Privacy Policy
How Answerr collects, uses, and protects personal data for individuals and institutions—including AI prompts, assessment results, and AIQ™ credentials.
Last updated: August 7, 2026
Supersedes: Privacy Policy dated December 21, 2025
Answer Labs Inc. (doing business as Answerr), 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, Delaware, USA.
1. Start here: who controls your data
Answerr plays two different roles depending on how you got access. This determines who you go to with a privacy request, so it matters more than anything else in this policy.
| If you… | Answerr is… | For privacy requests, contact… |
|---|---|---|
| Use Answerr because your university, college, or employer provides it | A processor (or “service provider”) acting on that organization’s instructions | Your institution first. They control the data. We will support them, and we will forward requests we receive directly. |
| Signed up and paid for Answerr yourself | A controller (or “business”) | Us, at support@answerr.ai |
| Visit answerr.ai, attend our events, or talk to our sales team | A controller | Us, at support@answerr.ai |
Where we act as a processor, our handling of your data is governed by our agreement with your institution and our Data Processing Addendum, not solely by this policy. If those documents conflict with this policy for institutional data, they control.
2. What we collect
2.1 Information you or your institution provide
| Category | Examples |
|---|---|
| Account information | Name, email address, role, institution or employer, department or program |
| Authentication data | SSO identifiers, LTI 1.3 launch claims, roster identifiers passed by your LMS |
| Billing information | Billing name and address, plan and credit balance. Card numbers are collected and stored by our payment processor, not by us. |
| Inputs | Prompts, questions, uploaded files, and other content you submit to AI models through Answerr |
| Assessment responses | Your work product during an AIQ™ assessment, including drafts, revisions, prompts, and iterations |
| Support and sales communications | Emails, tickets, demo requests, and meeting notes |
2.2 Information generated by your use
| Category | Examples |
|---|---|
| Outputs | Content returned by AI models in response to your Inputs |
| Usage and telemetry | Models selected, credits consumed, features used, timestamps, session duration, pages viewed |
| Assessment Results | Behavioral signals extracted from assessment responses, intermediate scoring values, and dimension-level results across the SLPT dimensions |
| Credential records | AIQ™ Credentials issued, issue date, assessment version, expiry, revocation status |
| Device and connection data | IP address, browser type, operating system, device type, approximate location derived from IP |
| Security logs | Login events, access attempts, administrative actions |
2.3 Information collected only when a feature is enabled
| Category | When collected |
|---|---|
| Session media (camera images or video during an assessment) | Only where an Institutional Customer has enabled session monitoring for a specific assessment campaign, and only after you affirmatively consent. Off by default. See Section 6. |
| Identity verification data | Only where an institution requires identity verification for a proctored assessment. |
We do not collect government identification numbers, financial account numbers beyond what our payment processor handles, precise geolocation, biometric templates for any purpose other than as described in Section 6, or special-category data such as health, religious, or political information. Do not submit that information through Inputs.
3. Why we use it, and our legal basis
Where the GDPR or UK GDPR applies and we act as a controller, we rely on the legal bases below.
| Purpose | Legal basis |
|---|---|
| Provide, operate, and maintain the Service | Performance of a contract |
| Authenticate you and secure accounts | Contract; legitimate interests in security |
| Process payments, manage credits, and prevent billing fraud | Contract; legal obligation |
| Route your Inputs to AI model providers and return Outputs | Contract |
| Administer and score AIQ™ assessments and issue Credentials | Contract; where we act as processor, the institution’s basis |
| Detect and investigate assessment integrity violations | Legitimate interests in the validity of Credentials |
| Provide institutional administrators with governance and usage analytics | Contract with the institution; legitimate interests |
| Diagnose faults, monitor performance, and improve the Service | Legitimate interests |
| Produce aggregated, de-identified benchmarks and research | Legitimate interests, using data that no longer identifies you |
| Send service and security notices | Contract; legal obligation |
| Send marketing to business contacts | Legitimate interests, or consent where required |
| Comply with law and respond to lawful requests | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights, and you may object as described in Section 12.
