ScaLearn.ai← Back to home

Privacy policy

Last updated 30 September 2026

This policy explains what personal data ScaLearn collects when you use scalearn.ai, why we use it, who processes it for us and where, how long we keep it, and your rights. It covers students, educators, visitors who use a tutor through a share link, and anyone who visits our website. Our terms of use set out the rules for using ScaLearn.

Contents

  1. Who we are
  2. What we collect and why
  3. How we use AI
  4. Who can see your data
  5. Service providers and where they process data
  6. Transfers outside the UK
  7. Our lawful bases
  8. How long we keep data
  9. Your rights
  10. Cookies and local storage
  11. Changes to this policy
  12. Contact

1. Who we are

ScaLearn AI Ltd is a private limited company registered in England and Wales, company number 17158584. We run ScaLearn and are the controller of the personal data this policy describes. For anything about your data, email [email protected].

2. What we collect and why

Your account

To create an account with an email address, we collect your name, email address and a password. Accounts created through sign-up are student accounts. Our admins set up educator and admin accounts. We record the modules you are enrolled on, and we show you notifications in the app.

To stop automated sign-ups, the sign-up form runs a Cloudflare Turnstile check, which sends your IP address to Cloudflare, and we limit how many sign-ups can come from one network. For that limit we store only a hashed form of your IP address, and we delete it after two days.

Signing in with Google or LinkedIn

If you sign in with Google or LinkedIn, the provider shares your name, your email address, whether that email address is verified, your profile picture if you have one, and the identifier of your account with them. We accept only verified email addresses, and we do not use your profile picture. We use these details to sign you in and to create or find your ScaLearn account, and after that they are your account details. We do not receive your Google or LinkedIn password, and we do not ask for access to anything else in those accounts.

Google Identity Platform runs this sign-in for us. It keeps a record of your sign-in account (your name, email address and the provider you use) and processes it in the United States. A service we run in London links that record to your ScaLearn account. To limit abuse, that service counts new accounts from each IP address, in memory only.

Course materials

If you are an educator and upload course materials, we store the files (PDF, Word, PowerPoint, text and image files), the text we extract from them, short titles and descriptions that AI writes for them, search indexes built from the text, and who uploaded each file. The files are stored in Google Cloud Storage in London. The extracted text and indexes are stored in our database in Ireland.

Chat with the course tutor

We store your questions, the tutor’s answers and the sources each answer cites, as conversations you can come back to. If you attach a file (up to 10 MB) or a link to a message, we store the file or the link, and the text taken from it, with the conversation. Our server fetches a linked web page for you, so the website sees a request from ScaLearn rather than from you.

For each question we also keep an answer-quality log: the question (sometimes as AI has reworded it) and the passages that were found. These logs are not linked to your name or account. We use them to check and improve answers.

Video avatar and text tutors

Some tutors are video avatars, run by Tavus or by HeyGen’s LiveAvatar service. During a session your browser sends your microphone audio to the provider, and for Tavus tutors your camera video too, if your camera is on. We record when each tutor session starts and ends, how long it lasts and the topics it covered. Educators and admins can ask AI to list those topics from the transcript.

  • Tavus. We send Tavus your email address and the topic you choose, so the tutor knows who it is talking to, and Tavus sends us a transcript after the session. Tavus records the video of a session only if we switch recording on for that tutor, which is off by default.
  • LiveAvatar. We send no details about you, and we do not store transcripts of signed-in LiveAvatar sessions.
  • Text tutors. Answers come from the same AI as the course chat. We record the session but not the conversation.

Tavus can infer emotion from facial expressions and tone of voice. For people connecting from the European Economic Area, or whose location we cannot tell, we ask Tavus to turn this off and to tell you at the start that you are talking to an AI. For everyone else, including people in the UK, Tavus’s emotion recognition stays on and Tavus does not make that announcement, although ScaLearn still shows you a notice that you are talking to an AI system.

