← Back to Home

Privacy Policy

Last updated: September 26, 2026 · Effective: September 26, 2026

Introduction

C.O.R.E. (Cyber Operational Risk Education) is a cybersecurity training platform operated by Core Cybersecurity, LLC, an Ohio limited liability company (91 S. 30th Street, Newark, OH 43055, USA). We are committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you use the C.O.R.E. platform.

By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Platform.

Information We Collect

Information You Provide

CategoryDataPurpose
Account InformationFull name, email address, password (hashed)Account creation and authentication
Organization DataCompany name, organization IDEmployer-sponsored enrollment
Training ProgressLesson completion, quiz scores, activity results, final test scores, streak and daily-goal preferencesTrack learning progress and issue certificates
AI InteractionsQuestions you type or dictate to the AI Tutor; your written answers to AI Learning Checks and the resulting feedbackTutoring and personalised feedback on your learning
DepartmentDepartment or team assigned to you by your organization’s administratorRisk reporting by department
Notification SubscriptionBrowser push endpoint, only if you enable study remindersSend the reminders you asked for

Information Collected Automatically

CategoryDataPurpose
Device InformationBrowser type, operating system, screen resolutionPlatform compatibility
Usage DataPages visited, time spent, features usedService improvement
Log DataIP address, access timestamps, referring URLSecurity monitoring
Phishing Simulation ResultsWhether and when you clicked a link in a simulated phishing email sent as part of your organization’s trainingMeasure and improve security awareness

Information We Do NOT Collect

  • Social Security Numbers or government-issued IDs
  • Financial or payment card information
  • Biometric data
  • Precise geolocation data
  • Data from anyone under 18 years of age — the Platform is designed for adults in a professional setting and we do not knowingly collect information from minors

How We Use Your Information

  • Service delivery: Account management, course delivery, progress tracking, certificate issuance.
  • Communication: Registration confirmations, invitations, password resets, completion notifications.
  • Security: Fraud detection, unauthorized access prevention, security incident response.
  • Improvement: Usage analysis to improve content, features, and user experience.
  • Training simulations: Sending simulated phishing emails to employees enrolled by their organization and recording responses, so the organization can measure and improve security awareness.
  • Legal compliance: Compliance with applicable laws and regulations.

Artificial Intelligence Features

The AI Tutor, the AI Learning Checks, the lesson summaries and the administrator reports are generated with large language models provided by OpenAI. Your questions and answers are sent to OpenAI to produce a response and are processed under API terms that prohibit OpenAI from using them to train its models. AI Tutor conversations are not stored by us as a chat history; Learning Check feedback is saved with your training progress. If you use the voice mode, speech recognition is performed by your browser.

We do not use your personal information for targeted advertising or for automated decision-making that produces legal or similarly significant effects. AI-generated feedback is a learning aid and never the sole basis for a decision about you.

Disclosure of Your Information

We do not sell, rent, or trade your personal information to third parties.

Employer/Organization

If enrolled through your employer, your organization’s administrator may access your training progress, completion status, scores, AI Learning Check reports, hands-on activity results, phishing simulation results, department assignment and certificate status. Administrators cannot access your password or your AI Tutor conversations.

Service Providers

We rely on a small number of providers that process data only on our instructions, under contracts that require confidentiality and appropriate security:

ProviderRoleLocation
SupabaseDatabase, authentication and server-side functionsUnited States
NetlifyWeb hosting and content deliveryUnited States (global CDN)
OpenAIAI Tutor, Learning Checks, reports and phishing-simulation text generationUnited States
ResendTransactional email (invitations, password resets, notifications, simulations)United States
Google FontsWeb fonts — your IP address is sent to Google when a page loadsUnited States

Legal Requirements

We may disclose your information if required by law, court order, or governmental regulation.

Data Retention

We keep personal information only for as long as it is needed for the purposes described in this Policy:

DataRetention
Account and profile informationFor as long as your account is active. Deleted or anonymised within 90 days after the account is closed by you or your organization.
Training progress, scores and Learning Check reportsFor the life of the account; completion and certificate records may be kept up to 5 years after completion so that certificates can be verified and your organization can evidence its training obligations.
Phishing simulation results24 months from the simulation, then deleted or aggregated.
Security and access logsUp to 12 months.
Push notification subscriptionsUntil you disable reminders or the browser revokes the subscription.
AI Tutor conversationsNot retained by us beyond the session; processed transiently by our AI provider.

