NNoscenda
BETA PRIVACY NOTICE

Privacy & your study data

This in-product notice describes the Noscenda University, A-Level and GCSE closed beta. The operator should obtain jurisdiction-specific legal review before a public commercial launch.

What Noscenda stores

Account/profile details, module metadata, uploaded course files, curriculum maps, questions and answers, tutor-session history, mastery evidence, misconceptions, generated notes, revision schedules and operational events needed to run the service.

How course files are used

Course files are private to your account under the application's access controls. They are used to build your curriculum map and retrieve evidence for tutoring. When AI features are enabled, files are indexed through the configured OpenAI API project and relevant excerpts, prompts and student answers are processed there to generate and evaluate learning content. The operator should keep API data-sharing settings aligned with the privacy notice and document the exact processor/retention configuration used for the beta.

What Noscenda does not do

The closed beta does not intentionally publish your private course material to other students or create a shared public library from your uploads. Course material is treated as private evidence for your course unless a future sharing feature is explicitly introduced and separately consented to.

Your controls

You can open or remove individual course files, download a JSON export of your Noscenda learning data from Settings, delete a module, or delete your entire account. Account deletion is designed to propagate through Noscenda's database, private file storage and the OpenAI files/vector stores created for your modules.

Age scope of this beta

The default closed-beta configuration is limited to adult testers aged 18 or over. GCSE curriculum mode may be tested by adults, teachers and operators. Before enabling access for under-18s, the operator must complete child-specific privacy, age-assurance and age-appropriate-design review and update the product accordingly.

Before public launch

The service operator must add its legal identity/contact details, retention periods, lawful bases, processor/subprocessor disclosures, international-transfer information and any required UK GDPR/GDPR notices before inviting public users.