Cognity
    What Cognity is
    Product
    What gets recorded, and what a teacher reads
    AI Visibility
    The alternative to AI detection
    Outcomes
    What changes once the process is visible
    For Schools
    Overview
    All paths and Pioneer Program
    Curious Teachers
    Wanting to try AI, unsure how
    Scaling Schools
    Already using AI, want governance
    Inquiry-Led Schools
    Inquiry-based & international K-12
    For Universities
    Higher Education
    Keeping the standard when students use AI anyway
    PricingResourcesSecurityAbout
    English日本語한국어

    Cognity — Privacy Policy

    Effective Date: 2026-09-15 Last Updated: 2026-10-08


    1. Introduction

    CT Corp. ("Cognity," "we," "us," or "our") provides an AI-governance and transparency platform for education. This Privacy Policy explains what personal data we collect, how we use and share it, and the rights available to you. It applies to our websites, applications, and services (the "Service").

    We design the Service to make AI use in the classroom visible and accountable. That means we process data about how Students interact with AI. We describe that processing here.

    This Policy does not apply to third-party sites or services that link to or integrate with the Service; their own privacy notices govern.

    What the Service is for. Cognity is a tool for coursework. It is not designed for research data, material requiring ethics-board or IRB approval, clinical or counselling records, or anything else that is not a course assignment. Student prompts are transmitted to an AI provider in another country as described in Section 10, so putting such material into the Service may take it outside what your Institution has approved. Please check this before using the Service in a university setting.


    2. Our Role: Controller and Processor

    2.1 Institution-provisioned use. When a school, district, or other organization ("Institution") provisions the Service, the Institution is the controller (or, under FERPA, the party in control of education records) of Student personal data, and Cognity acts as a processor / service provider on the Institution's behalf. We process Student personal data only per the Institution's instructions, this Policy, and any Data Processing Agreement ("DPA"). The Institution is responsible for the lawful basis and required consents.

    Where the Student is an adult (universities and colleges). An adult Student is their own data subject, and there are things the Institution cannot do on their behalf. In particular, the separate consent required for sensitive data (Sections 5 and 8) and the exercise of access, correction, deletion and objection rights (Section 15) run to the Student themselves. To that extent Cognity stands toward the Student as described in Section 2.2. Processing needed to run the course continues on the Institution's instructions.

    2.2 Direct relationships. Where you interact with us directly (for example, an Educator signing up independently, website visitors, or account administrators), Cognity is the controller of that data as described in this Policy.


    3. Personal Data We Collect

    3.1 Account and profile data.

    Educators and administrators create accounts. For them we collect name, email address, password (stored hashed) or, when they sign in with Google or institutional single sign-on, the identifiers that service provides; role; Institution affiliation; and, if set, preferences.

    Students do not create accounts. A Student joins a class in one of two ways: (a) by opening a join link from their Educator and entering a six-digit PIN and their name, with no account and no password; or (b) by signing in with the Google account their school uses for Google Classroom. For a PIN join we collect only the name the Student enters. For a Google Classroom join we receive the Student's name, school email address and class membership from Google.

    We do not require a mobile phone number from anyone.

    3.2 Institutional / roster data: class and section membership, grade level, and rostering identifiers provided by the Institution or via integrations (e.g., SSO, LMS, or rostering standards).

    3.3 Student work and AI-interaction data (core to the Service): - assignment content, drafts, revisions, and submissions; - prompts and messages exchanged with AI features (including Jello) and the AI Output returned; - Transparency Records — the record of how a Student worked with AI, including prompt history, revision timeline, and process metadata used to make AI use visible to Educators and to support process-based assessment; - rubric scores, feedback, and academic-integrity flags generated within the Service.

    3.4 Well-being Signal data (sensitive): indicators derived from Student interactions that may suggest distress or difficulty, surfaced to authorized Educators. Depending on jurisdiction, this may constitute a special category / sensitive personal data and is handled with additional safeguards (Section 8).

