Privacy Policy
How ENKARI LLC collects, uses, stores, and protects your data on the SpaceForge platform.
Effective date: July 15, 2026
1. Who We Are
The SpaceForge platform is owned and operated by ENKARI LLC (“Enkari,” “we,” “us”). Enkari is the data controller for personal information processed on the platform: we decide what is collected and how it is used, and we are the party responsible to you under this policy.
SpaceForge is an independent demonstration platform built to propose a graduate program concept to prospective university partners. It is not operated by, affiliated with, or endorsed by Arizona State University or any other university, and no university receives or has access to platform data. University names appearing in demonstration content are illustrative of a proposed program only.
This policy covers both registered accounts and anonymous visitors to the public demo floor and sandbox.
2. Data We Collect
We collect the data needed to operate the platform and demonstrate its features — nothing beyond that.
Account Information
Name, email address, and account credentials. At registration you may optionally provide a professional background category, a years-of-experience range, and a program interest; these fields are voluntary and can be left blank.
Simulation Telemetry and Scores
For signed-in users, we record simulation runs, decisions made during runs, scores, and debrief results, so your progress and results can be shown back to you.
Deliverables, Reflections, and Messages
Written deliverables and submissions, reflection and journal entries, discussion posts, direct messages, and AI conversation logs created under your account.
Payment Data
If you purchase a paid offering, payment is processed by Stripe. We receive transaction metadata (amount, status, card brand, and similar) but never your full card number.
Usage and Security Data
Login timestamps, pages visited, feature usage, and security-relevant events. IP addresses are processed for rate limiting, abuse prevention, and security logging. We do not sell usage data or use it for third-party advertising.
3. Anonymous Demo Visitors
You can use the demo floor and the public sandbox without an account. For anonymous visitors:
- We do not ask for your name or email, and we do not build profiles of anonymous visitors.
- Interactive demos on the demo floor run on synthetic data in your browser.
- Your IP address is processed transiently to enforce per-visitor run limits (currently five sandbox simulation starts per 24 hours) and for security logging; rate-limit counters expire automatically at the end of their window.
- Sandbox run starts are logged with an anonymized client label for operations and abuse prevention.
- Short-lived operational records (such as transient simulation state) expire automatically within days.
4. How Data Is Stored and Protected
Encryption in Transit
Data transmitted between your browser and our servers is encrypted using TLS. Calls to the third-party services listed in Section 5 are also encrypted in transit.
Application-Layer Encryption at Rest
Sensitive content — direct messages, journal entries, and AI conversation logs — is designed to be encrypted at the application layer using AES-256-GCM authenticated encryption, with a unique nonce per record, where the deployment's encryption key is provisioned. Database backups are managed by our hosting provider.
Access Control
Access to data inside the platform is role-based and follows least privilege: users see their own records, faculty-role accounts see only the work assigned to them, and administrative access is limited by role. Production system access is restricted to authorized Enkari personnel.
No method of transmission or storage is completely secure, and we do not claim certification under any third-party compliance framework. If we become aware of a breach affecting your personal data, we will notify affected users as required by applicable law.
5. Service Providers
We use a small set of service providers to run the platform. Each receives only what its function requires. We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.
Hosting and Storage
The platform and its database are hosted on Railway infrastructure in the United States. Files uploaded to the platform are stored on Vercel Blob when that storage is configured for the deployment, and otherwise on platform server storage.
Email, Payments, and Bot Protection
Transactional email (verification, password reset, notifications) is delivered via Resend. Payments, if offered, are processed by Stripe. Registration and other public forms are protected by Cloudflare Turnstile, which processes a challenge token and connection metadata (including IP address) to distinguish people from bots.
AI Features
AI features (tutoring, feedback, search, AI-assisted scoring) send text to Anthropic and OpenAI APIs for real-time processing. This includes text you enter into AI tools and, where a feature provides AI-assisted feedback or scoring, the submission text being evaluated. Under the API terms we rely on, these providers do not use API-submitted content to train their models by default; they may retain content for a limited period for abuse monitoring under their own policies. We do not send your credentials or payment details to AI providers.
Feature-Dependent Services
Some services run only when the corresponding feature is enabled in a deployment: Google Perspective API screens discussion posts for toxicity before publication (if screening is unavailable, posts are held for review rather than published unscreened); Google and Microsoft Entra ID process sign-ins if you choose OAuth sign-in where offered; Sentry receives error reports and diagnostic context for error monitoring; Plausible, a cookie-free analytics service, counts page views and product events in aggregate without identifying individual visitors; and Inngest schedules background jobs such as notifications and reminders.
6. Cookies and Session
Essential Cookies
We use essential cookies for sign-in sessions, security (including cross-site request forgery protection), and core platform operation. These cannot be disabled without breaking sign-in.
Analytics
Where analytics is active, we use Plausible, which is cookie-free and does not track individuals across sites. We do not use third-party advertising trackers.
7. FERPA Status
ENKARI LLC is a private company. It is not an educational agency or institution receiving federal education funds, and the Family Educational Rights and Privacy Act (FERPA) does not apply to data held on this platform today. No FERPA education records exist on the platform.
The platform's data handling is designed so that, if a university adopts the proposed program, student records could be managed to FERPA-grade standards under that institution's policies, with the institution as the school of record. Unless and until that happens, the commitments that protect your data are the contractual and consumer-privacy commitments in this policy.
8. Data Retention
We retain data only as long as needed for the purposes in this policy.
Account Data and Content
Profile data, submissions, simulation results, messages, and journal entries are kept while your account is active. On a verified deletion request, we remove them within 30 days, except records we must keep for legal, tax, or security reasons (for example, payment transaction records), which are kept only as long as those obligations require.
AI Conversation Logs
AI conversation logs are retained to support quality and integrity review. They are deleted when your account is deleted or on request to the contact in Section 11.
Usage, Security, and Transient Data
Usage data is retained while your account is active and is deleted or anonymized when your account is deleted or on request to the contact in Section 11. Rate-limit counters expire at the end of their window (currently 24 hours), and transient simulation state expires automatically within days.
9. Your Rights
We honor the following for all users as a matter of policy, in addition to any statutory rights you have where you live:
Right to Access
You can view the data associated with your account through the platform at any time.
Right to Correction
You can update profile data in the platform, or ask us to correct inaccurate personal information.
Right to Deletion
You can request deletion of your account and associated data by emailing [email protected]. See Section 8 for what we remove and on what timeline.
Right to Export
You can request an export of your submissions, reflections, and results in a machine-readable format.
Right to Restriction
You can ask us to limit processing of your data in certain circumstances, such as while a correction request is pending.
We verify identity before acting on requests, we aim to respond within 10 business days, and we will not penalize you for exercising these rights.
10. Children
The platform is intended for adults; accounts require users to be at least 18 years old. The platform is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child under 16 has provided personal information to the platform, contact [email protected] and we will delete it.
11. Changes and Contact
We may update this policy from time to time. For material changes, registered users will be notified by email or platform notice before the changes take effect; the effective date at the top of this page reflects the current version. To ask a question, exercise a data right, or report a privacy concern, contact:
ENKARI LLC — SpaceForge Privacy
Email: [email protected]
SpaceForge is an independent demonstration platform of ENKARI LLC and is not operated by or affiliated with any university.
We aim to respond to all privacy inquiries within 10 business days. For urgent matters, include “URGENT” in your subject line.
Last updated: July 15, 2026
View Terms of Use