Voice rubric building

If you are an educator and build a rubric by voice, your microphone audio goes through our service in London to Google Vertex AI Live in Belgium (europe-west1), which transcribes your speech and answers it. It hears your speech and the rubric’s current contents only, never student work. We store transcripts of what you say with the rubric’s history in London. We do not keep the audio.

Coursework and marking

If your educator sets an assignment in ScaLearn and you submit work for it, we store the text of your work (not the file you upload), your name and student identifier, the marks and evidence AI suggests, your educator’s decisions and comments, the feedback released to you, and a log of the actions taken on the assignment. AI reads the full text of your work to suggest marks. Your name is not sent to the AI as a separate item, but any name written in your work is. Until your educator releases marks, you see only the status of your submission.

If you are an educator, we record your decisions, comments and email address against the marks you confirm and release, and we store your conversations with the rubric assistant and the documents you use, such as course outlines and assignment briefs.

Coursework and marking records are stored in Google Cloud in London. Google keeps backups of that database in its EU multi-region. Records from before we moved this database to Google Cloud in September 2026 are also held in a Supabase database in London.

Study profile

You can choose to paste a summary of your study habits, for example one written by another AI assistant. AI turns it into a short profile and we store only that profile, not what you pasted. We ask the AI to leave out names, health details and other personal information, so paste only what you are happy for it to read. The tutor uses your profile to tailor its answers. You can edit or delete it at any time.

Feedback and messages

After a tutor session you can rate it and add tags and a comment. If you message our team from the app, we store your message and your role. If you use the contact form on our home page, your name, email address and message are sent to us by email, and we do not store them in our database.

Share-link visitors

If you use a tutor through a share link, you do not need an account. We store the display name you enter, a transcript of your conversation, whether you used the avatar or the chat and for how long, and a hashed form of your IP address. Your display name is given to the AI tutor so it can address you. To protect each link we check the passcode and record the attempts, and we delete those attempt records after 30 days. If you rate a share-link session, your rating and tags go to our analytics provider only, and any comment you type is not kept.

Analytics

We use Mixpanel to understand how ScaLearn is used and to improve it. On every page, Mixpanel records the address of the page, the buttons and links you click, events such as signing in or starting a session, and a recording of your visit that shows how you move through the pages. Mixpanel’s default settings, which we have not changed, hide the text on the page and anything you type in these recordings, and leave out images and video. When you are signed in, Mixpanel links this activity to your account identifier, name, email address and role. Mixpanel uses your IP address to estimate your approximate location. Errors in your browser are also reported to Mixpanel, with the technical error message.

Error monitoring

When something goes wrong in your browser or on our servers, we send an error report to Sentry. It includes what failed, the page address, the technical steps leading up to it, and your browser and device type. In your browser, we remove email addresses and access tokens from error messages before they are sent. Sentry does not record your screen.

Hosting, security and fonts

Cloudflare hosts our website and protects it, so it processes your IP address and the details of each request. The Cloudflare Turnstile bot check runs on the sign-up form, the share-link passcode form and the contact form on our home page. It runs in your browser, so Cloudflare receives your IP address. Our pages load fonts from Google Fonts, so your browser sends your IP address to Google when a page loads.

Organisations that visit our website

When you first open our home page or research page, we load Apollo.io’s website tracker. It uses your IP address to identify the company or organisation you may be visiting from, so we can follow up with organisations interested in ScaLearn. It stores identifiers in your browser and sends Apollo the address of each page you view and the page you came from. Where Apollo’s service allows it, the script also loads a tag from LiveIntent. LiveIntent receives details of your visit and can match it to an email address it already holds, and then gives Apollo a hashed (scrambled) copy of that address. The tracker does not load when you open other pages directly, but if you move on from the home or research page in the same tab, it keeps running until you reload or leave the site.

