Last updated 23 August 2026
ux-phi is run by Nathaniel Hansen. For the ordinary use of this site — an individual signing up and playing a simulation — the data controller is ux-phi. [TODO: legal entity, contact address, ICO registration number.]
When your instructor enrols you in a class section, the relationship changes: your institution decides what is collected and why, and ux-phi processes it on their instruction. Questions about a class section go to your instructor or your institution’s data protection officer first.
For anyone with an account:
Additionally, if you hold a seat in a class section:
ux-phi uses the following providers. Each processes only what the service requires.
Your conversations are not sold, and are not used for advertising or marketing. They are not used to train AI models.
Opening a class experiment attaches a one-way tag derived from your seat so your own responses can be shown back to you afterwards. Your name and account are never sent to the experiment site, and your instructor sees class results rather than who answered what. But the tag is derived from your seat, which means ux-phi can re-associate an experiment response with your account. We describe this as pseudonymous rather than anonymous because that is what it is.
[TODO: decide and state actual periods. Proposed defaults below — change them to whatever you will genuinely honour, because a retention promise you do not keep is worse than none.]
Take a copy, or delete everything, from your account page.Both are self-service and neither needs anyone’s permission: the export downloads as a JSON file, and deletion removes your account and everything in it immediately and irreversibly. To have something corrected rather than deleted, write to the contact address above.
Two things deletion deliberately does not erase. What you wrote in a paired discussion stays in your partner’s thread as a removal marker, with your name and your words gone — their record of that conversation is not yours to erase. And records of administrative access to a class are kept as a security log; an audit trail that erases itself on request is not an audit trail.
If you are a student in the United States, records your instructor uses for grading may be education records under FERPA, which gives you a right to inspect and review them and to request correction. Those requests go to your institution. If you are in the UK or EU, your UK GDPR / GDPR rights are exercised against your institution for class data, and against ux-phi for your personal account.
Grades are not decided automatically. The evaluations ux-phi generates are drafts for your instructor to read, override, or ignore; a person decides your mark.
A class section can be read through ux-phi by the instructor who owns it, and by nobody else. There is no administrator override: the operator of ux-phi cannot open another instructor’s roster, gradebook, evaluations or transcripts through the site, and no site-wide listing of other people’s classes exists.
Being precise about what that does and does not mean, because the difference matters: it removes standing access through the application. It does not remove the operator’s ability to query the database directly, which is inherent in running the service and which no application-level change can take away. Anyone who tells you otherwise about any hosted service is overstating it. What can be said honestly is that there is no routine path, no interface, and no day-to-day reason to look.
If your institution needs a stronger guarantee than that — contractual limits on operator access, or a support process that runs only on an instructor’s explicit invitation — that belongs in a written agreement with the institution, and is available on request.
When the course consent text changes, the new version gets a new version stamp, and a seat records the stamp it was taken under — so it is always possible to show a student exactly what they agreed to.