    3.5 Usage and technical data: IP address, device and browser information, access dates and times, pages and features used, and diagnostic logs. We do not collect precise geolocation. An IP address may indicate an approximate location, and we use it only for security and to operate the Service.

    3.6 Cookies and similar technologies: as described in Section 13.

    3.7 Support and communications: information you provide when contacting us.

    3.8 Billing and payment data (paid plans): billing name and contact, plan and transaction records, and limited payment details. Payments are handled by Paddle (our Merchant of Record); we do not store full payment-card numbers.

    We collect only the personal data needed to provide, secure and improve the Service.

    We collect this data when you use the Service, when an Institution or integration provides it, automatically through your use, and when you contact us.


    4. How We Use Personal Data (Purposes)

    We use personal data to:

    • provide the Service — create and manage accounts, generate assignments and rubrics, operate Jello, and produce Transparency Records and reports;
    • make AI use visible — record and display Student AI interactions to authorized Educators and the Institution to support academic integrity and process-based assessment;
    • operate the Well-being Signal — surface possible distress indicators to authorized Educators (Section 8);
    • secure the Service — authenticate users, prevent abuse and fraud, and maintain safety and integrity;
    • support and communicate — respond to inquiries and send service and administrative messages;
    • improve the Service — analyze aggregated or de-identified usage to develop features and improve quality, subject to Section 6;
    • comply with law — meet legal obligations and enforce our Terms.

    No sale, no advertising, for any user. These commitments apply to every user of the Service — Students, Educators, administrators and website visitors:

    • We do not sell or rent personal information.
    • We do not share personal information with third parties for their advertising or marketing purposes.
    • We do not display advertising in the Service, contextual or behavioral.
    • We do not allow third-party companies to use cookies or other tracking technologies on the Service for commercial purposes, including advertising, marketing, or building profiles of users. The analytics tools named in Section 13 act for us only to improve the Service and may not use the data for their own purposes.
    • We do not use personal information to track users across other websites or services or to target advertising to them there.
    • We do not create advertising or marketing profiles of any user, and we do not allow third parties to do so.

    5. Legal Bases (GDPR / UK GDPR)

    Where GDPR or UK GDPR applies and Cognity is a controller, we rely on: performance of a contract; legitimate interests (e.g., securing and improving the Service, balanced against your rights); consent (where required, e.g., certain cookies or optional features); and legal obligation. Where Cognity is a processor for an Institution, the Institution establishes the legal basis. For special-category data (Section 8), an additional Article 9 condition (such as explicit consent or a substantial public-interest/safeguarding basis established by the Institution) is required. Where the Student is an adult, that condition — explicit consent, in practice — must be obtained from the Student; an Institution cannot give it on an adult's behalf.


    6. AI Processing and Model Training

    6.1 How AI processing works. To operate AI features, Content (including Student prompts and related material) is processed by our systems and by vetted AI/LLM sub-processors. We contractually restrict sub-processors from using your data for their own purposes.

    6.2 No sale; no advertising. We do not sell personal data and do not use the personal data of any user for third-party advertising (see Section 4).

    6.3 Model training. We do not use Student personal data to train third-party foundation models. We do not use Student personal data to train our own general-purpose AI models except where expressly authorized by the Institution and permitted by law, and we prefer aggregated or de-identified data for any product-improvement or model work. We contractually require AI sub-processors to exclude Institution/Student data from training their models.

    6.4 Automated processing. AI Output, flags, and Well-being Signals are decision-support only; they do not produce legal or similarly significant effects without human review. Educators make the final determinations affecting Students.