3. How we use AI

ScaLearn uses Google’s Gemini models on Google Cloud’s Vertex AI to: answer questions from a module’s materials and cite the passages used; read, transcribe and index uploaded materials; write short titles and descriptions for them; suggest starter questions for a tutor; list the topics a session covered; turn a pasted study summary into a short profile; and, in the marking tools, draft rubrics from a course outline and suggest marks, evidence and feedback. These models run in London (europe-west2), except live voice for rubric building, which runs in Belgium (europe-west1). The video avatar providers, Tavus and LiveAvatar, run their own AI to hold a spoken conversation, using the context we give them.

AI can be wrong. Chat answers show their sources so you can check them, and you should check anything important. In the marking tools AI only suggests: an educator decides every mark, and no mark is final without their review. We do not make decisions about you that have legal or similarly significant effects by automated means alone.

We do not use your data to train AI models.

4. Who can see your data

  • Your educators. The educators assigned to a tutor can see the dates, length, topics and transcripts of your sessions with it, and the feedback you leave. While you are in a Tavus video session with their tutor, they can see that it is live and join it. In the marking tools, the educators on a module can see your submitted work, the AI’s suggestions and their decisions, with your name and student identifier. Educators can read the answer-quality logs for their modules, which are not linked to who asked.
  • Only you. In the app, only you can see your chat conversations with the course tutor and your study profile.
  • Share-link visitors. The educator who created a share link and our admins can see your display name and transcripts.
  • If you are an educator. Your name can be seen by other people using ScaLearn, including visitors to your share links, and the address of a share link you create includes your title and surname, or the first part of your email address if we have no name for you. If your tutor carries your name, its video avatar provider receives that name. Materials on a module can be opened by anyone signed in to ScaLearn, and share-link visitors can open a file their tutor cites.
  • Our admins can see account details, tutor sessions, transcripts, feedback and messages to our team, to run and support ScaLearn. Our technical team can access the underlying databases to run, secure and support the service.
  • Service providers receive data, as the next section describes. We do not sell your personal data.

5. Service providers and where they process data

These providers receive personal data when you use ScaLearn:

  • SupabaseOur main database, email and password sign-in, storage for chat attachments, and server functions.Where: Ireland. Server functions run in the Supabase region closest to you. Older coursework records are held in London.
  • Google CloudAI models (Vertex AI), storage for course files, the coursework database, the marking service and the service that links Google and LinkedIn sign-ins to your account.Where: London (europe-west2). Backups of the coursework database are kept in Google’s EU multi-region, and request logs in Google’s global logging storage. Live voice for rubric building runs in Belgium (europe-west1).
  • Google Identity PlatformSign-in with Google or LinkedIn.Where: United States.
  • TavusVideo avatar tutors.Where: United States.
  • HeyGen (LiveAvatar)Video avatar tutors.Where: United States.
  • MixpanelProduct analytics and session recordings.Where: European Union.
  • SentryError monitoring.Where: European Union (Germany).
  • CloudflareHosting and protecting the website, and the Turnstile bot check.Where: Cloudflare’s global network.
  • ResendDelivering messages from the contact form on our home page to us by email.Where: United States.
  • Apollo.io, and LiveIntent through Apollo’s scriptIdentifying organisations that visit our home and research pages and, where Apollo allows it, the people visiting.Where: United States.
  • Google FontsFonts used on our pages.Where: Google’s global network.

6. Transfers outside the UK

Ireland, Belgium and Germany, and the EU locations Mixpanel and Google use, are in the European Economic Area, which UK law recognises as protecting personal data adequately.

Google Identity Platform, Tavus, HeyGen, Resend, Apollo.io and LiveIntent process data in the United States, and Cloudflare and Google Fonts may process it anywhere on their global networks. Google, HeyGen, Resend and Apollo.io are certified under the UK-US data bridge (the UK Extension to the EU-US Data Privacy Framework), which UK law recognises. So are Mixpanel and Sentry, which keep our data in the EU. Email [email protected] to ask about the safeguard for a particular provider.

