Privacy

Last updated August 9, 2026.

What this page covers

Sci-AI is UC Merced's research-practice platform. This policy describes the personal data the platform collects about you — when you create an account, when you practice, and when you connect an external AI tool (Claude, ChatGPT, or a custom OpenAI GPT) — how that data is used, which service providers process it, and how you can inspect or delete it.

Account and identity data

When you register or sign in, we store what's needed to run your account:

To confirm your email we send a one-time verification link (valid for 24 hours); we store only a hashed form of that link's token, not the link itself.

Practice and learning data

As you use the practice tools and prelab activities, we record your study activity:

AI processing of your practice

When you submit a written (free-response) practice answer, that answer — up to about 4,000 characters — is sent, together with the question and a reference answer, to Anthropic's Claude API, which grades it and returns personalized grading feedback. We store the resulting grade and feedback in your review log. We send only your answer and the question context — not your name, email, or a chat transcript.

When you finish a class-attributed retrieval session, Sci-AI also creates a whole-session assessment automatically. A factual version is produced on our server from the recorded grading. We then send bounded excerpts of the session's questions, your answers, reference answers, recorded outcomes, and feedback to Anthropic's Claude API so it can improve the wording of that assessment. Claude is instructed to summarize the recorded grading, not re-grade your work. We do not send your name, email, user ID, or class identity. If Claude is unavailable, the server-produced assessment remains in use.

An authorized instructor or administrator can also deliberately generate a briefing for one lesson from the strictly incorrect answers visible in their Retrieval progress view. For that request, Sci-AI sends Claude the students' display names and usernames, the applicable class, the exact question wording, and the submitted incorrect answers. The briefing may name individual students so staff can identify who needs a particular intervention. It is shown only to the requesting staff member and is not saved by Sci-AI.

Staff may separately generate a briefing from the lesson-specific topics recorded by the prelab tutor. That request contains the topic statements, their categories, and affected- student counts, but no student names, usernames, emails, or IDs. This briefing is also request-time only and is not saved by Sci-AI.

Separately, we may send the extracted text of public course Student Guides to Claude to determine the order in which lab-resource cards should appear. This lesson-flow analysis contains course material only: it does not include student answers, account details, activity, or other student data. The result is cached before students open the lab page.

What a connected AI tool writes to our database

Separately, when you authorize an external AI tool (Claude, ChatGPT, or a custom OpenAI GPT) to connect to Sci-AI, that tool can call a small set of write actions on your behalf. Each call creates a row in one of two tables:

Each row is linked to your user account and to the specific AI app (OAuth grant) that wrote it, so you can revoke one app without affecting others.

Personal information is scrubbed before your notes are stored

Before anything written back by a connected AI tool is saved — a session summary, and also your mind map, personalization notes, learning style and struggles — the server runs a redactor that replaces likely personal information with placeholder markers. It runs on every route that can write those columns, so the four note sections that appear on your shareable profile link are covered no matter which one wrote them. Patterns currently scrubbed:

We do not keep a pre-scrub copy. There is also a hard size cap (~4 KB) on the summary text and (~16 KB) on the structured note; anything longer is truncated before storage. Note that the redactor is a best-effort defense, not a guarantee — if you type sensitive information to an AI tool in an unusual format, it may not be recognized. Don't paste secrets into AI chats.

What a connected AI tool does not store

Cookies and sessions

We use only first-party, functional cookies. There are no analytics, advertising, or third-party tracking cookies, and no tracking pixels.

IP addresses

We never store your raw IP address. To prevent abuse (rate-limiting sign-in attempts) and for the audit trail when you authorize an AI app, your IP is first put through a salted, one-way hash. When you authorize an AI app we also record the browser's user-agent string alongside that hashed IP, as part of the consent record.

Third parties who process your data

We rely on a small set of service providers to run the platform. Each receives only what it needs for its function:

We do not sell your data or share it with advertisers. If you connect Claude or ChatGPT, the conversation itself happens on that service under its own privacy policy (see below).

How long we keep it

Your rights (and how to use them today)

You can exercise all of the following at any time — email the Sci-AI maintainers (see Contact below) and we'll action it:

Who can see this data

We do not sell this data, share it with advertisers, or pass it to any third party for marketing purposes.

What the external AI service stores

When you use Claude, ChatGPT, or a Custom GPT, that service has its own data-handling policies separate from Sci-AI. The Sci-AI integration only governs what is written back to Sci-AI's database. For what the AI service itself stores about your chat history, see Anthropic's or OpenAI's respective privacy policies.

FERPA

Information Sci-AI keeps about you as a student — including your practice records and the data AI tools you authorize write back — is part of your educational record under FERPA. On request to the Sci-AI maintainers (see Contact below), the download and delete of your data are intended to satisfy the FERPA inspection and amendment rights without requiring a formal request.

Contact

Questions, concerns, or requests about your data: email tle271@ucmerced.edu.

← Back to home