Operator and scope
Mission AI Academy is operated by Thien-Nga T Vo, DBA TVT Software Consulting, 1112 Masonic Avenue, San Francisco, CA 94117. Contact tisa@leafandburr.com or 415-793-2254 with privacy questions. This notice describes the application’s current behavior; the hosting and sign-in providers also process information under their own terms.
Information the application receives
Account activation uses a one-time link provided by your administrator after identity verification. The application stores a salted password hash, never your plaintext password. It stores hashed session and activation tokens, expiration times, and sign-in attempt counters. Administrators supply enrollment information such as name, email, cohort, role, and active status. Training records include exercise responses, completion dates, assessment answers and scores, attempt history, last-seen time, and activity events. A quote inquiry includes the name and contact email you provide, organization, requested seats, message, and submission time. Inquiry email addresses are not automatically verified.
Why the information is used
Account information connects learners to their enrollment and permissions. Learning records support saving work, grading assessments, issuing certificates, and reporting progress. Administrative events help track account and learning activity. Inquiry information is used to review and respond to requests. The application does not enroll inquiry senders into an automatic marketing list.
Who can access records
Learners can access their own training records through the application. Authorized administrators can manage enrollment and see individual and cohort progress and report exports. The product owner can review commercial inquiries. The operator and service providers may process stored information to operate and maintain the service. Authorized administrators can download reports, which may then be handled under their organization’s policies. The application does not make learner records public.
Hosting, identity and AI processing
The service is hosted through OpenAI Sites, using Cloudflare infrastructure and a hosted database. Learner sign-in uses academy email and password; a ChatGPT account is not required. The hosting service may process technical connection and security information, including IP addresses; this page does not independently establish their retention periods or data locations. The training application does not send exercise responses to an external AI model for generation or grading. Its assessments use predefined questions and server-side scoring.
Public samples and browser data
The sample lesson uses temporary page memory for practice selections and notes. It does not send those responses to the training database, and reloading clears them. Regular site requests still pass through the hosting service. The application does not add advertising pixels or third-party marketing analytics. The academy uses an essential, secure, HTTP-only session cookie. Sessions expire after eight hours or 30 minutes without authenticated requests. Hosting services may also use cookies. No application-specific response to Do Not Track signals is implemented.
Retention and requests
The current application retains enrolled training records and inquiry records until the operator takes action; automatic expiry is not implemented. Deactivating an enrollment disables access but does not erase history. Contact the operator to request access, correction, or deletion, using your account email and identifying the request without sending sensitive records. Identity and organizational authority may need verification. Retention and deletion may also depend on applicable requirements and the customer’s written agreement. Customer-specific retention and closeout arrangements must be agreed before deployment.
Permitted information and security
Use fictional exercise data or authorized public information. Do not enter classified information, CUI, credentials, personal personnel records, or operationally sensitive material. The application uses authenticated access and role checks, but no independent security certification or government authorization is claimed. If you suspect a disclosure, stop adding information and use the support contact; do not send the sensitive material again.
Changes and external services
This notice is dated September 16, 2026. Material changes should be reflected in an updated notice. Links to external sites are subject to those providers’ practices. Contact the operator for clarification before submitting information if this notice does not address your organization’s requirements.