Privacy Policy
Version v2.0-2026-07-01 · StudentBench (https://studentbench.org)
StudentBench is a research platform (see the Terms of Service). This policy lists everything we collect, how it is used and processed, who can see it, how long we keep it, and the choices you have. Contact: inaara.hasmani-ctr@joinhandshake.com,trevor.khangi@joinhandshake.com.
1. What we collect
1a. Account data (you provide it at signup)
- Name, email address, and age. Your email is your login key. Your password is stored only as a one-way cryptographic hash — we never store the password itself. We also record email-verification status, account status, signup and last-login timestamps, and the research-consent checkbox with its timestamp and the version of the consent language you agreed to.
- For participants under 18: parent/guardian email, the parent/guardian's name and relationship, the parent-permission signature date and version, the youth-assent timestamp and version, and any operator approval record if staff help repair the consent flow.
- Inside the app you are shown only as an anonymous ID number (e.g. user_id=15012); your name and email are kept separate from the research data (§4).
1b. Study data (created as you participate)
- Test answers — every answer you submit on the screener, pre-test, and post-test, including every intermediate answer change with timestamps, whether each answer was correct, and the time you spent on each question (when each question was opened, answered, and changed).
- Scores — your pre-test score, post-test score, and the learning gain between them.
- Tutoring chat transcripts — the complete tutoring conversation: everything you type to the AI tutor and everything it replies, with timestamps. Please don’t type personal information (yours or anyone else’s) into the chat.
- Practice attempts — every practice problem shown or requested, your answers and number of attempts, correctness, and timing.
- Self-paced session events — how you move through the session: advancing to the next concept early, requesting extra practice, finishing the tutoring session early, time spent per concept, and the overall tutoring duration.
- Intake answers — your grade/education level, whether you have taken the test before, and prior tutoring experience.
- End-of-study feedback — your optional rating and free-text feedback form responses.
1c. Technical data (collected automatically)
- IP address — recorded automatically with your session and with logged events, and stored only as a salted cryptographic hash (we cannot recover the raw address from what we store).
- Approximate location — a coarse city / region / country derived from your IP address at signup/enrollment (see §3 for the lookup service).
- Browser and device info — your browser’s User-Agent string, your timezone and clock offset, and client timestamps.
- Interaction event log — a detailed, append-only log of in-app events (page views, clicks, answer changes, navigation), including when the page loses or regains focus or visibility — i.e., switching tabs, windows, or apps — during a timed test, and when you leave mid-study. These events are used for research validity and for the payment integrity review described in the Terms of Service §6.
- Essential cookies — see §8.
1d. Study-assignment records (created by the platform)
- Which AI model and provider tutored you, which version of the tutor’s instructions (prompt) was used, your experimental condition/arm, your test-form order and difficulty tier, and your attempt number. These are experiment bookkeeping, recorded with your session.
2. Processing by AI providers
The tutoring is generated by a third-party large language model — currently Anthropic (the maker of the Claude models). To produce your tutoring plan and every tutor reply, we send the AI provider’s API: your pre-test responses (questions, your answers, correctness, and per-question timing) and the ongoing tutoring chat transcript, including the messages you type. This data is identified to the provider only by session context — never by your name or email — and is handled under the provider’s API terms. Some study conditions may use models from other AI providers; the provider and model used in your session are always recorded (§1d).
3. Service providers we use
- Hosting and database — the application and its database run on third-party cloud infrastructure (currently Render for hosting and Neon for the Postgres database).
- IP geolocation — when a local geolocation database is not configured, we look up the coarse location of your IP address via a geolocation service (currently ipapi.co), which receives your IP address to answer the lookup.
- Email delivery — verification, password-reset, and staff notification emails are sent through an email (SMTP) service.
- AI provider — §2 above.
- Payment and gift cards — adult payment is made through the Handshake platform; your completion code links your Handshake task to your StudentBench session so completion can be verified. Eligible SAT minors may receive a $50 gift card after completion and integrity review (Terms §6).
