In short
- Your data stays on the server that CyberLab runs. Nothing is sold, there is no advertising, and no analytics or tracking scripts are loaded from anywhere else.
- Data leaves that server only through features an administrator chooses to switch on: e-mail, the AI assistant, and IP location lookup. Section 05 explains each one and who would receive what.
- This instance runs in School Mode: the school creates every account, students sign in with a username, and no student e-mail address is needed or collected.
- Instructors can see the work of the students in their own classes. Administrators can see everything on this instance.
01Who is responsible for your data
CyberLab runs this instance on its own server. It decides who gets an account, how the platform is configured, and who on its staff may see what. It is the operator of this instance and the party responsible for the personal data described here. You can reach it at the support address shown at the top of this page once the administrator sets it.
CyberLab is the software. Its developers receive no data from this server and cannot sign in to it, unless they are also the ones operating it. This policy therefore describes how the software behaves as configured here, so that you, or the institution you belong to, can review it against your own obligations.
School Mode
Accounts on this instance are created by the school from its class lists, not by students themselves. The school is responsible for telling students and, where they are minors, their parents or guardians about this platform, and for obtaining any consent that their age and local law require. This policy complements the school's own privacy notice; it does not replace it.
02What is collected
2.1 — Account and profile
- For students: the username the school assigned, your name as it appears on the class list, and your role. The system also stores a generated placeholder address ending in
@school.localthat only exists to satisfy the database; no mail is ever sent to it. - For instructors, administrators and support staff: name, e-mail address and role.
- Your password, stored only as a one-way hash. Nobody, including the administrator, can read it back. The one-time password on your credential slip must be changed the first time you sign in.
- An optional avatar, and for instructors the school name and defaults an administrator set for them.
2.2 — Coursework
- Lecture progress, and every attempt at an in-lecture quiz with its score.
- Lab sessions: which lab, when it started and stopped, the identifier of the container that ran it, hints you opened, flags you submitted and points earned.
- Assignment and course progress, and certificates issued to you.
- Exam attempts and your answers, together with the marks and feedback an instructor gives. If an instructor grants you extra time or attempts for an exam, that setting is recorded; the reason for it is not.
2.3 — Classrooms and communication
- The classes you belong to, the join code you used, your standing on the class leaderboard, and comments you leave under lectures.
- Direct messages, notifications, and support tickets with their replies and any files you attach.
2.4 — Technical and security records
- Your IP address and the time of sign-ins and of security-relevant actions, kept in the audit log.
- An approximate location for that address, only if the administrator has enabled a location lookup (section 05).
- Container identifiers and resource use for your lab sessions, and server-load samples that contain no personal data.
- Short-lived counters used to slow down repeated sign-in attempts and form submissions. They live in memory and are not written to the database.
2.5 — The public Book-a-meeting form
Anyone can ask CyberLab for a walkthrough from the public Classrooms page. The form stores the name, work e-mail, phone, school, role, class size and message entered, together with the sender's IP address, so that staff can follow up. It is not linked to any account.
2.6 — What is not collected
No payment details, no health or financial information, no precise location, no contacts or calendar, nothing from social-media accounts (there are no third-party sign-ins), and no advertising or analytics identifiers.
03How it is used
| Purpose | Data involved |
|---|---|
| Running the platform and keeping you signed in | Account details, session token |
| Teaching, practising and grading | Lecture progress, quiz and exam attempts, lab sessions, flags, assignments, certificates |
| Letting instructors run their classes | Class memberships, progress, attempts and answers, reports, the leaderboard |
| Keeping the instance secure and fair | IP addresses and timestamps, the audit log, rate-limit counters, the CAPTCHA |
| Answering support tickets and meeting requests | Ticket messages and attachments, the meeting form |
| Optional AI help, if the administrator enables it | Your question and the lecture or lab text it is about (section 05) |
| Backups and recovery | Everything above, in an encrypted archive an administrator controls |
Nothing here is used for advertising, profiling, or automated decisions about you. Scores are calculated by the rules your instructor set, and an instructor can always review them.
04Who can see what
- You see your own progress, scores, certificates, messages and tickets.
- Classmates see the class leaderboard. An instructor can show full names, initials only, or switch the leaderboard off, and can hide the class list from students. Comments you leave under a lecture are visible to others reading it.
- Instructors and co-instructors of a class see everything its students do in that class: progress, every attempt and answer, marks, reports, and the credential slips they print. They hold the one-time password they hand you; resetting a password creates a new one-time password and invalidates the old.
- Administrators and support staff can see everything on this instance, including the audit log, tickets, meeting requests and backups.
