Back to Home

DRAFT — pending legal review, not legal advice.

This document is a starting template. It has not been reviewed by a licensed attorney and does not constitute legal advice.

Privacy Policy

Last updated: 2026-09-20

Vanguard SIM (“Vanguard SIM,” “we,” “us”) respects the privacy of the institutions, instructors, and students who use the Vanguard SIM platform (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have. Our handling of student education records is further governed by our FERPA Statement and Data Processing Agreement.

1. Information We Collect

We collect the minimum information needed to operate the Service:

  • Account information: name, institutional email address, and authentication credentials (hashed passwords, or SSO / LTI identifiers issued by the institution).
  • Course-scoped submissions: simulation responses, team artifacts, free-text answers, and scoring events generated during a course offering.
  • LLM interactions: prompts and outputs exchanged with the large-language-model subprocessor (Anthropic) as part of simulation gameplay, feedback, or grading assistance.
  • Technical logs: IP address, browser and device metadata, timestamps, and error traces, used for security, abuse prevention, and debugging.
  • Contact-form inquiries: information you voluntarily provide when you contact us (name, institution, message).

We do not knowingly collect government-issued IDs, financial account numbers, health information, or biometric identifiers. We do not use advertising cookies or third-party tracking pixels.

2. How We Use Information

  • To authenticate users and provide the Service.
  • To score simulation responses, deliver AI-generated feedback, and pass grades back to the institution’s LMS.
  • To operate, secure, monitor, and improve the Service, including debugging and rate-limit enforcement.
  • To communicate about the Service (transactional messages, security notices, service announcements).
  • To generate de-identified, aggregated statistics used for product research and marketing benchmarks. Aggregated data does not identify any individual or institution.
  • To comply with legal obligations and to enforce our Terms of Service.

We do not sell personal information and we do not use student submissions to train foundation models.

3. Who We Share Information With

We share information only with the following categories of recipients, in each case under a written agreement that restricts use to what is needed to provide the Service:

  • Anthropic, PBC— provider of the LLM used to generate simulation feedback and grading assistance. Prompts and outputs are processed via Anthropic’s API and are not used by Anthropic to train models under its zero-data-retention API terms.
  • Supabase, Inc.— database, authentication, and file storage provider. Data is stored in Supabase’s U.S. regions with encryption at rest and row-level security.
  • Vercel, Inc. — hosting and edge-serving of the web application.
  • Stripe, Inc. (if used) — payment processing for institutional or seat purchases.
  • LTI 1.3 platforms operated by the enrolling institution (e.g. Canvas, Blackboard, Moodle) — grade passback and roster provisioning under the institution’s control.
  • Contact-form transport — an email delivery provider that carries contact-form inquiries to Vanguard SIM.

We may also disclose information (a) with the institution or user at their direction, (b) to comply with valid legal process, or (c) to protect the safety, rights, or property of Vanguard SIM or others. We do not share personal information with third parties for their own marketing.

4. Retention

Student submissions, scoring events, and LLM interactions are retained for twenty-four (24) months after the end of the course offering, unless the institution requests earlier deletion or longer retention in writing. Authentication accounts are retained while the user is enrolled at a subscribing institution and are purged within thirty (30) days after termination. Technical logs are retained for up to twelve (12) months. Aggregated, de-identified data may be retained indefinitely.

5. Security

We protect personal information with administrative, technical, and physical safeguards proportionate to the sensitivity of the data, including TLS 1.2+ in transit, AES-256 at rest (via Supabase), row-level security on every application table, an access allowlist for administrative operations, hashed password storage, and audit logging of privileged actions. No system is perfectly secure; users should protect their credentials and report suspected incidents to the address in Section 10.

6. Your Rights

Subject to applicable law and the institution’s custody of education records, you may:

  • Request access to the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your information, subject to legitimate retention needs and the institution’s record-keeping obligations.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a supervisory authority in your jurisdiction.

Students whose data is held as part of an institutional course should first contact the enrolling institution, which acts as the controller for those records. Vanguard SIM will support the institution’s response.

7. Children’s Privacy

The Service is intended for use by college-age learners and faculty. Accounts require users to be at least thirteen (13) years of age, and account creation on the public site requires users to be at least eighteen (18). We do not knowingly collect information from children under thirteen (13), and the U.S. Children’s Online Privacy Protection Act (COPPA) does not apply to our typical user population. If you believe a child under thirteen has provided information to the Service, contact us and we will delete it promptly.

8. GDPR (EU / UK / EEA Users)

Where the EU General Data Protection Regulation (GDPR) or the UK GDPR applies, Vanguard SIM acts as a “processor” for student and course data on behalf of the institution (“controller”), and as a “controller” for our own business contacts and website visitors. Our lawful bases are: (a) performance of a contract with the institution or user, (b) our legitimate interests in operating and securing the Service, and (c) consent, where required.

International transfers to U.S.-based subprocessors are covered by the European Commission’s Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

You may exercise your GDPR rights using the contact address below. Institutional customers who need a signed EU Standard Contractual Clauses addendum should request one through their order form.

9. CCPA / CPRA (California Users)

Under the California Consumer Privacy Act (CCPA), as amended by the CPRA, California residents have the right to know what personal information we collect, to request deletion or correction, to opt out of “sale” or “sharing” of personal information for cross-context behavioral advertising, and to limit use of sensitive personal information.

Vanguard SIM does not “sell” personal information or “share” it for cross-context behavioral advertising as those terms are defined by the CCPA. To exercise a California right, contact us using the address in Section 10. We do not discriminate against users who exercise their privacy rights.

10. Contact

Privacy inquiries should be sent to privacy@vanguardsim.com. We will acknowledge receipt within a reasonable period and respond within the time frames required by applicable law.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced through the Service or by email at least thirty (30) days before they take effect.