Privacy Policy

Effective date: 2026-05-09

This Privacy Policy describes how this learning management system (the “LMS”), operated by Eric P. Green, Ph.D. of the Duke Global Health Institute, collects, uses, and protects personal information for the GLHLTH 702O course at Duke University.

Information we collect

  • Identity and contact: name, email address, time zone (collected during course registration and confirmed by you on first sign-in)
  • Course participation: section assignment, condition, invitation status, response timestamps, FERPA and research-consent timestamps
  • Activity data: sign-in events, page views, navigation between the LMS and the Pairthink activity platform, and (within Pairthink) per-question drafts, submissions, AI hint requests, and collaborative-editing operations
  • Technical: IP address and user-agent string at sign-in for audit purposes

How we use information

  • Course operations: enrollment, communications, grading
  • Research: improving the design of the course and the platform. Use of your data for research is governed by the separate research consent you provide at registration.
  • Security and audit logging

Service providers

We use the following sub-processors. Each holds only the data needed for its function and is bound by their own privacy and security commitments:

  • Vercel (US) — application hosting; processes data in transit only
  • Neon (US) — managed Postgres database; encrypts data at rest with AES-256
  • Resend (US) — transactional email delivery; receives only your email address and the content of the messages we send you
  • Cloudflare (US) — DNS resolution only; does not see traffic or content
  • OpenAI (US) — AI grading and feedback inside Pairthink; configured under a zero-data-retention agreement

Retention

  • Sign-in tokens: single-use; expire within 24 hours
  • Invitation tokens: single-use; expire within 7 days
  • Session cookies: 30-day rolling expiration; revoked on sign-out
  • Course and research data: retained for the duration of the study plus 7 years post-publication, per Duke standard, then securely purged
  • Audit log entries: 365 days, then automatically deleted

Your rights

You may request access to your data, correction of inaccurate data, or deletion of your data by contacting the principal investigator. Withdrawing research consent does not remove you from the course; it stops further use of your data for research purposes.

FERPA

This LMS handles student education records subject to the Family Educational Rights and Privacy Act (FERPA). Records are not disclosed outside the course team without your consent except as permitted by law.

Contact

Eric P. Green, Ph.D., Duke Global Health Institute — please use the contact form.