We do not use your Inputs, Outputs, or assessment data to train AI models.
4. Your prompts and our AI model providers
This is the section most people want and most policies bury, so we have written it plainly.
What happens. When you submit an Input, Answerr transmits it through the API of the AI model provider you selected so the model can generate a response.
Model providers are our contracted subprocessors, not independent recipients. They process your content on Answerr’s instructions in order to return a response to you, under the terms Answerr has contracted with each. They do not receive your content for their own independent purposes.
Training. We select providers and contract on terms intended to ensure that content submitted through Answerr is not used to train their models. Answerr does not train its own models on your content either.
What varies between providers. Other data-handling terms differ — in particular retention for abuse monitoring, where some providers offer zero-retention arrangements and others retain content briefly under their own security programs. The position that applies to each provider is maintained in our Trust Center and is available on request.
What we send. Only what is needed to fulfil your request: the prompt, any attached content, and relevant conversation context. We do not attach your name, email address, or institutional identifiers. Requests are associated with a pseudonymous identifier for rate limiting and abuse prevention.
One thing to be clear about. Your content is processed on infrastructure operated by these providers, not solely on Answerr’s own systems. That is how the Service works, and our agreements with them are what protect it.
If your institution has specific requirements about which models may be used or where data may be processed, those are configured at the institutional level. Ask your administrator.
Do not submit protected health information, government-classified material, payment card data, or other people’s confidential information through Inputs.
5. Assessment data, Assessment Results, and AIQ™ Credentials
What AIQ is. AIQ™ is a credential. It attests to how a person works with AI — the judgment, questioning, reasoning, and adaptation they demonstrate in a measured context. It is not an aptitude score and not a measure of general ability.
What we do with assessment responses. Your responses are processed by an automated scoring pipeline that extracts behavioral signals and produces dimension-level results, on the basis of which a Credential is issued. This pipeline uses multiple AI models under the arrangements described in Section 4.
Who sees your results. Where an institution sponsors your assessment, that institution can see your Assessment Result and dimension-level detail, subject to its own policies and to FERPA where applicable. Answerr staff access individual assessment data only to operate the Service, investigate an integrity concern, respond to a support request, or as required by law, under access controls and logging.
Credentials you choose to share. A Credential is verifiable by third parties only through the verification endpoint, and exposes only the fields you elect to make public. You control whether to publish or share it.
What a Credential is not. It is not a consumer report, and Answerr is not a consumer reporting agency, under the Fair Credit Reporting Act. Section 8 of our Terms of Service sets out the limits on how Institutional Customers may use Credentials and Assessment Results.
Automated processing. Assessment Results are produced by automated means. Answerr does not use them to make decisions about you that produce legal or similarly significant effects. Any such decision — hiring, admission, grading, advancement — is made by the institution or employer, not by Answerr, and our Terms require meaningful human review and prohibit use of a Credential as the sole basis for a consequential decision. If you are in the EEA or UK and believe you have been subject to a decision based solely on automated processing, contact the organization that made the decision, and contact us at support@answerr.ai so we can assist. You may also appeal under Section 6(c) of the Terms of Service by emailing support@answerr.ai with “Assessment Appeal” in the subject line.
6. Session monitoring and biometric information
Session monitoring, including camera capture, is disabled by default. It can be enabled only by an Institutional Customer, for its own assessments, at the campaign level.
Where it is enabled:
- You are told before the session begins what is captured, why, how long it is kept, and who can access it.
- You must affirmatively consent before any capture starts. You may decline; declining may mean you cannot complete that particular assessment, and the sponsoring institution — not Answerr — decides whether an alternative is offered.
- Captured session media is retained for 30 days and then permanently deleted, unless retained longer for an open integrity investigation or as required by law.
