processing rather than provider model training. See the Data & Training Policy.

Can AI output be wrong?

Yes. AI output may be incomplete, biased, outdated, or inaccurate. It should be reviewed by the user or an appropriate educator. MHLE does not intend AI output to make admissions, grading, disciplinary, eligibility, or other high-stakes decisions without meaningful human review.

Schools, Students, and Parents

How does FERPA apply?

FERPA applies to covered educational agencies and institutions, not automatically to every technology vendor. A covered institution may disclose education records to a vendor under the school-official exception only when the legal conditions are met, including direct control over use and maintenance and limits on use and redisclosure. MHLE's DPA is designed to document the institution's instructions and MHLE's obligations.

Students and parents should normally direct FERPA record requests to their school or institution. They may also contact contact details withheld pending approval so MHLE can coordinate with the institution.

What happens when a user is under 13?

MHLE uses the supplied date of birth to determine whether its under-13 consent gate applies. An identified child account is restricted until the required parent, guardian, or authorized school consent process is completed. Parents may request access, correction, or deletion by following the instructions in the children's privacy disclosure or contacting contact details withheld pending approval.

Can schools consent under COPPA?

In some educational contexts, a school may authorize collection on a parent's behalf when the service is used for the benefit of the school and not for another commercial purpose. The institution must receive notice of the collection, use, and disclosure practices. The appropriate consent path depends on the deployment and agreement.

Does MHLE sell student information or use it for advertising?

MHLE's published policies prohibit selling student data and using it for targeted or behavioral advertising. Student content is used to provide contracted or user-requested educational functions, secure the service, and meet legal obligations.

Who can see a student's information?

Access depends on the deployment and permissions. It may include the student; authorized instructors, coaches, organization administrators, or parents; MHLE personnel with a business need; and subprocessors needed to provide the requested feature. Public or group sharing occurs only through applicable sharing features and settings.

Retention, Security, and Rights

How long is information retained?

Retention varies by record type, account status, institutional contract, legal requirement, and user action. The Privacy Policy and Student Data Transparency Notice describe the current schedules. Legal holds, security investigations, and statutory recordkeeping may require longer retention. Customers should review their DPA for contractual terms.

How does MHLE protect information?

MHLE uses layered safeguards that include access controls, password hashing, signed authentication tokens, rate limiting, encrypted transport, selected field-level encryption, security headers, validation and sanitization, monitoring, backups, restoration testing, and security-review processes. No service can guarantee absolute security.

How can I access, correct, export, or delete information?

Available paths depend on whether the account is individual or institution-managed:

  1. Use the privacy and account settings available in the application.
  2. For an institution-managed education record, contact the institution's privacy or FERPA official.
  3. Contact contact details withheld pending approval with the request and enough information to verify identity and locate the account.

MHLE may need to verify identity, preserve legally required records, or coordinate with the institution that controls the education record.

Does MHLE respond to security incidents?

MHLE maintains incident and breach-response procedures and contractual notification commitments. Applicable timing and recipients depend on the nature of the event, affected data, contract, and law. Suspected vulnerabilities should be reported to contact details withheld pending approval.

Contact

  • Privacy and individual rights: contact details withheld pending approval
  • Institutional compliance: contact details withheld pending approval
  • Security: contact details withheld pending approval
  • Contracts and DPA: contact details withheld pending approval

Review Note

This FAQ remains Draft pending confirmation of contact inboxes, retention descriptions, and final approval by MHLE leadership and counsel.

Back to Trust Center