    7. Sharing and Disclosure

    We share personal data only as needed:

    • With the Institution and authorized Educators — Transparency Records, submissions, scores, and Well-being Signals are visible to authorized Educators and administrators of the relevant Institution, consistent with their configuration and role.
    • With Sub-processors — AI/LLM providers, cloud hosting, analytics, and support tools that process data on our behalf under contract. We publish a current, versioned sub-processor list at https://www.cognity.cc/sub-processors that names the AI/LLM providers that process Student prompts and Content, with each provider's purpose and location; you may subscribe to change notifications there. AI sub-processors are contractually barred from using your data to train their models (Section 6).
    • With our payment provider (Merchant of Record) — for paid plans, Paddle acts as Merchant of Record and, as such, is an independent controller of billing and tax data for the transaction. Their handling of payment data is governed by their own privacy notices.
    • For legal reasons — to comply with law, valid legal process, or to protect rights, safety, and the security of users and the public.
    • Government and legal requests — we disclose personal data in response to a legal request only where required by law, and we review each request for validity. Unless legally prohibited, we notify the affected Institution (and, where Cognity is the controller, the affected user) before disclosing, so they can seek to limit it.
    • Corporate transactions — if Cognity is involved in a merger, acquisition, bankruptcy or sale of assets, personal data may be transferred to the successor. The successor will be contractually required to protect it under commitments at least as protective as this Policy. We will notify affected Institutions and users before their data is transferred and becomes subject to a different privacy policy, and Institutions and users may request deletion of their data before the transfer.

    We do not otherwise disclose personal data to third parties without the required consent or legal basis.


    8. Well-being Signal — Handling of Sensitive Data

    Because Well-being Signals may reveal information about a Student's mental or emotional state, we treat them as sensitive:

    • access is restricted to Educators/staff authorized by the Institution;
    • the Institution is responsible for establishing the legal basis (e.g., explicit consent or a safeguarding/substantial-public-interest basis) and for its safeguarding response. Where the Student is an adult, that consent must come from the Student rather than from the Institution on their behalf;
    • the Signal is decision-support only and is not a diagnosis, medical service, or emergency/crisis-monitoring service; it may produce false positives and negatives and must not be relied upon to detect or prevent harm;
    • we apply additional access controls and shorter or configurable retention where feasible.

    9. Minors' and Students' Privacy

    The Service is used in educational settings and may be used by minors. What follows applies where the Student is a minor. Students do not create accounts: they join through a link and six-digit PIN provided by their Educator, or by signing in with their school's Google Classroom account (Section 3.1). Student participation is therefore mediated by the teacher/Institution, which provides the required authorization or consent. Requirements vary by jurisdiction:

    • United States — COPPA: For Students under 13, we rely on the Institution/Educator to provide, or to obtain from parents, the consent required by COPPA before Student personal information is collected, under COPPA's school-authorization framework. Institutions must make this Policy available to parents and retain consent records. Where the Institution obtains parental consent itself, it chooses the method. A parent may review their child's personal information, ask us to delete it, or refuse further collection by contacting the Institution or us at cognity@ctcorp.ai.
    • United States — FERPA and state laws: For education records, Cognity acts as a "school official" with a legitimate educational interest under the Institution's control, and complies with applicable state student-privacy laws (e.g., SOPIPA-type restrictions on advertising, selling data, and profiling).
    • EEA/UK — GDPR: The applicable age of digital consent ranges from 13 to 16 by country; where a child is below that age, consent/authorization is provided by the holder of parental responsibility or by the Institution as controller.
    • Other jurisdictions: We follow applicable local requirements for minors' data.

    If we learn that we collected a child's personal data without the required authorization, we will delete it promptly.

    Adult Students (universities and colleges). Where a Student is an adult, no parental or guardian consent is required. The Student is their own data subject: they consent for themselves, and they exercise their own rights (Sections 2.1 and 15). An Institution adopting the Service for its courses does not change that — in particular, the separate consent for Well-being Signals, which are sensitive data, must be obtained from the Student rather than from the Institution.

    Visibility and safety. Students' profiles, work and AI conversations are not public. Students cannot see other students' work or AI conversations. What a Student does in an assignment is visible to that Student and to the Educators and administrators the Institution authorizes. The Service has no public profiles or open social features between Students. Student AI interactions are screened by safety filters, logged, and available to authorized Educators for review, and Educators can flag and address misuse.