- Where captured information constitutes biometric data under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, the Washington biometric privacy statute, or similar law, we obtain separate written consent, disclose our retention and destruction schedule before collection, and do not sell, lease, trade, or otherwise profit from that information.
- Automated monitoring signals are indicators, not conclusions. No Credential is revoked on an automated flag alone without human review.
7. Student records and FERPA
Where an educational institution subject to FERPA uses Answerr to process education records and designates us as a “school official” with a “legitimate educational interest” under 34 C.F.R. § 99.31(a)(1)(i)(B), we:
- use those records only to perform the services for which the designation was made, under the institution’s direction;
- do not re-disclose them except as directed by the institution or as permitted by FERPA;
- remain subject to the institution’s direct control with respect to their use and maintenance.
Students: your rights of access, correction, and complaint under FERPA run against your institution, not against Answerr. Contact your registrar or privacy office. We will support your institution in responding.
We do not sell student personal information, do not use it for targeted advertising, and do not use it to build profiles for any purpose other than providing the Service to the institution that provided it. These commitments align with FERPA, applicable state student privacy laws, and our contractual obligations.
8. How we share information
We disclose personal information to the following categories of recipients, and only as described. All of these are contracted service providers or subprocessors acting on our instructions, except where noted.
| Recipient | Purpose |
|---|---|
| AI model providers | To generate Outputs in response to your Inputs, as subprocessors under enterprise agreements. See Section 4. |
| Your institution or employer | Where they provisioned your access: usage, governance, assessment, and Credential data, subject to their policies |
| Cloud hosting and infrastructure providers | To host and operate the Service |
| Payment processors | To process payments and manage subscriptions |
| Analytics, logging, and error monitoring providers | To diagnose faults and monitor performance |
| Email, communications, and support tooling providers | To send service notices, respond to requests, and where permitted, send marketing |
| Professional advisors | Legal, accounting, and audit services, under confidentiality |
| Acquirers | In connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply |
| Authorities | Where required by law, valid legal process, or to protect rights and safety |
A current list naming each subprocessor is maintained in our Trust Center and is available on request. We give Institutional Customers at least 30 days’ notice before adding a subprocessor that processes their Customer Data.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We have not done so in the preceding twelve months.
9. Cookies and tracking
We use cookies and similar technologies in these categories:
- Strictly necessary — authentication, session management, security, load balancing. These cannot be disabled.
- Functional — remembering preferences such as model selection and interface settings.
- Analytics — understanding aggregate product usage to improve the Service.
- Marketing — used only on our public marketing website, never inside the authenticated product or during an assessment.
Where required by law, we ask for consent before setting non-essential cookies, and you can change your choices through the cookie preferences link in our website footer.
Global Privacy Control. We honor the Global Privacy Control (GPC) signal as a valid opt-out of sale and sharing where applicable law requires it. Because we do not sell or share personal information, GPC does not change our practices, but we recognize it.
10. How long we keep things
| Data | Retention |
|---|---|
| Account information | Duration of the account, then 90 days after closure |
| Inputs, Outputs, and conversation history | Until you delete them, or 90 days after account closure |
| Assessment responses | As directed by the sponsoring institution; where we are the controller, for the duration of the account plus 90 days |
| Assessment Results | Retained with the associated Credential record |
| Credential issuance and verification records | As long as necessary to support verification, including at least 3 years after an institution’s subscription ends, unless the holder requests deletion |
| Session media | 30 days, unless subject to an open investigation |
| Billing and tax records | 7 years, as required by law |
| Security and audit logs | 12 months |
| Marketing contact data | Until you unsubscribe, then suppression-list only |
| Aggregated and de-identified data | Indefinitely, in a form that does not identify you |
Institutional Customers may configure shorter retention in their agreement. On termination we delete Customer Data within 90 days, except backups deleted on our ordinary cycle and records we must keep by law.
11. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest, role-based access controls, logging of administrative access, least-privilege internal access, documented internal security policies, vendor security review, and continuous control monitoring.