7. Our lawful bases

UK data protection law requires a lawful basis for each use of personal data. Ours are:

  • Contract. To provide ScaLearn to you under our terms of use: your account, the tutors, the course chat, course materials, share links, the study profile, the marking tools and notifications.
  • Legitimate interests. To provide a tutor an educator has shared with share-link visitors; to keep ScaLearn secure and prevent misuse, through bot checks, rate limits, passcode attempt records and error monitoring; to understand and improve ScaLearn, through analytics, session recordings and answer-quality logs; and to find organisations interested in ScaLearn and reply to messages sent to us. You can object to any of these.

8. How long we keep data

We keep your data while your account is open and delete it when you ask us to. Some things work differently:

  • Hashed IP addresses used for rate limits are deleted after two days, and share-link passcode attempt records after 30 days.
  • Request logs kept by our Google Cloud services, which include IP addresses, are deleted after 30 days.
  • You can delete a chat conversation, with its messages, and your study profile yourself. Files you attached to messages are kept after you delete the conversation: email us to have them removed.
  • Coursework and marking records are kept until the assignment is deleted. We can delete an assignment, with its submissions, marks and feedback, on request, keeping a short record that the deletion happened. Google’s backups of that database roll over within about a week. The older records held by Supabase in London are kept until we delete that database.
  • Materials an educator uploads stay on their module until they are deleted from it, even if the educator’s account is closed.
  • Transcripts of share-link visitors stay available to our admins after the link, or its educator’s account, is deleted.
  • A hashed form of a share-link visitor’s IP address is kept with their session.
  • Answer-quality logs are not linked to you, so they are not deleted with your account.
  • Mixpanel keeps analytics events for two years, session recordings for 30 days, and the profile that links events to your account until we delete it. Sentry keeps error reports for up to 90 days. We can ask either to delete a person’s data sooner.

There is no button to delete your account yet. To close it, email [email protected].

9. Your rights

Under UK data protection law you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send data you gave us to you or another service in a common format. You can object to our using your data on the basis of legitimate interests, including for analytics and the Apollo tracker.

If you signed up with an email address, you can change your email address and password in Settings. For anything else, including correcting your name or deleting your account, email [email protected]. We will reply within one month.

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

10. Cookies and local storage

ScaLearn itself sets one cookie, sidebar:state, which records whether the app’s side menu is open and lasts seven days. It keeps everything else in your browser’s local storage, session storage or IndexedDB:

  • Signing in. Your ScaLearn sign-in session, and, if you use Google or LinkedIn, the sign-in state that Google’s sign-in library keeps. Signing out removes them.
  • Share links. The display name you entered for a link, until you close the tab, and a random identifier used to decide whether a shared tutor opens as an avatar or a chat.
  • Preferences. Your light or dark theme, layout choices such as sidebar and chat width, how you sort and pin modules, the modules you opened last, whether you have finished the welcome tour or dismissed a prompt, your place in our home page slideshow, and similar settings.

Other services on our pages keep their own data in your browser:

  • Analytics. Mixpanel keeps an identifier, its settings and parts of the session recording before they are sent.
  • Organisations that visit our website. On our home and research pages, Apollo.io’s tracker and LiveIntent keep identifiers.
  • Content from other services. Video tutors, the sign-in window and the bot check come from Tavus, HeyGen, Google, LinkedIn and Cloudflare, which may keep their own data in your browser under their own policies.

You can clear or block this storage in your browser settings. Clearing sign-in storage signs you out. To stop analytics or the Apollo tracker, you can block them with your browser’s privacy settings or a tracker blocker, or email us to object.

11. Changes to this policy

We will update this policy when ScaLearn changes. The date at the top shows when it last changed. If a change significantly affects how we use your data, we will tell you in ScaLearn.

12. Contact

Email [email protected] about this policy or your data.

Privacy policyTerms of useHome

© 2026 ScaLearn AI Ltd. Registered in England and Wales, company number 17158584.