This notice explains how Cyamate, Inc. (“Cyamate,” “we,” “us,” or “our”) handles personal information when you use Cyamate, a conversational assessment tool for coursework (the “Service”).
Your instructor arranged for the Service to be used in your course, decides how it is used there, and gave us your email address so we could send you an invitation. If you have questions about this notice, email stephen@cyamate.com or call +1 (839) 293-2058.
Summary of key points
- What we collect
- Your first and last name, your email address, and the transcript of each spoken assessment you complete. We do not collect dates of birth, student IDs, or payment information.
- What happens during an assessment
- Your instructor assigns a set of questions, and you answer them in a spoken conversation with a conversational agent. Audio is processed in real time and is not stored. The transcript is saved, and you and your instructor can both read it.
- The completeness check
- After each conversation, an automated check determines whether the questions were covered and whether the session ended early, so that a session cut short by a technical problem is not marked complete. The result is not a grade, and instructors can override it.
- No grades
- Cyamate does not assign grades or calculate scores. Grading is done by your instructor, and your official academic record remains with your institution.
- AI
- Artificial intelligence conducts the spoken conversation and runs the completeness check. Your data is not used to train AI models.
- No sale, no ads, no tracking
- We do not sell personal information, show advertising, run analytics, or track you.
1. What information do we process?
When your instructor invites you
- Your email address, which your instructor enters to send you the invitation
When you create your account
- Your first and last name
- A password, which is held by AWS Cognito and is never visible to Cyamate
When you complete an assessment
- Your spoken responses, processed as you speak
- The transcript of the conversation. The agent greets you by your first name, so every transcript contains it, along with anything else said aloud.
From instructors
- Assignment questions, notes, and settings
- Course material, either uploaded in the lesson builder or emailed to us to upload on the instructor’s behalf
We also keep internal identifiers for your account, your course, and each assignment and conversation, so that these records can be linked together. We do not collect dates of birth, student ID or SIS numbers, payment information, or government identifiers.
2. Your records
Cyamate is engaged by your instructor rather than by your institution. Your instructor asked us to provide the Service for their course, and they decide how it is used there. The Service is used in higher-education courses and is not directed to children under 13.
We treat your account information and your transcripts as part of your education record. We use them only to provide the Service for your course, at your instructor’s direction. We do not disclose them except as described in section 4, and we do not use them for any other purpose.
Where an institution designates Cyamate a “school official” under the Family Educational Rights and Privacy Act (FERPA), we perform that function at the institution’s direction and use education records only as described in this notice.
For your official academic record and your grades, contact your institution. Cyamate does not hold them.
3. How do we process your information?
- To deliver your instructor’s assignment as a spoken conversation and save the transcript, where you and your instructor can read it.
- To run the completeness check and set the status of your submission, which you and your instructor can both see, and which your instructor can dismiss.
- To let instructors draft lessons from course material they upload. No student information is involved, and the instructor edits, accepts, or discards the draft.
- To create accounts and to send invitation and password-recovery email.
- To keep the Service running and secure.
We do not use personal information for marketing, advertising, analytics, or profiling, and we do not use it to train artificial intelligence models.
4. Who processes your information on our behalf?
We use three service providers.
Amazon Web Services (AWS). The application, its database, and its accounts run in our AWS environment in the United States. Names, email addresses, and passwords are held in AWS Cognito, which also sends account email. Transcripts and course records are held in our database.
ElevenLabs. Our conversational voice provider. During an assessment, audio flows directly between your browser and ElevenLabs over an encrypted real-time connection. ElevenLabs receives the assignment’s questions and material, along with your first name, which the agent uses to greet you. It does not receive your last name or your email address. The conversation itself is conducted by a model from Google, which processes conversation data on ElevenLabs’ behalf under the same terms. Call audio is not stored. Transcripts held on the ElevenLabs side, and personal information derived from them, are deleted after 90 days. Course material an instructor selects is kept in a knowledge base scoped to that course, so the agent can ask about the actual course content. Under our agreement with ElevenLabs, your data is not used to train models.
Anthropic. Anthropic’s Claude model runs the completeness check and drafts lessons. Under Anthropic’s commercial terms, data sent to it is not used to train models and is deleted within 30 days, except where Anthropic must keep it longer to enforce its usage policies or to comply with the law.
No other third party receives personal information, except where the law requires it or in connection with a business transfer such as a merger or acquisition, in which case this notice would continue to apply to information already collected.
5. How long do we keep your information?
| Data | Retention |
|---|---|
| Voice audio | Never stored, by us or by ElevenLabs. Streamed for processing only. |
| Transcripts held by ElevenLabs | Deleted after 90 days, along with personal information derived from them. |
| Your transcripts and submission status | Kept in your account until you or your instructor asks us to delete them. |
| Your account details (name, email address) | Kept until deletion is requested. This includes invitations that were never accepted. |
| Data sent to Anthropic | Deleted by Anthropic within 30 days under its commercial terms. |
| Course material uploaded for lesson drafting | Deleted from our storage one day after upload. |
| Course material in the ElevenLabs knowledge base | Kept for the life of the course. |
| Instructor questions and course configuration | Kept for the life of the course. |
| Failed processing jobs | Held at most 14 days in a holding queue so that a failure can be retried, then deleted automatically. May contain a transcript. |
| Operational logs | Identifiers and error information. Kept 30 days. |
| Email you send us | Kept as ordinary correspondence. |
To have your account and your transcripts deleted, email stephen@cyamate.com or ask your instructor. We delete them promptly from our own systems and from ElevenLabs. Data already sent to Anthropic is deleted by Anthropic within 30 days, as described above.
6. Cookies and browser storage
Signing in stores an authentication token in your browser so that you stay signed in. The sign-in page sets session cookies to complete the sign-in itself, and the application sets one cookie that remembers whether the sidebar is expanded. Work you have not saved yet, such as a draft assignment, is kept in your browser until you save it. We set no advertising or analytics cookies, and the Service contains no third-party trackers.
7. How do we keep your information safe?
The Service runs in our AWS environment in the United States. Signing in is handled by AWS Cognito in a user pool used only for this Service, so your password is never visible to Cyamate. Course data is stored in a shared database, scoped so that one course’s data cannot be reached from another. Data is encrypted in transit. At the infrastructure layer, a web application firewall and standard hosting logs process IP addresses to protect the Service. These are not used to identify, profile, or track anyone.
A transcript is visible to the student who completed the assessment and to the instructor who assigned it. Beyond that, access is limited to a single Cyamate administrator, for support and troubleshooting.
If we become aware of a security incident affecting course data, we will notify the affected instructors without undue delay.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Where is your information processed?
The Service is operated from the United States, and your information is processed there.
9. Your privacy rights
To see, correct, or delete what we hold about you, email stephen@cyamate.com or ask your instructor. We will respond to verified requests within 30 days. In practice, deletion requests are usually handled much sooner.
For your official academic record and your grades, contact your institution, which holds them.
We do not sell or share personal information, and we have never done so. We do not use it for targeted advertising or profiling. We do not respond to Do-Not-Track signals, because we do not track users.
10. Updates to this notice
We may update this notice. The current version is always the one at this address, and the date at the top shows when it last changed. If we make a material change, we will email instructors using the Service.
11. Contact us
Cyamate, Inc.
280 S Mangum St, Suite 330
Durham, NC 27701
United States
Email: stephen@cyamate.com
Phone: +1 (839) 293-2058