← Back to portal
Privacy Policy
Effective: 2026-05-17 (placeholder — replace with reviewed version before launch)
Placeholder. Replace this entire document with a Privacy Policy reviewed by legal counsel — particularly if your students reside in the EU, UK, or California. This text is a structural template, not legal advice.
What we collect
- From Google OIDC sign-in: your email address, display name, profile picture URL, and Google subject identifier.
- From lab activity: which lab you deployed, when, for how long, the session hostname, lesson progress, flag submissions.
- From web requests: session cookies, IP address, browser user-agent (held in request logs).
How we use it
- To authenticate you across sessions.
- To deliver labs, track progress, and provide an audit trail of admin actions.
- To enforce quotas (max sessions, duration, idle timeout).
- To investigate operational issues and abuse.
What we share
Instructors / administrators on your training program can see your lab activity, progress, and active VMs. We do not sell data to third parties. We do not share data with advertisers.
Retention
- Sessions cookies: 24 hours, then deleted.
- Lab session records: 30 days after the lab reaches a terminal state.
- Activity log: 30 days.
- Magic-link tokens: 10 minutes, single use.
- Account record (user + progress): retained while you have active entitlements; deletable on request.
Your rights
You may request a copy of your data or its deletion. Email replace-with-real-contact@cyberwarrange.com from the address associated with your account. We will respond within 30 days.
Security
Data in transit is encrypted with TLS. Data at rest in Azure Cosmos DB is encrypted with Microsoft-managed keys. Magic-link tokens are HttpOnly cookies; the underlying secret is single-use and short-lived.
Contact
Data controller: replace-with-real-contact@cyberwarrange.com