Privacy policy
ilmCore, Inc.
Last updated: 2026-08-19
ilmCore provides Study Room and Instructor's Office, learning workspaces used by universities, students, and instructors. This Privacy Notice explains what personal data we handle, why we handle it, how it is protected, and the rights available to you.
Our role
When ilmCore is provided through a university or other institution, the institution will generally act as thedata controller and ilmCore acts as a data processor, processing personal data on the institution's behalfand in accordance with our agreement with that institution.
If you use ilmCore directly outside an institutional agreement, ilmCore may act as the controller for personal data associated with your account and use of the service.
For visitors to our website and individuals who contact us directly, ilmCore is the controller of the relevantcontact, communications, and technical data.
What we collect
Depending on how you use ilmCore, we may process the following categories of personal data:
Account data. Your name, email address, institutional identifier, role (such as student or instructor), andother information needed to authenticate or administer your account. This information may be provideddirectly by you or by your institution or learning platform when you sign in.
Learning content and activity. Course materials made available through the service, as well as notes,questions, quiz responses, study materials, prompts, conversations with AI study tools, and other contentor activity generated when you use ilmCore.
Technical and security data. Information generated when you use the service, such as IP address, browserand device information, timestamps, authentication events, application logs, and security event records.
Communications data. Information you provide when you contact ilmCore, request support, submit a privacy request, or otherwise communicate with us directly.
ilmCore does not require health information or other special-category or sensitive personal data in order tocreate or use an account. However, users or institutions may include such information in content theychoose to provide to the service. Where this occurs, we process that information in accordance with ouragreement with the relevant institution and applicable law.
ilmCore does not collect payment-card information through the learning product. Our product contains no advertising, and we do not use third-party advertising or cross-site behavioraltracking technologies. We use cookies and browser storage that are necessary to authenticate users,maintain sessions, secure accounts, and operate the service.
How we use personal data
We process personal data for the following purposes:
Providing the service. To authenticate users, provide institutional learning workspaces, store and delivercourse and study content, and operate the features you choose to use.
Providing AI features. When you invoke an AI-powered feature, such as asking a question about a lectureor requesting an explanation, ilmCore sends your request and relevant contextual information to AI serviceproviders as necessary to generate the requested response.
We use OpenAI with Zero Data Retention enabled for the eligible API endpoints and capabilities used byilmCore. Under those controls, eligible customer content is not retained by OpenAI after processing, subjectto OpenAI's applicable Zero Data Retention terms and technical limitations.
We also use Google Cloud AI services under enterprise terms governing the processing and use of customer data.
We do not permit our AI providers to use ilmCore customer content to train their general-purpose AI models where our applicable provider agreements prohibit such use.
Service quality and reliability. We process diagnostic information about AI and application interactions toevaluate system performance, identify errors, monitor reliability, and improve the quality of the service. Where practicable, diagnostic records use internal identifiers rather than directly identifying information such as names.
Security and fraud prevention. We use authentication, audit, application, and security information toprotect accounts and systems, detect suspicious activity, investigate incidents, and maintain the security ofthe service.
Legal and compliance purposes. We may process information where necessary to comply with applicablelaw, enforce contractual obligations, establish or defend legal claims, and meet regulatory or compliancerequirements.
We do not sell personal data and do not use personal data for advertising.
ilmCore's AI features are designed to support learning. ilmCore does not make decisions based solely onautomated processing that produce legal or similarly significant effects about students. Where ilmCoreprovides instructors or institutions with learning insights, academic and educational judgments remain theresponsibility of the institution and its authorized personnel.
Legal bases where ilmCore is a controller
Where the GDPR or UK GDPR applies and ilmCore acts as the controller, we process personal data on one or more of the following legal bases, depending on the activity:
performance of a contract or taking steps requested before entering into a contract;
our legitimate interests in operating, securing, supporting, and improving our services, where those interests are not overridden by your rights and interests;
compliance with legal obligations; and consent, where we specifically ask for consent and consent is the appropriate legal basis.
Where ilmCore acts as a processor for an institution, the institution determines the purposes and applicable legal basis for processing, and ilmCore processes personal data on the institution's documented instructions.
Visibility within your institution
ilmCore is designed to preserve the privacy of students' individual study activity.
Instructors may receive aggregated, class-level analytics about learning activity within their courses. Your individual study activity — including your conversations with AI study tools and personal study materials — is not shared with instructors unless a particular feature clearly indicates otherwise before you use it or your institution has configured a different use that is communicated to you.
Who processes data for us
We use a limited number of service providers and sub processors to operate ilmCore. These providers are contractually required to protect personal data and process it only for authorized purposes.
Our providers include:
Google Cloud for cloud infrastructure, hosting, databases, storage, and certain AI services;
OpenAI for certain AI-processing functions;
Cloudflare for network, content-delivery, and security services; and specialist providers supporting functions such as content search and indexing, video delivery, application and error monitoring, AI diagnostics, and document processing.
