Privacy on Aegis
This page is maintained by the institution operating this Aegis instance and describes the controls and defaults enabled in the app. It is not an independent certification.
Data we capture during assessments
- Identity: face photo and face-plus-ID photo before the exam, and a post-submission face snapshot.
- Integrity: webcam snapshots and, where required by the assessment, session recordings.
- Academic: written answers, uploaded files, audio recordings, and typing/paste behaviour.
How long we keep it
- Marks, rubric scores, answer text, transcripts, and audit logs — indefinitely.
- Biometric-adjacent media (photos, snapshots, recordings, submissions) — 30 days after submission, then archived offline and removed from the live system.
Controls enabled today
- Explicit consent screen with linked privacy notice before any camera capture.
- All media stored in private storage buckets; access via short-lived signed URLs only.
- Row-level security scoped to the student or authorised staff by role.
- Raw IP addresses are hashed with a per-project pepper, not stored.
- Admin-triggered fortnightly retention workflow with SHA-256 checksums.
- Self-serve student data export (portability).
Your rights
Access, rectification, restriction, portability, and erasure. Signed-in students can download their data from within the student area. For erasure, contact the institution's data-protection officer.