Residual copies may persist in encrypted backups for up to 30 days before being overwritten. We may retain information longer where required by law or to resolve disputes.

Data Security

  • Encryption in transit: TLS 1.2 or higher for all data transmission.
  • Encryption at rest: Sensitive data encrypted in database storage.
  • Password security: Passwords hashed using bcrypt, never stored in plaintext.
  • Access controls: Restricted to authorized personnel on a need-to-know basis.
  • Row Level Security: Database policies ensure users can only access their own data.
  • Content Security Policy: HTTP headers prevent cross-site scripting and injection attacks.

No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

Cookies & Local Storage

TechnologyPurposeDuration
Supabase auth token (localStorage)Maintain authenticated sessionSession duration
Progress data (localStorage)Track lesson and activity completionUntil cleared by user
Preferences (localStorage)Theme, streak and daily-goal settings, installed-app hintsUntil cleared by user
Push subscription (browser)Deliver study reminders you enabledUntil you disable notifications
Service worker cacheFaster loading and offline access to pages you visitedRefreshed on each new release

We do not use third-party tracking cookies, advertising cookies, or analytics cookies.

Your Privacy Rights

All Users

  • Access: Request a copy of your personal information.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion, subject to legal retention requirements.
  • Portability: Request your data in a machine-readable format.
  • Withdraw consent: Where processing is based on consent.

California Residents (CCPA/CPRA)

  • Right to Know: Request categories and specific pieces of personal information collected in the preceding 12 months.
  • Right to Delete: Request deletion, subject to certain exceptions.
  • Right to Opt-Out: We do not sell or share your personal information. No opt-out is necessary.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights.

Contact support@core-aiowl.org. We will respond within 45 days.

Other US States

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with privacy laws may have similar rights. Contact us to exercise any applicable rights.

International Transfers

The Platform is operated from the United States. If you access it from outside the US, your information may be transferred to and processed in the United States. For EEA/UK/Switzerland users, transfers comply with applicable requirements including Standard Contractual Clauses.

Changes & Contact

Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top shows the current version. For material changes we will notify you by email or with a notice on the Platform before the change takes effect. Continued use after that date means you accept the updated Policy.

Contact Us

Questions, requests or complaints about this Policy or your personal information:

  • Email: support@core-aiowl.org
  • Mail: Core Cybersecurity, LLC, 91 S. 30th Street, Newark, OH 43055, USA

If you are enrolled through your employer, you may also direct requests about your training data to your organization’s administrator, who controls that data.

© 2026 Core Cybersecurity, LLC. All rights reserved.

Terms of Service

Last updated: September 26, 2026 · Effective: September 26, 2026

Acceptance of Terms

By accessing or using the C.O.R.E. platform, a cybersecurity training platform operated by Core Cybersecurity, LLC, you agree to be bound by these Terms of Service. If you do not agree, you may not use the Platform.

If you are using the Platform on behalf of an organization, you represent that you have the authority to bind that organization to these Terms.

Eligibility

  • You must be at least 18 years of age.
  • You must provide accurate and complete registration information.
  • Employer-sponsored access is subject to both these Terms and any agreements between your employer and Core Cybersecurity, LLC.

Account & Security

  • You are responsible for maintaining the confidentiality of your account credentials.
  • Notify us immediately of any unauthorized use of your account.
  • You may not share credentials or allow others to access your account.
  • We may suspend or terminate accounts that violate these Terms.

Acceptable Use

You agree not to:

  • Copy, reproduce, distribute, or publicly display any Platform content without written consent.
  • Reverse engineer, decompile, or disassemble any part of the Platform.
  • Use the Platform for any unlawful purpose.
  • Attempt to gain unauthorized access to any part of the Platform or connected systems.
  • Use automated tools (bots, scrapers) to access the Platform.
  • Share, distribute, or publish quiz answers, test questions, or assessment content.
  • Misrepresent your identity or impersonate another person.
  • Interfere with the Platform's operation or security.

Intellectual Property

All content on the Platform — including lessons, videos, quizzes, activities, graphics, text, software, and design — is the exclusive property of Core Cybersecurity, LLC or its licensors and is protected by United States and international intellectual property laws.

