DATA PROTECTION & STUDENT PRIVACY

Student & School Privacy Policy

How QuestAI Study and QuestAI Core protect student identity, coursework, and intellectual property with commercial-grade AI boundaries, fail-closed safety, and transparent Australian Privacy Principles (APP) compliance.

Updated: September 2026 · Version 3.2 Australian Privacy Principles (APPs / OAIC) Enterprise Paid Gemini API Fail-Closed AI Gateway

1. Our Fundamental Privacy Commitments

QuestAI Study is engineered specifically for secondary and senior school learning environments. We ensure schools, educators, and students maintain sovereign control and strict ownership over their educational data under the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs).

Commercial AI Protection

AI requests are routed via approved providers under strict privacy controls (such as Google Cloud Gemini API paid projects). Prompts and responses are not used by Google to improve its products or train foundational models.

100% Student & School IP

Students and enrolled schools retain absolute ownership of all notes, drafts, task sheets, proofs, and uploaded evidence files.

Multi-Tenant Isolation

Every school's records, assessments, and classes are logically segregated with database-enforced row and schema security.

2. Categories of Information Processed

Data Category Examples Purpose & Lawful Basis Standard Retention Lifecycle
Identity & Authentication School email address, student name, Authentik SSO ID, academic role, year level (Years 7–12) Authentication, role authorization, grade-appropriate syllabus scoping Active school enrolment; purged within 14 business days of withdrawal
Learning Progress & Mastery Topic revision status, formative question checks, spaced repetition intervals, mastery scores Adaptive daily study plans, timetable sprint scheduling, spaced retention cues Duration of active academic enrolment; exportable upon request
Coursework & Student Drafts Working drafts, DOCX files, revision notes, math scaffolds, evidence uploads Personal writing workspace, draft versioning, formative teacher reviews Governed by school policy; exportable on demand or permanently purged within 14 business days of account deletion
AI Study Interactions Formative prompt inquiries, Feynman explanation breakdowns, curriculum source lookups Real-time formative study assistance and concept clarification Processed transiently with student identifiers stripped; security audit telemetry retained up to 30 days

3. QuestAI Core Gateway Architecture & AI Retention Boundaries

QuestAI operates an internal, hardened AI orchestration gateway (QuestAI Core) that isolates the frontend application from upstream AI providers, manages upstream credentials, sanitises request payloads, and enforces data protection policies:

QuestAI Data & AI Gateway Flow:
QuestAI Study (UI / App)
    │
    ▼
QuestAI Core (Internal AI Gateway)
    ├── Request sanitisation & student identifier stripping
    ├── Provider eligibility & safety policy checks
    ├── Virtual API key validation & tenant rate-limiting
    └── Intelligent routing & fail-closed protection
    │
    ▼
Approved AI Provider (Paid Gemini API in Google AI Studio / OpenRouter Enterprise)

Accurate AI Retention & Google AI Studio (Gemini API) Terms

QuestAI Core uses approved AI providers under provider-specific privacy and retention controls. For paid Gemini API projects (configured via Google AI Studio with billing enabled):

  • No Product Improvement or Training: Prompts, grounded curriculum context, and generated responses are not used by Google to improve its products or train models. (Note: Paid API status in Google AI Studio is derived from project billing configuration, distinct from consumer Google AI Pro web subscriptions).
  • Configured Project Retention: Where provider-side logging or temporary storage is enabled for operational, safety, abuse prevention, or debugging purposes, retention is restricted according to the configured project settings (e.g. 7, 14, 28, or 55 days) and applicable provider terms.
  • Stateless & Minimal Transmission: QuestAI Core minimizes data transmission by using stateless Generate Content requests, avoiding student personal identifiers in prompts, and enabling store=false where supported.
Fail-Closed Privacy Architecture

If primary approved enterprise providers experience an outage, QuestAI Core fails closed. Requests return a temporary unavailable status rather than routing student data to unapproved, non-compliant, or consumer-tier models.

Server-Side Virtual Keys

Browser clients never interact directly with upstream AI providers or receive raw API keys. All calls are mediated by server-side workers with payload sanitization and strict token limits.

4. Overseas Data Disclosures & Cloud Infrastructure (APP 8)

In accordance with Australian Privacy Principle 8 (Cross-border disclosure of personal information), we disclose that QuestAI utilizes enterprise cloud infrastructure and verified AI processing providers located in:

  • Australia (Primary Hosting & Database): Primary relational databases, student records, authentications, and application servers are hosted within Australian data centre regions.
  • United States & Australia (Enterprise AI Inference): Automated AI study guide generation and formative question evaluations are processed through enterprise cloud infrastructure located in Australia and the United States (e.g. Google Cloud Enterprise API).

All cross-border data transmissions are encrypted using TLS 1.2 / TLS 1.3 and governed by commercial data protection terms ensuring privacy standards equivalent to the Australian Privacy Principles.

5. Advertising, Cookies & Web Storage Policy

We enforce a complete separation between public informational web pages and authenticated student learning areas:

Authenticated Student & School Areas

100% Ad-Free & Zero Commercial Tracking. Logged-in student accounts, school workspaces, coursework, submissions, and AI study prompts are never sold, rented, leased, or used to build behavioral advertising profiles or serve ads.

Public Informational Pages

Public, non-authenticated website areas (e.g. public overviews and articles) may display non-personalized or contextual advertising (such as Google AdSense) and standard anonymous web analytics, subject to cookie consent choices.

Cookies & Local Storage: Authenticated areas use strictly necessary session cookies and local browser storage (for offline study preferences and draft saves). Third-party advertising cookies are never loaded in authenticated student zones.

6. Student & Parental Rights, Portability & Deletion

Under the Australian Privacy Principles (APPs) and applicable school guidelines, students and their authorized guardians have the right to:

  • Access & Portability: Export personal notes, drafting records, and revision progress in open formats (DOCX, JSON, PDF) at any time.
  • Correction: Request updates or corrections to personal profile details and subject enrolments via self-service or school administration.
  • Permanent Deletion: Request account deactivation and complete data purging. Coursework and account records are removed from active databases immediately upon request and permanently purged from backup archives within 14 business days.

7. Privacy Complaints & Dispute Resolution (APP 1.4)

If you believe QuestAI has breached the Australian Privacy Principles or mishandled your personal information, you may lodge a formal complaint following our step-by-step resolution process:

  1. Step 1 · Lodge Complaint: Email our Privacy Officer at privacy@questai.com.au (or contact your school's appointed Data Protection Officer). Please specify the nature of the breach, date of occurrence, and affected account details.
  2. Step 2 · Formal Acknowledgement: We will confirm receipt of your complaint in writing within 5 business days and initiate a technical audit.
  3. Step 3 · Investigation & Resolution: Our security and privacy team will conduct a comprehensive review and provide a formal written resolution and remediation plan within 30 calendar days.
  4. Step 4 · External Regulatory Escalation: If you are dissatisfied with our response, you have the right to escalate your complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001.