    10. International Data Transfers

    We may transfer and store personal data in countries other than yours, including where our infrastructure and sub-processors operate. Where required, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful mechanisms.

    Because Cognity is operated by a company established in the Republic of Korea, transfers of personal data outside Korea are disclosed in accordance with the Korean Personal Information Protection Act ("PIPA"). The table below identifies each overseas recipient, and the authoritative, versioned list — including the names of the AI/LLM providers that process student prompts and content — is maintained at https://www.cognity.cc/sub-processors (see Section 7). The two are kept consistent.

    Service data is hosted on Amazon Web Services in the Republic of Korea (Seoul region).

    Overseas transfer of personal data (PIPA disclosure):

    Recipient Country Items transferred Recipient's purpose Transfer date & method Retention period
    Google LLC (Gemini API, paid tier) United States Prompts, submissions, AI output AI generation, tutoring, and evaluation (Jello, project/rubric/image generation) Continuously, via encrypted network transmission (API) upon use Until service purpose is fulfilled or account deletion; then deleted
    Google Analytics (Google LLC) United States Usage & technical data Product analytics Continuously, via encrypted network transmission upon use Per Google Analytics retention settings
    Microsoft Corporation (Microsoft Clarity) United States Usage & technical data (page interactions) Product improvement analytics Continuously, via encrypted network transmission upon use Per Microsoft Clarity retention settings
    Paddle.com Market Ltd (Merchant of Record) United Kingdom Billing name & contact, transaction data Sale of record, billing, tax collection/remittance Upon purchase, via encrypted network transmission As required by law/accounting

    Legal basis for transfer. Overseas transfer is necessary to perform the Service — sending prompts to the AI provider is intrinsic to how Cognity works. On this basis, and because the required disclosures are provided in this Policy and in the Terms you accept when you begin using the Service, we do not request separate consent for the overseas transfer, as permitted under PIPA's contract-necessity provision. This basis is not consent and therefore cannot be "withdrawn" while you use the Service; if you do not want your data transferred as described, the Service cannot be provided to you. For personal data from the EEA/UK, the transfer is additionally safeguarded by Standard Contractual Clauses (or another valid mechanism); the PIPA basis and the GDPR safeguard operate together, not as alternatives. A copy of the safeguards is available on request at cognity@ctcorp.ai.

    Regional data storage (enterprise option). By default, Service data is stored in AWS's Seoul region. Under a separate enterprise agreement, an Institution may request that its data be stored in another AWS region. Regional storage does not by itself move AI processing: AI generation is performed via the Google Gemini API, which processes requests in the United States, so prompts are transmitted to the United States wherever other data is stored. The enterprise agreement will state the storage region and the AI-processing location.


    11. Data Retention

    We retain personal data only as long as needed for the purposes described, for the duration of the Institution's or your relationship with us, and as required by law. Institutions may configure retention and request deletion or return of Student data. On account deletion or contract termination, we delete or de-identify personal data without undue delay, except for limited backups (deleted on a rolling basis) and data we must retain by law. Well-being Signal data is retained for the shortest practicable period. We do not automatically delete inactive accounts. Personal data is kept until the Institution or the user deletes it, or until the account or contract ends, after which it is deleted or de-identified as described above.

    Deletion methods: electronic records are erased using non-recoverable methods; any paper records are shredded or incinerated.


    12. Security

    We implement administrative, technical, and physical safeguards appropriate to the risk, consistent with the security requirements of Korea's Personal Information Protection Act (PIPA) and Article 32 of the GDPR. These include:

    • an internal management plan and designated responsibility for personal-data protection;
    • access-rights management and access control — individual credentials, least-privilege access, and intrusion-prevention systems;
    • encryption of personal data in transit and at rest, including passwords and unique identifiers;
    • retention and periodic review of access (connection) logs;
    • anti-malware protection and timely patching;
    • physical security controls for systems that store personal data;
    • backups and disaster-recovery measures; and
    • confidentiality obligations and periodic security training for personnel.