- The public can see one thing: a certificate's verification page shows the student's name, the class name and the date to anyone who has its link. Links are long random tokens that cannot be guessed. Nothing else is public.
05When data leaves this server
Everything is stored on the server CyberLab runs. Data reaches another organisation only through the features below, each of which an administrator switches on deliberately. Whether a given one is on is part of the server's configuration, which CyberLab can tell you on request; this page does not publish it.
- E-mail — if the administrator configures a mail server, it delivers notifications and the meeting-request messages from the public form. That mail provider sees the addresses and content of those messages.
- AI assistant — if the administrator enables it, the "ask" help inside lectures and labs sends your question and the relevant lecture or lab text to the AI provider the administrator chose: one of Google Gemini, OpenAI, Anthropic or OpenRouter. Your name, e-mail, grades and classmates are not sent. Instructors can switch the assistant off for a class, and the administrator can withhold it from an instructor entirely. The provider's own privacy terms apply to what it receives.
- IP location lookup — if the administrator enables it, the usage report can show where sign-ins come from. The administrator chooses between a database kept on this server, in which case nothing leaves, and the ip-api.com service, in which case the IP address is sent there over an unencrypted connection.
- Lab images — a lab's container image is downloaded from a public image registry when it is first needed. Only the image name is sent; nothing about you.
- The optional desktop client — if your school also uses the CyberLab desktop client, your progress syncs between that device and this server using a device token. No third party is involved.
Fonts, scripts and styles are served from this server. No content is loaded from advertising, analytics or social-media networks.
07How it is protected
- Passwords are stored as bcrypt hashes; one-time passwords must be replaced at first sign-in.
- Sign-in is protected by a rate limit, a security-code image after repeated failures, and a check that requests come from this site.
- Every lab runs in its own container with a memory limit, cannot reach other students' containers, and is destroyed when the session ends.
- Uploaded files are checked by content, not just by name, and are stored with generated names.
- Backups are encrypted archives that only an administrator can create, download or restore.
- Administrative actions are written to an audit log.
- The connection to your browser is protected by the TLS certificate of the server CyberLab runs; that part is theirs to maintain.
No system is perfect. If you find a weakness, please tell the support address shown at the top of this page once the administrator sets it before telling anyone else.
08How long it is kept
- Accounts and coursework are kept for as long as the account exists. A student account also stops working after the last of the student's class terms has ended plus a grace period the administrator sets; the data stays until the school deletes the account.
- When an administrator deletes an account, its progress, attempts, messages, tickets and notifications are deleted with it, and audit-log entries about that person are scrubbed of e-mail address, IP address and location.
- The audit log is not deleted automatically. Administrators can export it and clear it; how often is CyberLab's decision.
- Server-load samples are deleted after 400 days. Meeting requests stay until staff delete them.
- Backups are kept up to the number of archives the administrator configures; older ones are removed as new ones are made. An archive an administrator has downloaded is outside this schedule.
- Lab containers are destroyed at the end of a session. Nothing inside them persists.
09Your rights
Whatever the law where you are calls them, here is what you can ask for and how it is done on this instance:
- See your data. Your dashboard and each class show your progress, attempts and scores. Instructors can print you a progress report.
- Correct it. You can change your avatar in Settings. Your name is fixed to the class list, so ask your instructor to correct it. Passwords are reset by your instructor.
- Delete it. There is no self-service delete button; ask the support address shown at the top of this page once the administrator sets it and an administrator will delete the account as described in section 08.
- Take it with you. Instructors and administrators can export class data as spreadsheets; ask for your part of it.
- Object. If you think something is being collected or used that should not be, say so; the optional features in section 05 can be switched off by the administrator.
Students and their parents or guardians should raise these requests with the school, which will act on them through its administrator. Where laws such as the GDPR, FERPA or COPPA apply, CyberLab is the party that answers to them, following its own procedures.
10Students under 18
This instance may be used by school students, including children under 13. That is possible because the school, not the child, creates the account; the student signs in with a username instead of an e-mail address; and the school controls what the class can reach. There is no self-registration, no public profile, no advertising, and nothing is shared with other organisations except through the features in section 05, which the school controls.
Parents or guardians who want to see, correct or delete a student's data should contact the school; it will act through its administrator.
11Changes to this policy
The date at the top says when this text last changed. When the wording changes in a way that matters, CyberLab will announce it inside the platform. An administrator can also replace this page with the school's own privacy notice.
12Contact
CyberLab
the support address shown at the top of this page once the administrator sets it
Questions about this platform's software, rather than this instance, belong to the CyberLab project.
This document is effective as of September 13, 2026. It describes how this copy of CyberLab, run by CyberLab, is configured and behaves; it is provided for review by your school and is not legal advice.