Where processing happens (international participants). StudentBench is operated from the United States, and the services above store and process data on servers in the United States. If you participate from outside the U.S., your information — including everything described in §1 — is transferred to and processed in the United States, where privacy laws may differ from those of your country. By checking the research-consent box at signup you agree to this transfer. The legal basis for our processing is your consent, together with our legitimate interest in conducting the research described in the Terms; you may withdraw consent as described in §6.
4. How your data is used, and who can see it
- Research. Your study, technical, and assignment data are analyzed to measure and improve AI tutoring. Results are published (papers, leaderboards, datasets) only in aggregate or de-identified form — never with your name or email. The research dataset we export for analysis never contains your name or email: the account table is excluded from the export, and you appear only as an opaque numeric ID. A separate, encrypted ID↔name mapping exists for research administration and is restricted to the research team.
- The research team can view individual sessions (scores, transcripts, event logs, integrity flags) through an internal dashboard, for study operations, grading verification, and integrity review.
- Staff completion notifications. When you complete the study, an automated email goes to the research-operations team so completion can be verified and payment processed. It contains your scores and gain, your StudentBench ID, your account name (withheld for minors), email, and age, your study assignment (model, prompts, arm, forms, tier), your approximate location and (hashed) IP marker, your intake answers, the session timing, and your integrity-review status.
- Operating the service — signing you in, resuming sessions, sending verification/reset emails, and processing payment through Handshake.
- Email from us is study-related only — account verification, password reset, parent-permission links, assent-ready notices, and study/payment administration. We send no marketing email and do not share your contact details for others’ marketing.
- We do not sell your data, and we do not use it for advertising.
- We may disclose information if required by law, and we would honor lawful requests narrowly.
5. How long we keep it (retention)
- Research data (study, technical, and assignment data, keyed by your opaque ID) is retained indefinitely in de-identified form. The research record is append-only by design — events are written once and never edited — which is what makes the study auditable.
- Account data (name, email, age, password hash) is retained while your account exists, and until you request deletion (§6). Signed parental-consent records for minors are retained as required for research-consent recordkeeping (at least three years).
6. Your choices — stopping, withdrawal, and deletion
Participation is voluntary and you may stop at any time (Terms §4). To withdraw from the research, request deletion of your account data, ask us to correct inaccurate or incomplete account information, or ask what we hold about you, email inaara.hasmani-ctr@joinhandshake.com,trevor.khangi@joinhandshake.com from your account email (or include your StudentBench ID). We will delete or irreversibly de-identify your account information. Limits, honestly stated: research data that has already been de-identified, aggregated, or included in analyses and publications cannot be traced back to you and therefore may not be retrievable or removable; in that case we remove the link between your account and the research record rather than the de-identified record itself.
7. Security
- The site is served over HTTPS; session cookies are HttpOnly.
- Passwords are stored only as one-way hashes; the re-identification map is stored encrypted; database access is restricted to the research team.
- IP addresses are stored salted-hashed in the production configuration (§1c).
- The research event log is append-only and tamper-evident; the production database additionally has delete-protection guards.
8. Cookies — essential only
We use only essential cookies: a session cookie (keeping you signed in and your place in the study) and an anonymous participant cookie that lets a returning browser resume its session. Both are HttpOnly and SameSite=Lax (Secure over HTTPS in production). We use no advertising, analytics, or third-party tracking cookies.
9. Participants under 18
The signup research consent covers adults (18+). An under-18 account cannot begin a study until our parental-permission and assent workflow is completed and approved (Terms §3); the parent-permission and assent records are retained (§1a, §5). Eligible SAT minors may receive a $50 gift card after completion and integrity review, and a minor's name is withheld from staff completion-notification emails.
10. Changes to this policy
Material changes update the version identifier at the top of this page (the version you consented to is recorded on your account). Continued participation after a change is acceptance of the new version.
11. Contact
Questions about this policy, your data, withdrawal, or your rights as a research participant: inaara.hasmani-ctr@joinhandshake.com,trevor.khangi@joinhandshake.com.