Legal
Privacy Policy
Last updated: 7 September 2026. This describes what we actually collect, including the analytics and advertising tools running on this site.
Data we collect
Account details, learning activity, assessment results and applied submissions. Organisation workspaces additionally record assignments and manager actions. When you create an account we also record the country, region, city and timezone your sign-up came from, so we can tell you what a session time means where you are.
Personal versus organisation data
Personal career activity — CVs, applications, private notes and personal assessments — belongs to your personal workspace and is never shared with an organisation you belong to.
How we use data
To deliver learning, score assessments, issue and verify credentials, and report capability to the organisation that assigned the learning.
Cookies, analytics and advertising
We use Google Analytics 4 and Google Ads tags, and the Meta Pixel, on this site. We also send conversion events to Meta from our own servers through the Conversions API, which means some events reach Meta even if your browser blocks the pixel. These tools set cookies and identifiers, and they let Meta and Google recognise you across sites for measurement and advertising.
How you found us
We keep a visitor record holding the first and most recent campaign, referrer and landing page associated with your browser, the advertising click identifiers passed in the link that brought you here, your browser user agent and the country we infer from your connection. Once you sign in or give us an email address, that record is linked to you.
What you do on the site
We record page views, how far you scroll, which sections hold your attention and for how long, the buttons and links you click, and whether you started a form and did not finish it. This is how we find out where a page is confusing rather than guessing at it.
Session recording
On our advertising landing, sign-up and sign-in pages only, we record a replay of the page: what moved, what you clicked and how the layout responded. Everything you type is masked in your browser before it is sent, along with anything that looks like an email address, a phone number, a card number or an identifier, and password fields are never captured at all. Signed-in pages are not recorded.
AI features
When you use an AI feature we record which feature, which model, how many tokens it used and what it cost, so we can bill credits accurately and show you your own usage. Conversations with the tutor and the agents are stored against your account so you can come back to them.
Community and messaging
Messages, replies, reactions and attachments in a community or a direct message are stored so the conversation persists. Room administrators can see the membership of the rooms they run. Nobody at TAI Labs reads private conversations except where we are required to investigate a report of abuse or are compelled by law.
Protecting confidential conversations
In community rooms and direct messages the content is hidden while the window is not in front, and copying, right-clicking and dragging images out are turned off. On Windows we can see the PrintScreen key and record that it was pressed, along with the page you were on; we cannot see screenshots taken on macOS, iOS or Android, and we do not pretend to.
Staff access and audit
Staff can view account and billing information to answer support requests, and can with a recorded reason view the product as you see it in order to reproduce a fault. Every such action is written to an audit log with who did it, when, and why. Destructive actions require a second member of staff to approve them.
Time on the platform
While you have the app open and the tab in front of you, your browser reports in once a minute. We record when a session started, when we last heard from you and how many minutes you were actually present, so we can see how the product is used. The clock runs on our side and a gap longer than ninety seconds is not counted, which means a closed laptop stops accruing time rather than recording an eight-hour day. Nothing is reported while the tab is in the background.
Credential verification
Verification pages disclose only the credential, the holder name and the issue date.
Retention and deletion
You can request deletion of your personal workspace at any time. Issued credentials remain verifiable unless revoked. Behavioural and session-recording data is kept for twelve months and then deleted.
Your choices
You can opt out of Google Analytics with Google's browser add-on, and limit Meta's use of your activity in your Meta ad settings. Your browser's do-not-track and cookie controls apply here as they do anywhere. Email preferences are in your account settings, and every email we send carries an unsubscribe link. Asking us to delete your account removes the analytics records linked to it.
Contact
Privacy questions, access requests and deletion requests can be sent to hello@tailabs.ai and we will answer within 30 days.