DRAFT — pending legal review, not legal advice.
This document is a starting template. It has not been reviewed by a licensed attorney and does not constitute legal advice.
Last updated: 2026-09-20
Vanguard SIM (“Vanguard SIM,” “we,” “us”) respects the privacy of the institutions, instructors, and students who use the Vanguard SIM platform (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have. Our handling of student education records is further governed by our FERPA Statement and Data Processing Agreement.
We collect the minimum information needed to operate the Service:
We do not knowingly collect government-issued IDs, financial account numbers, health information, or biometric identifiers. We do not use advertising cookies or third-party tracking pixels.
We do not sell personal information and we do not use student submissions to train foundation models.
We share information only with the following categories of recipients, in each case under a written agreement that restricts use to what is needed to provide the Service:
We may also disclose information (a) with the institution or user at their direction, (b) to comply with valid legal process, or (c) to protect the safety, rights, or property of Vanguard SIM or others. We do not share personal information with third parties for their own marketing.
Student submissions, scoring events, and LLM interactions are retained for twenty-four (24) months after the end of the course offering, unless the institution requests earlier deletion or longer retention in writing. Authentication accounts are retained while the user is enrolled at a subscribing institution and are purged within thirty (30) days after termination. Technical logs are retained for up to twelve (12) months. Aggregated, de-identified data may be retained indefinitely.
We protect personal information with administrative, technical, and physical safeguards proportionate to the sensitivity of the data, including TLS 1.2+ in transit, AES-256 at rest (via Supabase), row-level security on every application table, an access allowlist for administrative operations, hashed password storage, and audit logging of privileged actions. No system is perfectly secure; users should protect their credentials and report suspected incidents to the address in Section 10.
Subject to applicable law and the institution’s custody of education records, you may:
Students whose data is held as part of an institutional course should first contact the enrolling institution, which acts as the controller for those records. Vanguard SIM will support the institution’s response.
The Service is intended for use by college-age learners and faculty. Accounts require users to be at least thirteen (13) years of age, and account creation on the public site requires users to be at least eighteen (18). We do not knowingly collect information from children under thirteen (13), and the U.S. Children’s Online Privacy Protection Act (COPPA) does not apply to our typical user population. If you believe a child under thirteen has provided information to the Service, contact us and we will delete it promptly.
Where the EU General Data Protection Regulation (GDPR) or the UK GDPR applies, Vanguard SIM acts as a “processor” for student and course data on behalf of the institution (“controller”), and as a “controller” for our own business contacts and website visitors. Our lawful bases are: (a) performance of a contract with the institution or user, (b) our legitimate interests in operating and securing the Service, and (c) consent, where required.
International transfers to U.S.-based subprocessors are covered by the European Commission’s Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
You may exercise your GDPR rights using the contact address below. Institutional customers who need a signed EU Standard Contractual Clauses addendum should request one through their order form.
Under the California Consumer Privacy Act (CCPA), as amended by the CPRA, California residents have the right to know what personal information we collect, to request deletion or correction, to opt out of “sale” or “sharing” of personal information for cross-context behavioral advertising, and to limit use of sensitive personal information.
Vanguard SIM does not “sell” personal information or “share” it for cross-context behavioral advertising as those terms are defined by the CCPA. To exercise a California right, contact us using the address in Section 10. We do not discriminate against users who exercise their privacy rights.
Privacy inquiries should be sent to privacy@vanguardsim.com. We will acknowledge receipt within a reasonable period and respond within the time frames required by applicable law.
We may update this Privacy Policy from time to time. Material changes will be announced through the Service or by email at least thirty (30) days before they take effect.