Our current sub processor information, including the functions performed by relevant providers and applicable processing locations, is available on request at privacy@ilmcore.com.
We may also disclose personal data where required by applicable law, regulation, court order, or other valid legal process. Where permitted and appropriate, we will notify the affected institution before making such a disclosure.
We may also disclose information in connection with a corporate transaction such as a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate confidentiality and data-protection safeguards.
Where data is stored and processed
ilmCore supports regional data hosting for institutional deployments.
For US institutional deployments configured for US data residency, primary institutional data is stored in theUnited States.
For UK institutional deployments configured for UK data residency, primary institutional data is stored inthe United Kingdom.
Certain service providers may process limited personal data in other jurisdictions where necessary to provide their services. For example, pseudonymized diagnostic information may be processed within the European Union.
Where personal data protected by the UK GDPR or GDPR is transferred internationally and a transfer mechanism is required, we use appropriate safeguards, which may include adequacy decisions, StandardContractual Clauses, the UK International Data Transfer Addendum, or other legally recognized transfer mechanisms as applicable. More detailed information about processing locations and relevant sub processors is available from privacy@ilmcore.com.
How long we keep personal data
We retain personal data only for as long as necessary for the purposes for which it is processed, subject to our contractual commitments and applicable legal requirements.
For institutional customers, institutional data — including learning content and associated service records— is generally retained for the duration of our agreement with the institution and deleted in accordancewith the applicable agreement and our data-retention schedule.
Unless a different period is agreed with an institution:
institutional customer data is deleted from active systems within 30 days after the applicableagreement ends or deletion is requested in accordance with that agreement;
security and audit logs may be retained for up to one year where necessary for security, compliance,and incident investigation; and
deleted information may remain in encrypted backups for up to an additional 30 days before thosebackups expire or are overwritten in the ordinary course.
Some information may be retained for longer where required by law or where reasonably necessary toestablish, exercise, or defend legal claims.
Your rights
Depending on your location and applicable law, you may have rights concerning your personal data, including the right to:
request access to personal data about you;
request correction of inaccurate personal data;
request deletion of personal data;
request restriction of certain processing;
object to certain processing;
receive certain personal data in a portable format;
withdraw consent where processing is based on consent; and
complain to an applicable data-protection or privacy authority.
Where applicable, you may also have the right to appeal a decision we make in response to a privacy-rights request.
If your institution is the controller of your personal data, you should generally direct your request to your institution. ilmCore will assist the institution in responding to applicable requests as required by our agreement and applicable law.
You may also submit a request through available in-product privacy controls or contact us at privacy@ilmcore.com.
We may take reasonable steps to verify your identity before fulfilling a request. We will respond within the time required by applicable law and will not discriminate against you for exercising an applicable privacy right.
If you are in the United Kingdom, you also have the right to complain to the Information Commissioner's Office (ICO).
Security
ilmCore maintains technical and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, loss, and misuse.
These safeguards include encryption of data in transit and at rest, access controls, multi-factor authentication for administrative access, logging and monitoring, institutional data segregation, vulnerability management, and security incident-response procedures.
Our information security program incorporates controls aligned with recognized security frameworks, including SOC 2 and ISO 27001, and is subject to ongoing security review and independent assurance activities.
No system can guarantee absolute security, but we continuously review and improve our safeguards in light of applicable risks and industry practices.
Children and younger students
ilmCore is designed primarily for use in higher education and is not a consumer service directed primarily atchildren.
Some students using higher-education services may be under 18. Where an institution makes ilmCore available to a minor, ilmCore processes the student's personal data on the institution's behalf and in accordance with the institution's instructions and applicable law.
ilmCore does not knowingly offer the service directly to children under 13 outside an authorized institutional arrangement. If we learn that personal data from a child has been collected in circumstances where the required authorization or consent was not provided, we will take appropriate steps in accordance with applicable law.
If there is a security incident
If we become aware of a personal-data breach affecting an institutional customer's data, we will notify the affected institution without undue delay and in accordance with our contractual obligations, incident-response procedures, and applicable law.
We will provide reasonable assistance to support the institution in investigating the incident and meeting any applicable notification obligations.
Where ilmCore is itself the controller and applicable law requires us to notify affected individuals or a regulatory authority, we will do so in accordance with those requirements.
Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect changes to our services, processing activities, legal requirements, or privacy practices.
We will publish the current version at ilmcore.com/privacy and update the "Last updated" date above.Where required or appropriate, we will notify institutional customers or affected users of material changes.
Contact us
For questions about this Privacy Notice, requests concerning your personal data, or information about ourprivacy practices or subprocessors, contact:
ilmCore, Inc.
Email: privacy@ilmcore.com
Address: 2 Park Avenue 20th Floor, New York NY 10016