    Enhanced access restrictions and shortened retention apply to sensitive data such as Well-being indicators. We periodically test and update these measures. No system is perfectly secure, and we are not responsible for losses caused by a user's failure to safeguard credentials or by circumstances beyond our reasonable control. We maintain an incident-response process and will notify affected parties and regulators of a personal-data breach where required by law.


    13. Cookies and Analytics

    We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand how it is used so we can improve it.

    We use two analytics tools on our websites and in the Service, only to improve the Service:

    • Google Analytics (Google LLC) — aggregate usage statistics.
    • Microsoft Clarity (Microsoft Corporation) — how pages are used, including heatmaps and session recordings of interactions.

    Neither tool is used for advertising. In Google Analytics, Google Signals and ads personalization are turned off, and it is not linked to any advertising account. Data they collect may be processed outside your country under the safeguards in Section 10. You can control non-essential cookies through your browser settings or our cookie controls where provided.


    14. Communications

    We send service and administrative messages needed to operate your account, such as security notices, billing notices and changes to these terms. We do not send marketing messages to Students or Educators. If that changes, we will ask for consent where the law requires it, and every marketing message will include a way to unsubscribe. We do not share contact details with third parties for their marketing.


    15. Your Rights

    Subject to applicable law, you may have rights to: access, correct, delete, or receive a portable copy of your personal data; restrict or object to processing; and withdraw consent. Where GDPR/UK GDPR applies, you also have the right to lodge a complaint with a supervisory authority. Where US state consumer-privacy laws apply, you may have rights to access, delete, correct, and opt out of "sale"/"sharing" and certain profiling (note: we do not sell the personal data of any user or use it for targeted advertising; see Section 4).

    How to exercise: Minor Students and their parents or guardians should ordinarily direct requests to their Institution, which controls Student data; we will assist the Institution. Adult Students may contact us directly at cognity@ctcorp.ai without going through their Institution — we do not route an adult data subject's rights through a third party. For other data where Cognity is the controller, use the same address. We will verify your identity and respond without undue delay and within the statutory period (for example, within one month under the GDPR; access within 10 days under Korea's PIPA). These rights cover all personal data we hold about the individual — including AI prompts, drafts, transparency records, and, where applicable, well-being indicators — which we can retrieve, export, or delete on a per-user basis. Upon request, we will tell you which categories of third parties (such as the sub-processors listed at https://www.cognity.cc/sub-processors) have received your personal data.


    16. Data Protection Contacts

    Privacy Officer (개인정보 보호책임자, required under PIPA): 유재상 (Jaesang Yoo), R&D Center / CTO Email: cognity@ctcorp.ai

    Company: CT Corp., 12F, 34 Yeongdong-daero 85-gil, Seoul, Korea (US: 301 N. Market St., Ste 1410, Wilmington, DE 19801) General privacy inquiries: cognity@ctcorp.ai

    You may also contact your local data protection authority.


    17. Changes to This Policy

    We will post changes here and, for material changes affecting your rights, provide notice at least 14 days in advance (or as required by law) through the Service or by other reasonable means. The "Last Updated" date reflects the current version.


    Cognity

    Accountability in every step of learning

    AI for schools and universities, by CT Corp.

    Product

    • Product
    • For Schools
    • For Universities
    • Pricing
    • Outcomes
    • AI visibility
    • Resources
    • Security

    Company

    • About
    • Contact
    • Get started
    • cognity@ctcorp.ai
    • LinkedIn
    • YouTube

    © 2026 CT Corp. All rights reserved.

    Illustrations by Storyset

    Terms of ServicePrivacy PolicyRefundsSub-processors
    English日本語한국어

    HQ: 12F, 34 Yeongdong-daero 85-gil, Seoul, Korea

    US: 301 N. Market St. Ste 1410, Wilmington, DE 19801

    Company: 주식회사 CT · CEO: 조현구
    Business registration no.: 113-86-62155
    Mail-order business no.: 2018-서울강남-00985