Privacy / implemented behavior

Enough memory to survive a crash. Not a permanent student file.

ExoInquiry stores pseudonymous classroom progress so a student can rejoin during an eight-week course and a teacher can notice a quiet support need. It does not ask students for names, email addresses, prose, or audio.

Stored online

Class and progress records

  • Class code, teacher-key hash, anonymous teacher-browser owner hash, class label, mode, and expiry time
  • No pilot invitation, teacher email, teacher password, or teacher account is required. Legacy invitation hashes remain only until their scheduled deletion.
  • Student number within the class roster, anonymous role, join and interaction times
  • Mission opens, fixed-choice attempts and selected options, completion, teacher plan-review status, and saved lab state
  • Optional private teacher-help messages, help-request and resolution times, and whether a teacher has paused or restored a student station
  • Required fixed-choice Python-reading attempts and outcome; optional one-line practice stores only attempt count and outcome, not incorrect code text
  • Deterministic science result, integrity hash, and fixed-choice pilot feedback

Not requested

Direct identity and free response

  • No student name, email address, school ID, or account
  • No essay, typed reflection, recorded voice, or camera upload
  • No cursor, keystroke, screen, camera, microphone, or idle-behavior recording; the optional help box stores only the message the student deliberately sends
  • No public display of who receives a private teacher check-in
  • No claim that a student number is anonymous if a teacher keeps a separate roster

Automatic deletion

A fixed window, enforced every day.

A course class code remains open for 120 days after creation. Its progress is retained for a further 30-day teacher export window, then deleted automatically. A self-guided test expires after 7 days.

The deletion job runs at 03:17 UTC daily. It removes the class records whose export window has ended, including mission progress, private question-attempt history, private support messages, student run state, pilot feedback, and expired legacy teacher-entitlement hashes. The teacher dashboard shows the expiry and provides a full JSON export before deletion.

Before a school pilot

School review still matters.

A school should have a qualified privacy or legal reviewer confirm that this implementation and its classroom procedures meet local requirements before week one.