What this programme records about you, and what it never touches
GenAI Mindset keeps a record of how you move through the programme, so that the organisation that enrolled you can tell whether it is being used and where people get stuck. This page says exactly what that record contains. It is written to be read rather than to be filed — if anything here doesn’t match what you were told, the mismatch is a fault worth reporting.
Last updated 8 September 2026. This page describes the hub as it is deployed today, not an intention.
Your employer commissioned this programme and gave us your name and work email so that we could send you a personal link. As you work through the chapters, the hub records which screens you reached, which quiz options you chose, and how long you spent — the shape of your progress, not your thoughts.
Everything you type into a reflection or a commitment field stays in your own browser. It is never uploaded, so nobody at your employer and nobody at The Smarty Train can read it. What leaves your browser about a reflection is whether you filled it in and roughly how long it was.
There is no advertising, no tracking across other websites, no profiling and no sale of anything to anyone. The only third party involved is Microsoft, who host the site, the database and the error-monitoring service.
| What | Why it exists |
|---|---|
| Your name, work email, and job title or team if your employer supplied one | To issue your personal link and to show your progress on your organisation’s roster. Supplied by your employer, not by you. |
| When you first opened your link, and the last time you visited | The “activated” and “last seen” figures — the difference between a programme nobody opened and one people are working through. |
| Which chapters and sessions you have marked complete | Completion reporting. This mirrors the progress your browser already keeps, so a new device picks up where you left off. |
| Which screen of a chapter you reached, in what order, and how long you paused before moving on | To find the screens where people stop. This is the one measure that shows a chapter is losing readers halfway rather than at the end. |
| Which option you chose in a quiz, whether it was right, and how many attempts you made | To find questions that are unclear rather than hard. Attempts are counted because trying again is a good outcome, not a failure. |
| For a reflection or free-text field: that you completed it, and its length as a number of characters | To report whether people are engaging with the reflective work. The text itself never leaves your browser — see below. |
| Whether you are on a phone or a larger screen, and whether your device asks for reduced motion | Those two settings change what you are actually shown, so a figure compared across them would otherwise be comparing two experiences. |
| A random identifier for each page load | To put one visit’s events in order. It is not stored anywhere on your device and is different every time you load the page. |
| A diagnostic note if the 3D brain fails to load | The brain is the centrepiece of the experience and there is no fallback for it. Without this event, nobody would know it had broken. |
Times are recorded on our server’s clock, not your device’s. A device with the wrong date would otherwise place your work in the wrong week.
The words you write. Reflections, commitments, “this week” notes and every other free-text field are held in your browser’s local storage and are never transmitted. This is enforced in three places: the emitter that sends events deletes any text value before sending, the server rejects a text answer that arrives carrying content, and the database itself refuses to store one. No administrator asked to read them, and none can.
Your identity, in the monitoring service. The same behavioural events are copied to Microsoft Application Insights so that faults can be diagnosed, but with every identifier stripped first — no name, no email, no link, no learner reference. What arrives there is a shape of activity that cannot be traced back to a person.
Anything about you elsewhere. No advertising or analytics network is loaded, no cross-site cookie is set, no fingerprinting is attempted, and nothing you do on other sites is visible to this one.
Your precise location. As with any web request, Microsoft’s services see the IP address your request came from. It is used to infer a coarse region for fault diagnosis and is not stored alongside your events.
The learner hub sets no cookies at all. Your progress and your survey answers live in your browser’s local storage, under the keys genai-progress and byb-prefs. Clearing site data for this address removes both, and the hub carries on working — it will simply think you are new.
The administrator panels do set one cookie, when an administrator signs in. It holds a session reference only, is inaccessible to page scripts, is sent only to this site, and expires after eight hours with no renewal — so a forgotten browser session closes itself.
Your invitation is a single web address containing a key. Anyone holding that address can open the programme as you, so treat it as you would a password: don’t forward it, and don’t paste it anywhere public.
The key is stored on our side as an irreversible digest, so we cannot recover or re-send the original — a lost link is replaced with a new one, which invalidates the old. Opening your link on a second device is expected and supported; the two records merge rather than compete.