Answerr maintains a SOC 2 Type II report, examined by an independent CPA firm against the AICPA Trust Services Criteria for Security, Confidentiality, and Availability. Consistent with the report’s restricted-use terms, it is available to customers and prospective customers on request under a non-disclosure agreement. Our compliance posture, policy inventory, and control coverage are published in our Trust Center.
Our security program is also designed to meet the standards of the HIPAA Security Rule. The Service is not, however, offered as a HIPAA-regulated service, and we do not act as a Business Associate absent a signed Business Associate Agreement — see Section 4 on why you should not submit health information through Inputs.
No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you and, where applicable, your institution and the relevant regulator, without undue delay and in accordance with applicable law and our customer agreements. Report a suspected vulnerability to support@answerr.ai with “Security” in the subject line.
12. Your rights
12.1 Everyone
You may ask us to access, correct, delete, or provide a portable copy of personal information we hold about you as a controller, and to restrict or object to certain processing. You may opt out of marketing at any time using the unsubscribe link or by emailing support@answerr.ai.
If your access was provided by an institution, direct your request to that institution. We act on their instructions and will forward any request we receive directly, and tell you we have done so.
12.2 European Economic Area, United Kingdom, and Switzerland
You have the rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your supervisory authority; in the UK, the Information Commissioner’s Office.
12.3 California
You may request to know the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of recipients; to delete; to correct; and to limit the use of sensitive personal information. We do not sell or share personal information, and we do not use sensitive personal information for purposes requiring a limitation right. We will not discriminate against you for exercising any right. You may use an authorized agent with proof of authorization.
12.4 Other U.S. states
If you are a resident of a state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, and others as they take effect — you have comparable rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling.
Appeals. If we decline your request, you may appeal by emailing support@answerr.ai with “Privacy Appeal” in the subject line. We will respond in writing within 45 days with our decision and reasoning. If we deny the appeal, we will tell you how to contact your state attorney general.
12.5 How to make a request and how long we take
Email support@answerr.ai with “Privacy Request” in the subject line. We will verify your identity before acting, which usually means confirming control of the email address on the account and, for sensitive requests, additional verification. We respond within 45 days for U.S. state law requests, extendable once by 45 days with notice, and within one month for GDPR and UK GDPR requests, extendable by two months for complex requests with notice.
13. International transfers
We are based in the United States and process data there. If you access the Service from outside the U.S., your information will be transferred to and processed in the United States and in other countries where our subprocessors operate.
For transfers of personal data from the EEA, UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss addendum where applicable, supplemented by additional safeguards where required. You may request a copy of the relevant transfer mechanism by emailing support@answerr.ai.
14. Children
The Service is intended for users aged 16 and over. It is not directed to children under 13, and we do not knowingly collect personal information from them. Institutions must not provision accounts for individuals under 16 without a separate written agreement addressing applicable children’s privacy law. If you believe a child has provided us with personal information, contact support@answerr.ai and we will delete it.
15. Third-party links
The Service may link to third-party websites and services we do not control, including AI model providers’ own sites and LMS platforms. This policy does not cover them. Review their policies.
16. Changes to this policy
We may update this policy. For material changes, we will give at least 30 days’ notice by email or in-product notice before the change takes effect, and update the date at the top. Continued use after the effective date means you accept the updated policy. For Institutional Customers with a signed agreement, changes here do not modify negotiated terms during the term.
17. Contact
Answer Labs Inc. (Answerr™), 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, Delaware, USA.
All correspondence: support@answerr.ai
To help us route your message and meet our response deadlines, please use one of these subject lines:
| If your message concerns… | Use the subject line… |
|---|---|
| A privacy or data rights request | Privacy Request |
| A privacy request we have declined | Privacy Appeal |
| A security vulnerability or suspected breach | Security |
| An Assessment Result or Credential decision | Assessment Appeal |
| An accessibility barrier | Accessibility |
| Legal notices | Legal |
Trust Center: https://trust.inc/org_6908e3c1fe011d5b10bca425
