Privacy Policy
Effective date: 2026-05-09
This Privacy Policy describes how this learning management system (the “LMS”), operated by Eric P. Green, Ph.D. of the Duke Global Health Institute, collects, uses, and protects personal information for the GLHLTH 702O course at Duke University.
Information we collect
- Identity and contact: name, email address, time zone (collected during course registration and confirmed by you on first sign-in)
- Course participation: section assignment, condition, invitation status, response timestamps, FERPA and research-consent timestamps
- Activity data: sign-in events, page views, navigation between the LMS and the Pairthink activity platform, and (within Pairthink) per-question drafts, submissions, AI hint requests, and collaborative-editing operations
- Technical: IP address and user-agent string at sign-in for audit purposes
How we use information
- Course operations: enrollment, communications, grading
- Research: improving the design of the course and the platform. Use of your data for research is governed by the separate research consent you provide at registration.
- Security and audit logging
Service providers
We use the following sub-processors. Each holds only the data needed for its function and is bound by their own privacy and security commitments:
- Vercel (US) — application hosting; processes data in transit only
- Neon (US) — managed Postgres database; encrypts data at rest with AES-256
- Resend (US) — transactional email delivery; receives only your email address and the content of the messages we send you
- Cloudflare (US) — DNS resolution only; does not see traffic or content
- OpenAI (US) — AI grading and feedback inside Pairthink; configured under a zero-data-retention agreement
Retention
- Sign-in tokens: single-use; expire within 24 hours
- Invitation tokens: single-use; expire within 7 days
- Session cookies: 30-day rolling expiration; revoked on sign-out
- Course and research data: retained for the duration of the study plus 7 years post-publication, per Duke standard, then securely purged
- Audit log entries: 365 days, then automatically deleted
Your rights
You may request access to your data, correction of inaccurate data, or deletion of your data by contacting the principal investigator. Withdrawing research consent does not remove you from the course; it stops further use of your data for research purposes.
FERPA
This LMS handles student education records subject to the Family Educational Rights and Privacy Act (FERPA). Records are not disclosed outside the course team without your consent except as permitted by law.
Contact
Eric P. Green, Ph.D., Duke Global Health Institute — please use the contact form.