Privacy Policy
For schools, districts, colleges, educators, students and parents · Last updated: July 20, 2026
The short version. KogIT Labs is a training tool that schools use. We hold a student's name, school email, and their progress through simulations — nothing more. We use that data only to run the service for your school.
We never sell student data, never use it for advertising, and never build profiles from it. Your institution owns its data and can have it deleted at any time.
1. Who we are, and our role
KogIT LLC ("KogIT", "we") provides browser-based interactive IT simulations for education and training. This policy covers the KogIT Labs educator portal and the simulations reached through it.
When a school, district, college or university (the "Institution") uses KogIT Labs, the Institution decides what data is collected and why — we act on its instructions. In data-protection terms the Institution is the controller and KogIT is the processor. Students and parents with questions about a specific student's records should contact their school first; the school directs us.
2. FERPA — we act as a School Official
Under the Family Educational Rights and Privacy Act, an Institution may share education records with a contractor performing a service it would otherwise do itself. When an Institution engages KogIT, it designates us a "School Official" with a "legitimate educational interest" under 34 CFR § 99.31(a)(1)(i)(B).
That means we operate under the Institution's direct control regarding the use, handling and retention of student data, we use student data only to deliver the service, and we do not re-disclose it. Institutions sign a FERPA & COPPA Data Protection Addendum alongside their agreement; where that Addendum and this policy differ, the Addendum governs for that Institution.
3. COPPA — students under 13
KogIT Labs is offered to Institutions, not marketed directly to children. Where an Institution provides the service to K-12 students under 13, the Institution acts as the parent's agent and provides consent on the parents' behalf for us to collect and process the data described below, for educational use only.
We do not ask students for any personal information beyond what the school supplies to create their account, and we do not use student data to serve advertising or build commercial profiles.
4. What we collect
Student accounts are created by an educator or administrator at the Institution — students do not sign themselves up with personal details.
| Category | What it is | Why we hold it |
|---|---|---|
| Account data | First and last name, school-issued email address, role (student / educator / administrator), the Institution and classes the account belongs to, account status, and account/last-sign-in timestamps. | To create the account, authenticate the user, and place them in the right class. |
| Credentials | A one-way cryptographic hash of the password. We never store the password itself and cannot recover it. | To verify sign-in. |
| Learning records | Which simulations are assigned and opened, completion status and percentage, score, tasks completed, time spent, and start/last-active/completion timestamps. | So educators can see class progress — the core purpose of the portal. |
| Session records | For streamed 3D simulations: which simulation, when it started and ended, and how long it ran. | To meter usage, apply any limit the educator set, and bill the Institution accurately. |
| Technical data | A sign-in session identifier, and the IP address of sign-in attempts, held briefly. | To keep the user signed in and to block brute-force attacks. Not used to track browsing. |
| Error reports | If something breaks: the page or API path and browser type. Scrubbed of cookies, tokens and request bodies. | To find and fix faults. |
We do not collect home addresses, phone numbers, dates of birth, government identifiers, photographs, biometric data, precise location, or payment details from students. We do not use tracking or advertising cookies, and we do not run third-party analytics or advertising trackers on the portal.
Work inside a simulation stays inside it. KogIT does not have access to the content of a running simulation session — only the fact and duration of the session. Simulation reports must be saved by the user at the time of completion.
5. What we never do
- We never sell, rent or license student data.
- We never use student data for advertising, marketing, or behavioural profiling.
- We never mine student data to build products unrelated to delivering the service.
- We never disclose student data to third parties except the sub-processors listed below, or where strictly required by law.
We may use anonymised, aggregated usage statistics — which cannot identify any student or Institution — to improve and monitor the service.
6. Sub-processors
We use the following providers to run the service. Each is bound by data protection terms at least as protective as this policy, and none is permitted to use student data for its own purposes.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare, Inc. | Application hosting, content delivery, security | All service traffic |
| Neon, Inc. | Managed PostgreSQL database (United States) | Account and learning records at rest |
| Vagon & Amazon Web Services | Streaming of 3D simulations | Session delivery; no student records passed |
| Resend | Transactional email (password resets, access requests) | Name and email address |
| Functional Software, Inc. (Sentry) | Error monitoring | Page/API path and browser type only |
| Google LLC (Google Fonts) | Web fonts | IP address, as with any web request for a font file |
We will tell Institutions before adding a sub-processor that handles student data. Data is stored and processed in the United States.
7. How we protect it
- Encrypted in transit using TLS 1.2 or higher, with HTTP Strict Transport Security enforced.
- Encrypted at rest in our managed database and hosting platforms.
- Passwords are stored only as PBKDF2-SHA256 hashes with 100,000 iterations and a unique random salt per password, and are compared in constant time.
- Sign-in sessions use a random opaque token; only a SHA-256 hash of it is stored, so a database record cannot be replayed as a login. Session cookies are
HttpOnly,SecureandSameSite-restricted, and are never readable by page scripts. Sessions expire on inactivity and can be revoked instantly. - Access control is enforced on the server for every request: educators can reach only their own classes and students, students only their own records, and administrators only their own Institution.
- Brute-force protection locks out repeated failed sign-ins per account and per network address.
- Browser hardening via an enforced Content Security Policy, clickjacking and MIME-sniffing protections, and a restrictive permissions policy.
8. How long we keep it, and deletion
We keep account and learning records for as long as the Institution's agreement is active, because that is what makes progress history useful to educators.
- On request: an Institution may ask us to delete a specific student's records, or all of its records, at any time.
- On termination: we permanently delete the Institution's student records within 30 days of the agreement ending, unless the Institution asks us in writing to hold them longer.
- Backups: residual copies in encrypted backups are overwritten and unrecoverable within 60 days of the deletion request.
- Educators can remove a student from a class, and administrators can delete accounts, directly in the portal.
9. Rights of students and parents
Under FERPA, rights of access and correction sit with the Institution (and with parents or eligible students through the Institution). Please direct requests to your school — we act on the school's instructions and will support them promptly.
If you are an educator or administrator, contact us directly at contact@ekogit.com.
10. Security incidents
If student data held by us is subject to a confirmed unauthorised disclosure, we will notify the affected Institution without undue delay, describe what happened and what data was involved, and support the Institution in meeting its own notification obligations.
11. Educators and other adult users
For educators, administrators and prospective customers we also process the details submitted in access, material and feedback requests — typically name, work email, institution and role — in order to respond. This is business contact information, not student data.
12. Changes to this policy
We will update the date at the top when this policy changes. For changes that materially affect how student data is handled, we will notify Institutions directly rather than relying on this page.
13. Contact
KogIT LLC
800 North St, Wilmington, DE 19801
contact@ekogit.com · Text: +1 (302) 722-6727
kogitlabs.com
