Privacy policy
Learnova builds interactive learning tools for university courses. We designed the platform around a simple idea: the best way to protect data is not to collect it.
What we collect
| Data | When | Why |
|---|---|---|
| Display name and institutional email identifier | When you sign in with a university Google or Microsoft account | To save your learning progress across devices and identify you to your course |
| Learning events (chapters completed, choices made, forecasts and their outcomes) | While you use the products signed in | Progress, feedback, and — for enrolled courses — evidence available to your lecturer |
| CV content you create in CV Studio | Only if you choose cloud saving | Sync and sharing that you control. Without an account, your CV never leaves your browser |
What we deliberately don't collect
- No date of birth, home address or phone number
- No advertising identifiers, no third-party analytics trackers
- No student input sent to AI models — see the AI transparency note
What we never do
- We do not sell personal information, ever
- We do not use learning data for advertising or profiling
- We do not keep institutional data after an agreement ends — deletion follows the agreed schedule
Where data lives
Anonymous play stores progress in your own browser (local storage). Signed-in data is held with vetted cloud providers acting as our processing agents under the New Zealand Privacy Act 2020 (IPP 12). Our roadmap includes hosting institutional data in New Zealand-based data centres where an institution requires it, and per-institution isolation is enforced at the database layer.
Your rights
Under the Privacy Act 2020 you may request access to, or correction of, your personal information at any time. Institutions may additionally request export or deletion of their cohort's data under their agreement. Write to us at our contact address and we will respond within 20 working days.
For institutions
We provide a data processing agreement covering: the exact data elements collected, education-only use limits, security measures, sub-processor list, breach notification timelines, and end-of-contract deletion. Ask us for the current template.