University

Privacy · Last updated

What we keep, where it lives, and how you take it back.

The short version. Sessions are recorded, transcribed and written up for your course’s own staff, and never before you have said they may be. Course records are stored in the region the workspace chose, live conversation is processed by named providers overseas. You can export your platform record or start permanent account deletion from your own privacy page; MindMade completes any processor or storage cleanup that the automated workflow reports as unfinished.

  1. Clause 01. Who we are

    MindMade operates mindmade.university, a platform where university course staff run live teaching sessions with Maya, a digital tutor. This page describes what the platform records about you, where it lives, and how you take it back.

    For any privacy request, write to hi@mindmade.co. That address reaches the people who can actually act on it.

  2. Clause 02. Your account

    Accounts are managed by our authentication provider. It holds your email address and your name, and we use them for exactly two things: signing you in, and showing you the courses your email is enrolled in.

    Students never set a password with us and never hand us anything beyond the email their course already has on its roster.

  3. Clause 03. What a session produces

    A live teaching session with Maya produces a recording, a transcript and a session report, written for the course’s own staff. That is the record a tutor would keep of any tutorial: what was covered, where the student got stuck, what to pick up next time. A voice session records audio only and never uses the camera; a video session records camera and microphone.

    Nothing from your camera or microphone is recorded until you have said it may be. The notice appears before you enter the live room, names what that session captures, and stores your answer against the session. If you decline, you do not enter the room and no recording of you is created; we retain the consent decision and its audit record.

    Sessions also measure bounded voice-expression signals, a small set of numbers describing how the conversation sounded, hesitant or confident, flat or engaged. They exist to describe how a session felt, so a report can say “this student sounded lost in week three” while there is still time to help. They are never used as marks, never graded, and never shown as an assessment of the student.

  4. Clause 04. Where course data is stored, and where it is processed

    Every workspace chooses a data region when it is created, Sydney or the European Union, and the choice is permanent. Course content, rosters, transcripts, session reports and knowledge documents are stored in that region and stay there. Session recordings are written to storage in the same region, Sydney or Frankfurt, and are never copied out of it.

    Storage and processing are different questions, so this policy answers them separately. While a session is running, its audio, its video and the words spoken in it are handled by the voice, video, transport and language providers that make Maya work, and those providers are in the United States. The record the session leaves behind is written to your region and lives there. Clause 09 names every provider, what reaches it, and where it sits.

    Our application servers run in Sydney for every workspace, including European ones. A European workspace has European storage and Australian compute. We state that plainly here so the word “region” is not read as a promise about both.

    Nothing a course uploads is shared beyond it, and nothing is used to teach anyone else’s students.

  5. Clause 05. Analytics

    We run product analytics through an analytics service hosted on United States cloud infrastructure, which records pageviews and product events so we can see which parts of the platform work and which need fixing.

    After you sign in, those events carry an account identifier and your role, which is what lets us tell a lecturer’s experience of the platform from a student’s. Your email address is not sent with them, and neither is your name.

    Analytics run without cookies until you allow them. The choice is offered once, in a small banner, and “essential only” costs you nothing, the platform works identically either way.

  6. Clause 06. Billing

    Usage bills per minute through our payment processor. Card details go to the processor directly and never touch MindMade servers; what we keep is the invoice history a workspace owner would expect to see.

  7. Clause 07. Export and erasure

    From /me/privacy you can download the regional account and course record currently available in self-service, or start account deletion. The download does not yet include every control-plane audit or provider-held record; write to hi@mindmade.co for a complete access request.

    The automated workflow blocks sign-in, removes your account and membership records, deletes regional account data, attempts to delete individual-call recordings and conversations, and requests deletion from our analytics provider. Detected failures remain in an operations queue for retry. A request is complete only after MindMade confirms provider and storage cleanup; account deletion is not reversible.

    One honest limit. Teaching records shared with other students or required by a course may be retained. We remove your account link and direct profile labels, but shared transcript text, audio or video can still contain identifying content and is not automatically redacted. Contact hi@mindmade.co for a complete access or erasure request, an assessment of retained shared records, and confirmation of provider cleanup.

  8. Clause 08. Retention

    Session artifacts have expiry dates, and scheduled sweeps remove them once those dates pass. We keep what a course needs for teaching, not an archive for its own sake.

  9. Clause 09. Subprocessors

    These are the providers that process data on our behalf, each under contract and only for the purposes above. This is the whole list, published here so a university privacy office can read it without asking us for it first.

    Tavus, in the United States, runs the video engine. A video session’s camera and microphone pass through it, along with the student’s first name, the course name, and the teaching context Maya works from. It writes the session recording straight into our storage in your region.

    Anam, in the United States, runs the newer one-to-one video room, currently offered as a beta a course can choose. A session in that room carries your camera and microphone through Anam, and the conversation turns pass back through our own servers so the language providers below can answer. When a session is recorded with consent, the recording is made at Anam, copied into our storage in your region when the session closes, and the copy at Anam is then deleted.

    Hume, in the United States, runs the voice engine. A voice session’s microphone audio passes through it, along with the same teaching context, and it returns the transcript and the voice-expression signals described in clause 03. Where a course has turned on web search, Maya can also ask the voice engine to look something up during a voice session. The voice engine runs that search itself through a web search service it operates, whose provider it does not name and which MindMade does not contract with directly. What is looked up is drawn from the conversation, so it can include what was just said. This is off unless the course’s staff switch it on, and the session notice says so before a student starts.

    Daily, in the United States, carries the live audio and video between your browser and the video engine. The recording of that session is written to our own storage.

    Anthropic and xAI, both in the United States, are the language providers behind what Maya says and writes. The teaching context and the words spoken in a session reach them so a reply can come back, and so a transcript can be written up into a session report.

    Clerk, in the United States, manages accounts and sign-in. It holds your email address and your name.

    Stripe, in the United States, takes payment from workspace owners. Card details go to it directly and never touch our servers.

    Vercel, in the United States, hosts the platform and runs our application servers, which are pinned to Sydney. Every request your browser makes reaches us through its network.

    PostHog, in the United States, receives the product analytics described in clause 05. What reaches it is an account identifier, a role, and the events themselves.

    Neon, in the United States, operates our databases. The databases themselves sit in Sydney and in Frankfurt, in the region each workspace chose.

    Amazon Web Services stores session recordings and holds the databases underneath, in Sydney for a Sydney workspace and in Frankfurt for a European one.

    Sentry, in Germany, receives the error reports the platform raises when something fails, so a fault can be traced and fixed.

    Google, in the United States, serves the typefaces this site is set in. A browser loading a page requests them, and that request carries its own network address.

    When a provider is added, replaced or removed, workspace owners are told before the change takes effect. A register with the same detail, written for a security assessment, is at hi@mindmade.co.

  10. Clause 10. Changes

    When this policy changes, the date at the top changes with it. A change that affects what we collect or where it lives is announced to workspace owners before it takes effect.

A question this page didn’t answer?