Declare AI
Privacy Policy
Version 1.1 | Effective from [insert date] | Last updated [insert date]
1. Who we are
Declare AI Ltd (“Declare AI”, “we”, “us”, “our”) provides Declare AI, a software tool for higher-education institutions that lets students generate structured AI declarations for their assignments and gives institutions a verifiable record of those declarations.
This Privacy Policy explains what personal data Declare AI processes, how we process it, and the rights you have under UK data protection law. It is written to be read in plain English wherever possible, with technical and legal references kept to what is necessary.
Registered company: Declare AI Ltd, registered in England and Wales [insert company number].
Registered office: [insert registered address].
ICO registration: [insert ICO reference number once ICO registration is complete].
2. Who this policy applies to
This policy applies to:
Students who use Declare AI through their institution’s Learning Management System (Moodle, Canvas, Blackboard, or other LTI-compliant platforms) to generate AI declarations for their assignments.
Lecturers and teaching staff who configure Declare AI activities for their assignments inside their institution’s LMS.
Institutional administrators who manage Declare AI on behalf of their institution.
Visitors to declareai.co.uk and any related websites we operate.
If you are a UK university and you have signed a contract with Declare AI Ltd to provide the service to your students and staff, your institution is the data controller of your students’ and staff’s personal data. Declare AI Ltd acts as a data processor on your institution’s behalf under a Data Processing Agreement (DPA) you have signed with us under Article 28 of the UK GDPR.
3. What personal data we process
3.1 What we process by design (pseudonymous-only)
Declare AI is built so that we process the absolute minimum personal data needed to provide the service. Specifically, when a student or lecturer launches Declare AI from their institution’s LMS, we receive the following information from the LMS via the LTI 1.3 / LTI Advantage protocol:
An LMS user identifier (the LTI “sub” claim) which we one-way hash with a per-institution salt to produce a pseudonymous_hash. We do not store the raw LMS user identifier.
The user’s role at the institution (student, lecturer, or administrator).
The LMS context identifier (which course or module) and the LTI resource link identifier (which specific assignment activity).
Country-level information derived from the originating network request, which we resolve to an ISO 3166-1 alpha-2 country code and then discard.
3.2 What we do NOT process
These items are explicitly excluded from our processing by architectural choice:
Names. We do not request or store student or lecturer names.
Email addresses. We do not request or store email addresses from the LMS-launched user flow.
Network identifiers. We do not store IP addresses; we resolve country only at the moment of request and discard the IP.
LMS-provided personal data beyond the minimum needed for LTI launch authentication.
3.3 Declaration content
When a student generates an AI declaration, the structured declaration text is stored against the pseudonymous_hash for the duration of the institutional retention period. The declaration content describes which AI tools the student used and for what purposes; it does not contain identifying information about the student beyond what they themselves include.
3.4 Institutional administrator accounts
Institutional administrators access an administrative portal separately from the LTI launch flow. For administrator accounts we process: name, work email address, role at the institution, and authentication credentials managed by our authentication provider. Administrator authentication is governed by a separate access agreement signed by the institution.
3.5 Website visitors (declareai.co.uk)
When you visit declareai.co.uk we process limited information needed to deliver the website and prevent abuse: see our Cookie Policy for cookie-level detail. We do not use third-party advertising or behavioural-tracking cookies.
4. Lawful basis for processing
Under the UK GDPR we must have a lawful basis for processing personal data. The lawful basis we rely on depends on the processing:
4.1 Student and lecturer LTI use — Article 6(1)(e) (public task)
UK universities are public bodies exercising official authority in the conduct of academic assessment. Declare AI is provided to support that official authority. The processing of student and lecturer data through Declare AI is conducted under Article 6(1)(e) of the UK GDPR — “processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.” Your institution remains the data controller; we act as the processor on its behalf.
4.2 Institutional administrator accounts — Article 6(1)(b) (contract)
Administrator account processing is conducted under Article 6(1)(b) — “processing is necessary for the performance of a contract” — specifically the contract between Declare AI Ltd and the institution.
4.3 Website use — Article 6(1)(f) (legitimate interests)
Limited website operational data is processed under Article 6(1)(f) — our legitimate interest in operating and securing our website. We balance this interest against the data subjects’ rights and freedoms. You can object to this processing at any time using the contact details below.
5. Who we share your data with
Declare AI does not sell or rent personal data to anyone, ever. We share personal data only with the sub-processors listed below, each of whom acts on our documented instructions under a written contract that includes Article 28 UK GDPR processor obligations.
