Published document

Experimental practice alpha — privacy notice

Version
privacy-alpha-2026-09-06-1
SHA-256
de56321d4780930479cbe3aa1c271046b2aaacd73b6cbb5ee7e5a7be938d2768

This is the exact text the practice service asks you to accept. The version identifier and digest above are recorded with every acceptance. See also the terms of use.

Who this covers and who we are

This notice explains what personal data the operator of virtualreality.education ("we") collects when you use the experimental practice alpha, why, how long we keep it, and what you can do about it. It covers the public website, the request form, and the authenticated practice application. It applies to adults only; we do not knowingly collect data from anyone under 18.

What we collect and why

a) Public website. The website is static. It does not set tracking cookies, does not load third-party analytics, and does not fingerprint your device. Our hosting provider's ordinary connection logs (IP address, requested page, time, browser type) are used only to operate and secure the site.

b) Request form. When you submit a request for a practice experience you give us the task you describe, the kind of organization and audience it is for, the evidence you would need to see, an optional contact email, organization and name, and the version identifiers of the terms and privacy notice you accepted. We store this so that we can consider, build and report on requested experiences and, if you supplied contact details, so that we can answer you. The receipt you are shown is the only key to your request; we store a one-way digest of it, not the receipt itself. We keep the connecting IP address in memory only for a short time to limit abuse; it is not written to the request record.

c) Practice account. Access to the practice application uses an opaque credential issued to you. We store a one-way digest of the credential, its purpose, expiry and revocation state, the version identifiers and content hashes of the terms and privacy notice you accepted with the time of acceptance, and the eligibility assertions (that you are an adult and that you accepted the policies) recorded when the credential was issued. We do not store passwords in this alpha. We do not store your name or email with the credential unless you provide them through the request form.

d) Practice sessions and records. When you start a session we allocate a streaming worker and record the session lifecycle (requested, admitted, connecting, interactive, ended, and the reasons for each transition), the identifiers of the experience and build you used, and the practice record: the ordered semantic actions you performed (for example "select contact", "apply solder"), the observed state changes, timestamps, and the advisory result and completion reason produced by the simulation. Video is streamed to your browser and is not recorded or stored. Your mouse and keyboard input is interpreted by the simulation on the server; only the resulting semantic actions and observations are stored. These records exist so that you can review what happened, and so that we can check that the simulation behaved as designed. They are advisory rehearsal records; they are not assessments and are never used to grade or certify you.

e) Anonymous sampler. If we offer an anonymous try-out session, it collects operational telemetry only (whether the stream started, timing, failures). It creates no practice record and no account.

f) Operational telemetry. For every session and request we record timing, capacity, errors, streaming statistics and the cost of the underlying infrastructure. These measurements are tied to session and request identifiers, not to your name, and are used to operate, size and improve the service and to report on it in de-identified form.

Where processing happens

The practice application and its database run on servers we operate. Each practice session runs on a GPU worker leased for that session from a compute marketplace provider; the worker receives the experience build and your session's input, streams video back to you, and is destroyed when the session ends. Streaming may pass through a relay server we operate. Your practice record is written to our database, not kept on the worker. We do not sell personal data and do not share it with advertisers.

Cookies and local storage

The practice application sets one HttpOnly, same-site session cookie that holds no personal data and exists only to authenticate your browser to your account. The public website sets no cookies. The practice page may keep a session identifier in your browser tab so that a page reload can recover an interrupted session; it holds no credential.

How long we keep data

Practice records (sessions, actions, observations, summaries): 30 days from the last event, unless you delete them earlier.

Requests: 90 days from submission. If you cancel a request, any contact details in it are deleted immediately and the rest is deleted 7 days later.

Credentials: until they expire or are revoked; revoked and expired credentials are removed within 7 days.

Acceptance records (which policy versions you accepted and when): for as long as the associated credential or request exists.

Operational telemetry and infrastructure cost records: retained in de-identified form.

Backups: encrypted backups of the database follow the same retention and are overwritten on the same schedule, with at most 7 additional days for backup rotation.

Your rights and controls

You can, at any time and without asking us: read every practice record we hold for your account; export a record as a machine-readable file; delete a record; and cancel a request using its receipt. These controls are built into the practice application and the receipt page and do not require an email. Depending on where you live you may also have rights to access, rectification, erasure, restriction, portability and objection, and to complain to a supervisory authority; you can exercise them by submitting a "question about terms or privacy" request through the request form, and the receipt page shows the status of that request. We will verify that a request concerns your own records before acting on it.

Security

Credentials are stored as one-way digests; the application accepts only its exact configured origin; browser and worker credentials are separate and short-lived; the public site never stores learner data; and workers are destroyed after each session. No system is perfectly secure; if we learn of a breach affecting your data we will act under our incident procedure and notify affected people as the law requires.

Children

The alpha is for adults. If you believe a person under 18 has used it, tell us through the request form and we will delete the records.

Changes

When this notice changes we publish a new version identifier and content hash. You will be asked to accept the new version before starting a new session or submitting a new request. Earlier versions remain available on request so that you can see the text you accepted.

About this document

This notice describes the actual behaviour of the alpha software as deployed and was prepared by the operating team. It has not been reviewed by a lawyer. Version privacy-alpha-2026-09-06-1.