Effective 19 July 2026
At a glance
- We use account, learning, workspace, and limited first-party product data to operate the service.
- We do not sell personal data or use it for third-party targeted advertising.
- You can export or delete account data from settings, or contact support for help.
Who this policy covers
This policy applies to the Botopsy Lab website, accounts, courses, playgrounds, incident workspaces, beta waitlist, and support. Botopsy Lab is the controller of personal data collected directly through those services unless a school or other organisation tells you that it controls a managed classroom account.
Questions about this policy or Botopsy Lab's data practices can be sent to [email protected].
Information we collect
- Information you provide: name, email address, password credential, waitlist request, support messages, preferences, and any profile details you choose to add.
- Learning records: enrolments, lesson and assessment attempts, hypotheses, evidence, hints, repairs, test results, capstone submissions, and project reports.
- Workspace data: files and commands in a lab, environment image, session and checkpoint state, compute duration, resource usage, and diagnostic references.
- Technical and security data: session identifiers, IP address and user agent when recorded by authentication or infrastructure services, timestamps, and security or error logs.
- First-party product analytics: an anonymous browser identifier stored in local storage, route or content identifier, interaction name, and limited event properties. The site also stores your theme preference locally.
- Connected account data: if GitHub sign-in is enabled and you choose it, the identifiers and profile information GitHub makes available for authentication.
Where information comes from
Most information comes directly from you when you join the waitlist, create an account, complete learning activities, use a workspace, publish a report, or contact support. Technical data is generated by your browser, the service, and its infrastructure. Connected account data comes from GitHub only when you choose GitHub sign-in.
Why we use information
We use this information to provide and secure accounts; deliver courses and workspaces; save progress; grade repairs; manage beta invitations and capacity; provide support; investigate errors and abuse; understand whether lessons and incidents work as intended; and meet legal obligations.
Where applicable law requires a legal basis, we rely on performance of our agreement with you to provide requested services, legitimate interests in operating and improving a secure educational product, consent where we specifically ask for it, and compliance with legal obligations. You may object to processing based on legitimate interests by contacting support.
Botopsy Lab does not sell personal data, share it for cross-context behavioural advertising, or use learner code and evidence to train third-party advertising systems.
International processing
Botopsy Lab and its service providers may process information in countries other than the one where you live. Where law requires safeguards for an international transfer, we will use an approved transfer mechanism or another lawful basis and make further information available on request.
How long we keep information
We keep account and learning records while your account is active so that progress and reports remain available. Waitlist records are kept until you ask to be removed or the relevant beta intake is closed. Workspace sessions, operational logs, traces, metrics, and backups are kept for limited periods based on security, reliability, capacity, and recovery needs.
When you delete an account, associated records are removed from active product systems except where retention is required for security, fraud prevention, dispute resolution, or law. Residual copies may remain in protected backups until those backups expire through their normal rotation.
Your choices and rights
- Export account, progress, evidence, test, and project data from Account settings.
- Delete the account and associated active records from Account settings.
- Correct profile or preference information in Account settings.
- Keep project reports private unless you explicitly publish them.
- Ask to access, correct, delete, restrict, or receive a portable copy of personal data, or object to certain processing, by contacting [email protected].
- Withdraw consent at any time where processing is based on consent. Withdrawal does not affect earlier lawful processing.
Regional privacy rights
Depending on where you live, you may have additional privacy rights and the right to complain to your local data protection or privacy authority. We will not discriminate against you for exercising a privacy right. We may need to verify your identity before completing a request, and an authorised agent may be required to provide proof of authority.
Botopsy Lab does not make decisions that produce legal or similarly significant effects based solely on automated processing. Automated grading determines learning feedback and completion evidence, not employment, accreditation, professional licensing, or access to essential services.
Security
We use technical and organisational safeguards designed to protect personal data, including verified authentication, access controls, isolated workspaces, limited service credentials, and operational monitoring. No internet service can guarantee absolute security, so protect your credentials and do not place secrets or unnecessary personal data in learning workspaces.
Children
Botopsy Lab is a professional and higher-education service and is not directed to children under 13. We do not knowingly collect personal data from a child under 13. If you believe a child has provided personal data without the consent required by law, contact [email protected] so we can investigate and delete it.
Changes and contact
We may update this policy when the product, providers, or law changes. We will update the effective date and provide additional notice when a change materially affects how we use personal data.
For privacy requests or questions, email [email protected]. Include the email address connected to your account and enough detail for us to understand the request; do not send passwords, access tokens, or payment card details.