Privacy and trust¶
ControlAI works with recordings of classes that contain instructors' and students' voices and faces. That's why trust here isn't a "nice-to-have" — it's a condition for operating at all. Here's a calm, matter-of-fact explanation of how data protection works.
Consent and disclosure¶
Because classes are recorded and analyzed (video and audio), launch requires:
- instructors' consent — to have their classes analyzed;
- students being informed — that classes are recorded and analyzed.
University students are adults, so the consent process is simpler: transparently informing the students themselves is enough. Consent and disclosure are part of onboarding the university. Consent explicitly covers audio and video recording of classes. For instructors, ControlAI is a personal assistant: personal statistics and a breakdown of their own classes — that's exactly how it should be presented to the team when collecting consent.
Recordings have a short life¶
- Raw video and audio are deleted automatically — no later than 7 days.
- Only the results remain: transcripts (the text of what was said in class), report text, metrics, and scores.
In other words, what's kept long-term is the "distilled value," not the classes' actual video and voices.
Data stays in Uzbekistan¶
All recordings and data are stored on servers in Uzbekistan — in line with local personal data law. They don't get scattered across foreign third-party services.
What never leaves¶
This is a hard technical commitment:
- raw class video and audio are never sent to external AI services.
- Speech recognition and video analysis run on our own servers.
- Only text and numbers ever leave (to the external model that writes the report text) — the transcript and finished metrics, without the audio or video recording itself.
More on why "just upload the video to someone else's AI" isn't acceptable — in Why a university needs ControlAI.
Access — strictly role-based¶
- Everyone sees only their own: an instructor sees their own classes, a dean sees their own faculty, and so on (see Inside the admin panel).
- Instructors are protected from being put "on display": their statistics are private, and there's no public leaderboard. Oversight here is balanced by transparency: the same rules apply to everyone, and the data is for development, not for public call-outs.
- Our internal service logs contain no personal data — no names, no phone numbers, no conversation text: we see the system's state, not the content of classes. Our staff can access a class's actual content only in targeted cases — for example, when investigating an incident at the university's request.
When a university leaves¶
If a university stops working with ControlAI, its data is deleted — a commitment we're willing to put in writing.
Key takeaway from this chapter: privacy rests on simple rules — instructor consent and disclosure to adult students as part of onboarding, a short life for raw recordings (no more than 7 days), storage in Uzbekistan, a hard ban on sending raw video/audio to external AI, strictly role-based access, and data deletion when a university leaves.
→ Next: 15. Boundaries (what it does NOT do) — so there are no false expectations.