5.1 Current sub-processors
The authoritative sub-processor register — including service categories, data processed, security attestation links, DPA status, and dates last verified — is published at declareai.co.uk/sub-processors.
| Sub-processor | Service | Location |
| Supabase Inc. | Managed PostgreSQL database and authentication | European Union (Frankfurt region) |
| Render, Inc. | LTI tool compute at app.declareai.co.uk | European Union (Frankfurt region) |
| Functional Software, Inc. (Sentry) | Application error tracking (PII scrubbed at SDK level before transmission) | European Union |
| Vercel Inc. | Marketing website hosting at declareai.co.uk | European Union (Frankfurt or Dublin region) |
| GitHub, Inc. | Source code and continuous-integration infrastructure | United States and European Union |
If we add, change, or remove a sub-processor, we will notify our institutional customers at least 30 days in advance.
5.2 Disclosures we may be legally required to make
We may be required to disclose personal data to law enforcement, regulators (including the Information Commissioner’s Office), or courts where this is required by law. We will inform institutional data controllers of any such disclosure unless legally prohibited from doing so.
6. How long we retain personal data
Pseudonymous declaration records: retained for 7 years from generation by default, in line with UK higher education misconduct retention norms. Each institution may configure a different retention period in its Data Processing Agreement with us.
Audit trail records: retained for the same period as the underlying declarations. Audit records older than 2 years are archived to cold storage and remain retrievable but cannot be modified.
Verification metadata: Declaration ID metadata used to power the public verification page may be retained indefinitely for verification page integrity. The pseudonymous_hash is dropped at the end of the retention period.
Administrator accounts: retained for the duration of the institutional contract; deleted within 30 days of contract termination.
Website analytics: aggregate-only; no individual records retained beyond 12 months.
7. International data transfers
Declare AI is committed to keeping personal data within the UK and the European Economic Area (EEA). All sub-processors listed above are configured to process data within the EU. We are committed to moving to UK-only data residency in Year 2 of operation, when we will migrate to Cloudflare Workers with UK Points of Presence.
If we ever need to transfer personal data outside the UK/EEA, we will only do so under one of the appropriate safeguards permitted by UK GDPR (Articles 46–49), and we will update this policy and notify institutional data controllers in advance.
8. Your rights
Under the UK GDPR you have a number of rights in relation to your personal data. These rights apply to data Declare AI holds:
The right to be informed (this Privacy Policy).
The right of access (a copy of the personal data we hold about you).
The right to rectification (correction of inaccurate data).
The right to erasure (“right to be forgotten”), subject to legal retention obligations.
The right to restrict processing in certain circumstances.
The right to data portability for data you have provided to us.
The right to object to processing under Article 6(1)(e) or (f), including profiling.
Rights in relation to automated decision-making (Declare AI does not perform automated decision-making about individuals).
If you are a student or lecturer using Declare AI through your institution, please direct rights requests in the first instance to your institution’s Data Protection Officer. Your institution is the data controller and we will support them in responding to your request. If your institution directs you to us, or if you are a website visitor, contact us using the details in section 11.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk
9. How we keep your data safe
Declare AI is built with privacy and security as architectural principles, not afterthoughts:
Tenant isolation at the database level using PostgreSQL Row-Level Security — personal data cannot be accidentally exposed across institutions.
All data in transit is protected with TLS 1.2 or above.
All data at rest is encrypted with AES-256.
Audit events use a cryptographic hash chain with append-only storage — tamper-evident at the database level.
We follow the UK National Cyber Security Centre’s Cyber Essentials framework and pursue Cyber Essentials Plus certification.
We conduct annual external penetration testing from Year 2 onwards.
Sub-processor access is governed by Article 28 contracts and reviewed at least annually.
10. Cookies
Our use of cookies and similar technologies is described in our separate Cookie Policy: declareai.co.uk/cookies.
11. How to contact us
For questions about this Privacy Policy or about how Declare AI processes personal data:
Email: privacy@declareai.co.uk
Post: Declare AI Ltd, [insert registered address].
If you are a student or lecturer, please contact your institution’s Data Protection Officer in the first instance.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our service, in our sub-processor list, or in applicable law. Where the change is material we will notify institutional data controllers at least 30 days in advance. The current version, effective date, and last-updated date are shown at the top of this policy.
13. Document history
| Date | Version | Change |
| [insert effective date] | 1.0 | Initial publication. |