The lawful basis is legitimate interests under Article 6(1)(f) of the UK GDPR. Your employer paid for a learning programme and has a genuine interest in knowing whether it is being used, where people struggle, and whether it is worth continuing. We rely on that basis rather than on consent because a consent request from your employer’s learning platform is not a free choice, and pretending otherwise would be worse, not better.
The balance is kept by what is not collected. Your reflection text — the most personal thing the programme touches — stays on your device and is not sent to us, unless your employer has switched on the AI features described below and you choose to use one. If you disagree with that balance you have the right to object; the section below says how.
Your employer decides who is enrolled and who may see the reports: in data-protection terms they are the controller, and The Smarty Train operates the platform on their instruction.
Parts of this programme can be supported by an AI assistant. It is off unless your employer turns it on, and where it is off, nothing in this section applies to you.
Where it is on, the assistant is asked a question about the screen you are reading, and a record of that exchange is kept. That record can be read by the administrators at your own organisation who run the programme, and every time one of them opens it, the fact that they did is logged. Records are kept for a limited period set by your employer, up to a maximum of one year, and are then deleted.
Your own typed words are treated separately and more carefully. They are sent to the AI assistant only where your employer has specifically allowed it, which is a second switch and is off by default. Where it is not allowed, the assistant is asked about the screen and never about what you wrote.
Before the first time you use an AI feature you will be shown a short note saying what is recorded, and nothing is sent until you accept it. That note is versioned: if what we keep changes, you are asked again rather than being moved silently onto new terms.
What we can no longer promise. An earlier version of this page said that nothing here is used to assess, rank or discipline anyone. Now that your employer's administrators can read individual AI exchanges, that is not ours to promise: what your organisation does with what it can see is its decision, not ours. We have removed the sentence rather than leave it standing in a weaker form, because a reassurance we cannot keep is worse than none. Your right to object, and to ask what is held about you, is unchanged and is set out below.
| Who | Sees |
|---|---|
| Your organisation’s nominated administrator | Your name, email, and your progress through the programme — chapters completed, screens reached, quiz accuracy, whether reflections were filled in. Where AI is switched on, also the record of your AI exchanges, and every time they open one it is logged. Their view is restricted to their own organisation, and that restriction is enforced by the database, not only by the application. |
| The Smarty Train programme team | The same information, across all client organisations, for support and for improving the programme. Administrative actions are logged. |
| Microsoft (Azure, UK South) | Hosts the site, the database and the error-monitoring service. The monitoring copy has no identifiers in it. |
| The AI provider, where AI is switched on | The question put to the assistant, which describes the screen you are reading. It includes words you typed only where your employer has allowed that specifically, which is off by default. Your name and email are never sent. The provider answers the question and is not permitted to use what is sent to train its models. |
| Anyone else | Nobody. Nothing is sold, shared for advertising, or handed to a third party except where the law requires it. |
Completion is self-declared: the hub records what you mark as finished. Reports show it as such, so a figure is never presented as verified when it is not.
The programme database is hosted in the United Kingdom, and so is the monitoring service. Nothing is transferred outside the UK or the EEA.
Your record is kept for as long as your organisation’s programme runs. When that engagement ends, the organisation’s tenancy is deleted, and every learner record, progress row, event and answer belonging to it is removed with it. The identity-stripped copies in the monitoring service age out on Microsoft’s standard ninety-day retention.
A fixed retention period for behavioural events inside the programme database has not yet been set. Until it is, events are removed on request or when the engagement ends, whichever comes first — and we would rather say so than imply a policy that does not exist.
You have the right to ask what is held about you, to have it corrected, to have it deleted, and to object to it being collected at all. None of those requests needs to be justified, and making one has no effect on your access to the programme.
The quickest route is your organisation’s nominated programme administrator — they are named in the email that carried your invitation, and they can correct your details, deactivate your record, or ask us to delete it outright. If you would rather not go through your employer, contact your organisation’s usual contact at The Smarty Train and the request will be handled directly.
A deletion removes your learner record and, with it, your progress, your events and your answers — the database is set up so that they cannot be left behind. Anything held in your own browser is yours to clear at any time by clearing site data for this address.
If you are not satisfied with how a request was handled, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint.