Skip to main content

Privacy notice · pilot version 1.0

Your Hub account, learning record, and private evidence

This notice describes the system that is implemented now. It does not replace the final POPIA policy approval required before a real cohort, public portfolio, research programme, or under-18 pathway starts.

Last updated 28 July 2026 · Internal protected pilot

What the Hub stores

  • • An opaque Hub learner identifier and, when sponsored, the cohort role confirmed by the server.
  • • Bounded lesson observations, checkpoints, setup choices, and evidence states needed to resume and route learning.
  • • Private proof metadata, reviewer decisions, and an append-only history that separates V0, V1, and V2 evidence.
  • • Private evidence files that you explicitly upload. The current artifact rule records a 24-month retention date unless an approved request or policy requires earlier deletion.

The Hub does not store your Soruno password. The browser receives a rotated HttpOnly session after a single-use link code is exchanged.

Why it is used

Essential learning state supports secure access, saved work, feedback, recovery, proof review, privacy requests, and aggregate cohort operations. Optional product analytics and research use are separate choices, off by default, and are not required for core lessons.

The accountable South African privacy owner must approve lawful basis, the full retention schedule, minors rules, incident response, and public-proof conditions before a real cohort. Until then, this deployment remains a protected pilot and public publication is not enabled.

Who can access it

  • • Learners can access their own records and private files.
  • • Active facilitators or reviewers can access only the evidence in their confirmed cohort and only when its review scope permits.
  • • Funders receive bounded cohort aggregates, not learner files, contact details, or private artifacts.
  • • V0 is private unverified evidence, V1 passed Hub automatic checks, and V2 records an authorised human review. None of these tiers is a mastery, employment, or certification decision.

Device-only and offline work

A browser may keep bounded recovery data for the current learner scope. Credentials, proof binaries, and sensitive free text are denied from the offline outbox. Account changes quarantine unsent work under the original scope; the Hub does not silently reassign it to a different learner.

Your choices and rights

Settings provides a direct export, optional-data choices, unlink, and requests for access, correction, deletion, restriction, objection, or another export. A request receipt confirms intake; it is not a promise that deletion has already completed. Approved policy must define fulfilment, lawful exceptions, timing, appeal, backups, and the closure notice before real-cohort use.

You can complain to the Information Regulator of South Africa, and you don't need us to agree first.

Under-18 and public-proof boundary

No under-18, guardian-consent, or public-portfolio pathway is approved in this pilot. Do not enrol minors or publish learner evidence until the accountable owner approves those rules and the complete journey is verified.