Privacy and data practices
What the NCSC AI Toolkit collects, how long it keeps it, and how to request deletion. Last updated 2026-06-10.
What we collect
- Workshop password path (Path A). No personal data collected. The session cookie carries an anonymized identifier (
workshop@charterts.com) and an expiration timestamp. - Annual-access path (Path B). Email address (required), name, school, role (each optional). Stored in our
workshop_leadstable. Used to identify you when an authorized request reaches the toolkit operator (Joseph Colarusso) for manual review. - Bypass token path. No personal data. Anonymized cookie (
bypass@charterts.com). - Readiness snapshot (the public AI Governance Readiness check). Your answers to the ten questions, the computed band, and a fingerprint, stored in our
readiness_snapshotstable. Email and school are optional; provide them only if you want a follow-up or want to confirm your signed PDF later at/verify. Leave them blank to stay anonymous. - The vendor contracts you paste into the review steps stay in your browser. They are never sent to us. The review prompt you build runs in your school's own AI; nothing you paste is uploaded or stored.
- Visit metadata. Per-visit timestamp and visit count on your lead row. No browser fingerprinting. No third-party analytics.
Legacy audit reports (April through June 2026). An earlier version of the toolkit let you generate a signed PDF audit of a vendor agreement, which stored the pasted text and the AI's output. That feature has been removed. Reports created during that window are retained so the /verify page can still confirm them: workshop and bypass reports carry no email; annual reports are linked to the requester's email. No new audit reports are created.
What we don't do
- We don't sell or rent your contact information.
- We don't share it with vendors, partners, or affiliated CTS clients.
- We don't run third-party analytics or advertising trackers on the toolkit.
- We don't fingerprint your browser or device.
Retention
- Workshop leads. Auto-purged 18 months after last activity, unless flagged for follow-up.
- Readiness snapshots. Snapshots with no email are kept as anonymized usage records. Snapshots that include your email are kept until you request deletion (see below).
- Legacy audit reports. Workshop and bypass reports carry no identifying email and are kept as anonymized usage records. Annual reports are kept until you request deletion or until the underlying workshop_leads row is purged.
- Source-health logs. Per-URL availability checks, no personal data, retained indefinitely.
- Rate-limit counters. IP-keyed throughput buckets, auto-purged after 2 days.
Your rights
Regardless of jurisdiction, you can request: (a) a copy of the data we hold on you, (b) deletion of your lead, any readiness snapshot tied to your email, and any associated legacy audit reports, (c) correction of inaccurate information, (d) revocation of any active access link.
Email joseph.colarusso@charterts.com from the email address on file. Joe processes requests manually; expect a 5-business-day turnaround. Deletion is irreversible.
EU / California / New York residents
GDPR (EU), CCPA (California), and NY SHIELD Act recognize the rights above and add procedural requirements. The data we collect under Path B is processed with your explicit consent at submission. Withdraw consent anytime by emailing the address above.
Security
- All traffic served over HTTPS with HSTS preload.
- Session cookies are HttpOnly, Secure, host-locked (
__Host-prefix). - API endpoints carry per-IP rate limits and per-tier daily quotas.
- Stored in Atlas (Supabase Postgres), accessed only server-side through a per-app service role. No database credentials are ever exposed to the browser.
- Outbound email sent via authenticated Gmail SMTP or Resend; no third-party email tracking.
Contact
Joseph Colarusso · Charter Technology Solutions · joseph.colarusso@charterts.com · 866-399-3230