Skip to main content

Privacy Policy

How we protect your data

Effective August 24, 2026 V5.1 finalized contract

Who we are

TEPE CONSULTING LLC operates Ministry Sandbox, a simulation platform for ministry formation and seminary classrooms. Students and practice participants rehearse difficult pastoral conversations with AI characters and receive formative feedback. In academic modes, faculty remain responsible for final grades.

This privacy policy describes how we collect, use, and protect your information during the pilot program.

What information we collect

When you create an account and use Ministry Sandbox, we collect:

  • Account information: Your email address, full name, seminary affiliation, and optional profile details.
  • Submissions: The text you write when responding to scenarios and case studies.
  • Assessment records: Faculty-confirmed grades, rubric scores, and feedback.
  • Formation records: Reflection journal entries and, when you choose a voice feature, relevant recordings or transcriptions.
  • Usage information: When you log in, which modules you complete, and how you interact with the platform.

How AI is used

An AI system (currently Google Gemini) reads your submission and relevant case context to generate the next scenario and formative written feedback. In academic modules, AI may also propose rubric evidence, scores, and an assessment summary for faculty review.

Only faculty-confirmed scores are final. An AI proposal does not become your grade until a faculty member has reviewed and approved (or adjusted) it.

What data is sent to AI providers

  • The text of your submission
  • The relevant module, scenario, and prior session context, plus the rubric when the task is assessed

We do not send your email address, name, date of birth, or contact fields as separate prompt data to AI providers. The text you write is sent as written and may itself contain identifying information, so use fictional names for real people.

Cross-border processing: Google may process your text on servers outside your country. The active account region, logging, retention, and contractual controls require current operator verification. Google Gemini is the only server-side generative AI provider in current application source.

Product analytics

We may use the third-party product analytics service PostHog to understand how the platform is used and improve the user experience. This integration is optional and is loaded only when it is enabled in the application configuration.

When enabled, PostHog collects:

  • Page views and navigation patterns
  • Button clicks and form interactions (autocapture)
  • Browser type, device type, and basic technical information

PostHog uses a public project key (not a secret) and all events are tagged with the product identifier. When the analytics feature is disabled, no tracking snippet is loaded and no data is sent.

Optional voice features

When voice features are enabled and you choose to use them, ElevenLabs receives scenario text for read-aloud or your short audio recording for speech-to-text transcription. Spoken academic modules may also retain a copy of the recording for the same authorized instructor review as the written transcript.

Voice features are unavailable when the integration is not enabled. You can continue by reading and typing instead.

How we use your information

  • Service delivery: provide simulations, feedback, learner progress, faculty review, support, security, and required assessment or dispute records.
  • Product improvement: evaluate and improve Ministry Sandbox where authorized. Longer-term analysis should use de-identified, aggregated, or otherwise minimized data when identifiable records are not necessary.
  • Research: identifiable learner work is not licensed for unrestricted research. A research use requires a separate, compatible institutional and participant authority.
  • Model training: TEPE CONSULTING LLC does not authorize student work for third-party foundation-model training through these terms.
  • Marketing or publication: we do not sell student work or publish identifiable work for marketing under this policy. Separate permission is required.

Data retention

We use a category-based retention contract rather than claiming that every identifiable record is kept forever or for one universal period.

  • Active service and educational records: retained while needed to provide the service, support longitudinal learner formation, and meet an approved institutional program need.
  • Assessment and audit records: retained as needed for academic record integrity, faculty review, disputes, and applicable institutional or legal requirements.
  • Journal and formation records: retained only while needed for approved formation and service purposes, subject to the relevant institutional agreement and deletion obligations.
  • Operational and security records: retained for reliability, fraud prevention, investigation, and incident response only as long as reasonably necessary.
  • Provider operational data: governed by the enabled provider, account configuration, and applicable agreement.
  • De-identified or appropriately aggregated data: may be kept longer for authorized product and longitudinal analysis when it no longer identifies a learner.

Exact periods may be set by an institutional agreement, applicable law, deletion duty, or an approved stricter institution policy. Current implementation thresholds and unverified provider settings are documented in the retention policy; they are not an unlimited right to retain identifiable institutional student data.

Who can access your data

Access to your data is limited to:

  • Authorized faculty or cohort leaders with a legitimate educational relationship to your learner, course, or cohort. Course-linked journal reflections may be reviewed for formation; unlinked reflections remain visible only to you.
  • TEPE CONSULTING LLC platform operators when access is necessary for support, security, incident handling, or an approved product purpose
  • AI providers (Google) who process submissions as described above
  • Service providers that host the application and database, deliver transactional email, monitor errors, provide optional analytics or voice features, or store recordings when those integrations are enabled

Other students and unrelated faculty cannot access your work. We do not sell or share your data with third parties for marketing purposes.

Your rights

You have the right to:

  • Request access to the personal data we hold about you
  • Request deletion, subject to applicable institutional record-keeping, audit, legal, and contractual duties
  • Request human review of an AI proposal or consequential academic decision through your instructor or institution. The responsible faculty or institutional reviewer remains the decision-maker. Timing follows the relevant institution or separate agreement, not a universal product deadline.

To exercise these rights, contact your instructor or write to [email protected] .

Security

Current application source includes the following controls:

  • Production settings that require HTTPS redirects, secure cookies, and transport-security headers
  • Role, ownership, course, and institution access checks in application routes and queries
  • Environment-based secret handling, rate limits on sensitive endpoints, audit records for grading, and OTP on selected operator surfaces
  • Conditional monitoring and logging when the relevant integration is configured

These controls are source verified. Live encryption-at-rest, backups, provider membership, regions, monitoring, logging, retention, DPA status, and account-level security remain operational checks in the target environment and are not represented here as currently verified guarantees.

Security incidents

Report a suspected security or privacy incident to the contact below. TEPE CONSULTING LLC coordinates technical investigation and works with the responsible institution and enabled providers. Notice, remediation, and response timing depend on the incident, applicable law, and institutional or provider agreements; this policy does not invent a universal incident-response guarantee.

Changes to this policy

We may update this privacy policy from time to time. Material changes to access, retention, data purposes, AI processing, or consequential privacy terms receive a new applicable consent version and require re-acceptance before continued relevant participation. Prior acceptance records remain historical and are not reinterpreted.

Contact us

For questions about this privacy policy or how we handle your data, contact [email protected] .

Generating response…

This usually takes less than 12 seconds. Your response is saved. Please stay on this page.