You may access content solely for personal educational purposes. You may not reproduce, modify, distribute, sell, or create derivative works without express written permission.

"C.O.R.E.," "Cyber Operational Risk Education," and associated logos are trademarks of Core Cybersecurity, LLC.

Certificates

  • Issued upon successful completion of all required coursework (lessons, hands-on activities and the final test).
  • Non-transferable and issued to the individual who completed the training.
  • Represent completion of the C.O.R.E. program — not a professional certification, license, or accreditation.
  • May be revoked if obtained through fraud, cheating, or violation of these Terms.

Employer Accounts

  • Your employer's administrator may view your training progress, completion status, scores, AI Learning Check reports, hands-on results, phishing simulation results and department assignment.
  • Your employer may run simulated phishing exercises as part of your training; these are internal exercises commissioned by your organization.
  • Your employer may remove your access at any time.
  • Access may be revoked upon termination of employment or the employer's contract.

AI Features & Phishing Simulations

  • The AI Tutor, AI Learning Checks, lesson summaries and reports are generated automatically by large language models. They may be incomplete or inaccurate and are provided as a learning aid only. They are not legal, compliance or security advice; verify anything you rely on and consult a qualified professional for decisions affecting your organization.
  • Simulated phishing emails are training exercises sent at the request of, and to the employees of, the organization that enrolled you. They are never sent to third parties.
  • Company names, logos and visual styles that appear in simulations are used solely to make the exercise realistic. They belong to their respective owners, who are not affiliated with Core Cybersecurity, LLC and do not sponsor or endorse the Platform.
  • You may not use the simulation tools against anyone outside your organization or for any purpose other than authorized security-awareness training.

Indemnification

You agree to indemnify and hold harmless Core Cybersecurity, LLC from any claims, liabilities, damages, and expenses arising from your use of the Platform, violation of these Terms, or violation of any law or third-party rights.

Termination & Availability

  • We may suspend or terminate your access at any time, with or without cause.
  • You may terminate your account by contacting us.
  • We do not guarantee uninterrupted access and may modify or discontinue any part of the Platform.
  • The Intellectual Property, Indemnification, Disclaimer of Warranties, Limitation of Liability and Governing Law sections survive termination.

Disclaimer of Warranties

The Platform and all content are provided “as is” and “as available”, without warranties of any kind, express or implied, including implied warranties of merchantability, fitness for a particular purpose, accuracy and non-infringement. We do not warrant that the Platform will be uninterrupted or error-free, that defects will be corrected, or that completing the training will prevent any security incident. Security-awareness training reduces risk; it does not eliminate it.

Limitation of Liability

To the fullest extent permitted by law, Core Cybersecurity, LLC and its members, officers, employees and contractors will not be liable for any indirect, incidental, special, consequential or punitive damages, or for any loss of profits, revenue, data or business opportunity, arising out of or related to your use of the Platform, even if advised of the possibility of such damages.

Our total aggregate liability for all claims relating to the Platform will not exceed the greater of (a) the amount paid to us for your access in the twelve months preceding the claim, or (b) one hundred US dollars (USD 100). Some jurisdictions do not allow certain limitations; in those jurisdictions our liability is limited to the extent permitted by law.

Governing Law & Disputes

These Terms are governed by the laws of the State of Ohio and the federal laws of the United States, without regard to conflict-of-law rules. Before starting any formal proceeding you agree to contact us at support@core-aiowl.org and to try in good faith to resolve the dispute informally for 30 days. Any dispute that is not resolved informally will be brought exclusively in the state or federal courts located in Licking County, Ohio, and you consent to their jurisdiction. Nothing in this section prevents either party from seeking injunctive relief to protect intellectual property or confidential information.

Changes & Contact

Changes to these Terms

We may revise these Terms. The “Last updated” date shows the current version; material changes will be announced by email or on the Platform before they take effect. Continued use after that date means you accept the revised Terms. If any provision is held unenforceable, the remaining provisions stay in force. These Terms, together with the Privacy Policy and any agreement between your organization and Core Cybersecurity, LLC, are the entire agreement regarding the Platform.

Contact

  • Email: support@core-aiowl.org
  • Mail: Core Cybersecurity, LLC, 91 S. 30th Street, Newark, OH 43055, USA

© 2026 Core Cybersecurity, LLC. All rights reserved.