Skip to content
AptitudAI

Privacy Policy

What we collect, why, who controls it, and how to get it deleted. Written for the people who have to sign off on a procurement, not only for lawyers.

This policy is issued by AptitudAI Corporation (“AptitudAI”, “we”, “us”), 8565 S Eastern Avenue, Ste 100, Las Vegas, NV 89123, United States. It applies to www.aptitudai.com and to the AptitudAI assessment platform (the “Platform”). It is effective from 21 August 2026.

1. Two roles, two sets of rules

We act in one of two capacities, and which one applies changes what we may do with data.

  • Controller — for the website, for enquiries and demo requests, for marketing, and for the accounts of the staff at an institution who administer the Platform. We decide why and how that data is processed.
  • Processor (service provider) — for everything a learner does inside the Platform. The school, district, university, employer or agency that deployed the Platform (the “Institution”) is the controller. We process learner data only on its documented instructions and under the agreement we sign with it.

2. Student data: K-12 and other minors

AptitudAI is sold to schools and districts. That means learners under 18, and in some cases under 13, use the Platform. The following applies to all of them, in addition to everything else in this policy.

2.1 The Institution is the controller

We never collect student data directly from a child on our own behalf. Student accounts are created by, or under the authority of, the Institution. We are building the Platform and our contracts to meet the Family Educational Rights and Privacy Act (FERPA): we act as a “school official” with a legitimate educational interest, under the Institution’s direct control, and we use education records only for the purpose the Institution engaged us for.

2.2 Parental consent (COPPA)

Where a learner is under 13, the Children’s Online Privacy Protection Act (COPPA) requires verifiable parental consent before personal information is collected. We rely on the Institution to provide that consent on the parent’s behalf, which the Federal Trade Commission permits for educational services used solely for the benefit of students and the school. The Institution agrees, in its contract with us, that it has the authority to do so. A parent or guardian may review their child’s data, or ask for it to be deleted, by contacting the Institution or by emailing contact@aptitudai.com; we will act on the request in coordination with the Institution.

2.3 What we collect about a student

  • Name, class or cohort, and an identifier issued by the Institution.
  • Assessment data: the questions served, the answers given, time taken, the difficulty path the engine followed, and resulting scores and objective-level reports.
  • Practice data, where the Institution enables the self-paced practice track.
  • Technical data needed to run the service: device type, browser, IP address, and session logs.

We do not collect a student’s precise location, contacts, photos or biometrics. Where the Institution enables proctored sittings, the Institution decides what is captured and we document it in the deployment agreement.

2.4 What we will never do with student data

  • Sell it, rent it, or share it for advertising of any kind.
  • Build a profile of a student for any purpose other than the educational purpose the Institution engaged us for.
  • Use it to train models that serve any other customer. Generated questions are drafted from the Institution’s own coursework, not from other learners’ answers.
  • Serve advertising to students.
  • Retain it after the Institution tells us to delete it.

2.5 Retention and deletion

Student data is kept for the length of the deployment agreement plus 90 days, unless the Institution instructs otherwise or the law requires a different period. On termination, or on written request from the Institution at any time, we delete or return the data within 30 days and certify that we have done so. Backups are purged on their normal rotation, no later than 90 days after the deletion request.

2.6 State student-privacy laws

Where a state imposes additional obligations on operators of educational services (for example California’s SOPIPA, or student-privacy statutes in Illinois, New York, Colorado and elsewhere), the deployment agreement will name them and set out how we meet them.

3. Data we collect as controller

  • Enquiries and demo requests: name, work email, organisation, sector, and anything you write in the message.
  • Administrator accounts: name, work email, role, and the actions you take inside the Platform (these are logged for audit).
  • Website use: pages visited, referrer, approximate location from IP, and device and browser type. See the Cookie Policy for what is stored on your device.

4. Why we use it and on what basis

  • To respond to you and to run a demo you asked for (performance of a contract, or steps before one).
  • To operate, secure and support the Platform (performance of a contract; legitimate interest in keeping the service running).
  • To send product and company updates to people who asked for them (consent; you can withdraw it any time).
  • To meet legal obligations, and to establish or defend legal claims.

We do not make decisions with legal or similarly significant effects on a person by automated means alone. Assessment results are reported to the Institution; what is done with them is the Institution’s decision.

5. Who we share it with

  • Sub-processors who host and operate the service on our behalf, under written contracts that bind them to this policy. The current list is available on request and is included in every deployment agreement. We notify Institutions before adding one.
  • The Institution, for anything a learner does inside its deployment.
  • Authorities, where the law requires it, and after telling the Institution unless we are legally prevented from doing so.
  • A successor, if the company is sold or merged, under the same commitments.

We do not sell personal data, and we have not done so in the preceding twelve months.

6. Where it lives

Platform deployments run inside the Institution’s own environment or in a dedicated environment in the region the Institution chooses. Website and enquiry data is processed in the United States. Where data moves out of the European Economic Area or the United Kingdom, we use Standard Contractual Clauses or another mechanism the law recognises.

7. Security

Data is encrypted in transit and at rest. Access is role-based and logged. Deployments are isolated per client. We run a documented security programme and will describe it, and share the results of independent assessments as they are completed, to any Institution under a non-disclosure agreement. We are working toward SOC 2 and will publish our status here as it changes. If a breach affects personal data we notify the Institution without undue delay, and in any event within 72 hours of becoming aware of it, so that it can meet its own notification duties.

8. Your rights

Depending on where you are, you may have the right to access, correct, delete, restrict or port your personal data, to object to processing, and to withdraw consent. Residents of the EEA and UK have these rights under the GDPR; residents of California and several other states have equivalent rights under state law. To exercise them, email contact@aptitudai.com. We respond within 30 days. If the data concerns a learner inside an Institution’s deployment, we will route the request to the Institution, which controls it. You may also complain to your data protection authority.

9. Changes

We will post any change here with a new effective date, and tell Institutions directly about any change that affects student data before it takes effect.

10. Contact

Privacy questions, rights requests and parental enquiries: contact@aptitudai.com.
AptitudAI Corporation, 8565 S Eastern Avenue, Ste 100, Las Vegas, NV 89123, United States.

This policy is governed by the laws of the State of Nevada, United States.