Privacy Policy

How we protect your data

Effective May 18, 2026

Who we are

Ministry Sandbox is a research-grade simulation platform for seminary classrooms. Students rehearse difficult ministry conversations with AI parishioners and receive competency-graded feedback — reviewed and approved by faculty, never auto-published.

This privacy policy describes how we collect, use, and protect your information during the pilot program.

What information we collect

When you create an account and use Ministry Sandbox, we collect:

  • Account information: Your email address, full name, seminary affiliation, and optional profile details.
  • Submissions: The text you write when responding to scenarios and case studies.
  • Assessment records: Faculty-confirmed grades, rubric scores, and feedback.
  • Usage information: When you log in, which modules you complete, and how you interact with the platform.

How AI is used

AI assists rubric scoring. When you submit a response, an AI system (currently Google Gemini) reads your submission and proposes a rubric score and written feedback.

Only faculty-confirmed scores are final. An AI proposal does not become your grade until a faculty member has reviewed and approved (or adjusted) it.

What data is sent to AI providers

  • The text of your submission
  • The module scenario context and rubric
  • A pseudonymous internal identifier (not your name or email)

We do not send your email address, name, date of birth, or any contact information to AI providers.

Cross-border processing: Google may process your text on servers outside your country (typically in the United States). Google Gemini is the only AI provider used during this pilot.

Product analytics

We use first-party product analytics via PostHog to understand how the platform is used and to improve the user experience. This is optional and controlled by an environment variable.

When enabled, PostHog collects:

  • Page views and navigation patterns
  • Button clicks and form interactions (autocapture)
  • Browser type, device type, and basic technical information

PostHog uses a public project key (not a secret) and all events are tagged with the product identifier. When the analytics feature is disabled, no tracking snippet is loaded and no data is sent.

How we use your information

We use your information to:

  • Provide the simulation platform and generate feedback
  • Enable faculty to review and confirm grades
  • Track your progress through modules and competencies
  • Maintain an audit log for quality assurance and dispute resolution
  • Improve the platform and training materials

Data retention

We retain your information for the following periods:

  • Faculty-confirmed grades: 7 years (aligns with academic record retention standards)
  • Submissions and pending grades: Cohort lifetime + 12 months
  • Audit logs (metadata): 7 years
  • Raw AI responses: 12 months (then the full response is deleted, keeping only metadata)
  • Account profile: Cohort lifetime + 12 months, then anonymized

Who can access your data

Access to your data is limited to:

  • Faculty reviewers at your seminary who confirm grades
  • Platform operators (for technical support and quality assurance)
  • AI providers (Google) who process submissions as described above

We do not sell or share your data with third parties for marketing purposes.

Your rights

You have the right to:

  • Request access to the personal data we hold about you
  • Request deletion at the end of the cohort (subject to institutional record-keeping requirements)
  • Request human review of any AI-proposed or faculty-confirmed score within 14 days of receiving it

To exercise these rights, contact your instructor or write to [email protected] .

Security

We protect your data with industry-standard security measures:

  • Encrypted database storage
  • HTTPS encryption for all connections
  • Role-based access controls
  • Regular security monitoring and logging

Changes to this policy

We may update this privacy policy from time to time. We will notify you of any material changes by email or by posting a notice on the platform. Your continued use after changes are posted constitutes acceptance of the updated policy.

Contact us

For questions about this privacy policy or how we handle your data, contact [email protected] .

Generating response…

This usually takes 30–60 seconds. Your response is saved — please don't refresh.