Data minimisation
Collect only the account, school, class, learning preference, lesson notes, progress and assessment information needed to operate the service. Do not request unnecessary sensitive information from learners.
StemSphere is an ongoing educational project. This page describes the intended privacy-by-design direction and should be reviewed against the final production features before public school deployment.
Collect only the account, school, class, learning preference, lesson notes, progress and assessment information needed to operate the service. Do not request unnecessary sensitive information from learners.
School deployments should include appropriate school/guardian consent processes, age-appropriate notices, administrator controls and clear procedures for data access or deletion.
Questions, lesson excerpts and support-language requests sent to Sphere AI may be processed by configured AI providers. AI-generated translations can be cached for reuse. Production deployment should disclose the provider, retention choices and moderation/safety controls.
API keys stay server-side. Passwords are hashed. Production hosting should use HTTPS, least-privilege database accounts, regular backups and restricted administrator access.