Privacy Policy
Effective date: September 20, 2026
This Privacy Policy describes how Einbrain Lab ("we", "us", or "our") collects, uses, stores, and shares information when you use our websites, web applications, educational tools, and research prototypes. This includes XR Nook, an Einbrain Lab educational and research virtual-human platform hosted at xrnook.com, its related applications TechNook (tech.xrnook.com), TeachNook (teach.vividta.com), and MedNook (medchat.clinicalnook.com), and AGSTEM Research Studio, which is hosted at agstem.vividta.com.
1. Information We May Collect
Depending on the service you use, we may collect:
- Account information: If you sign in with Google or another provider, we may receive your name, email address, profile image, provider account identifier, and email-verification status.
- Conversation content: The text of each message you send to a virtual character, whether you type it or speak it, and the text of each reply the character returns, along with documents, uploads, feedback, or other content you provide while using our services.
- Voice input: If you use the microphone control, your browser records a short audio clip of your speech so it can be converted to text. Section 5 explains how that audio is handled.
- Usage and device data: Browser type, device type, approximate location derived from IP address, pages viewed, timestamps, referring pages, and interaction logs.
- Application diagnostics: Error logs, performance data, and security-related event records used to maintain reliability and prevent abuse.
- Research records: In some educational or research settings, conversation logs, anonymized activity patterns, or study responses associated with a session or study identifier.
2. How We Use Information
We use information to:
- Operate, secure, and improve our websites and applications.
- Authenticate users and manage access permissions.
- Provide AI-assisted features, simulations, tutoring, or feedback experiences.
- Respond to support requests and maintain service quality.
- Conduct educational research, product evaluation, and internal analysis.
- Comply with legal obligations and protect users, our systems, and our research programs.
3. AI and Third-Party Processing
Some Einbrain Lab services use third-party infrastructure and AI platforms to function. Depending on the application, submitted content may be processed by providers such as:
- Google / Firebase: for authentication, hosting, databases, analytics, and storage.
- Google Cloud Vertex AI (Gemini): for AI-generated character responses, summaries, simulations, or feedback.
- Google Cloud Speech-to-Text: for converting recorded voice input into text.
- Google Cloud Text-to-Speech: for generating the spoken voice of a virtual character.
These providers process data under their own terms and privacy policies. We configure our systems to limit data sharing to what is necessary for the service. Requests to these AI services are sent from our own server functions using our Google Cloud credentials; we do not send your conversations to OpenAI or to any other AI provider outside Google Cloud, and we do not use them to train generalized AI models. These Google Cloud services run inside a project administered under Texas A&M University's Google Cloud environment, so content submitted to them is processed under the university's cloud agreement with Google rather than under a consumer AI service.
4. Google Sign-In and Google Drive Data for AGSTEM Research Studio
AGSTEM Research Studio uses Google Sign-In to authenticate users. Google account data is used only to sign you in, maintain your authenticated session, display your account identity, and secure access to the service. Firebase Authentication maintains the account information needed for sign-in.
AGSTEM Research Studio may offer an optional Google Picker workflow. If you choose to use
it, AGSTEM requests the limited https://www.googleapis.com/auth/drive.file
scope, which permits access only to files you create with or explicitly select for the app.
Google Picker provides the identifier and name of the Google Doc you select so that the app
can construct and display its Google Docs URL in your workspace. AGSTEM does not request
access to all files in your Google Drive and does not read, download, copy, or store the
selected document's contents.
The Google OAuth access token used to open Picker is used temporarily in your browser and
is not persisted by AGSTEM application code. The selected Google Docs URL may remain in
your browser's local storage until you replace it or clear site data for
agstem.vividta.com. Document viewing and editing occur through Google Docs and
remain subject to the file owner's Google sharing settings.
We do not sell Google user data or use it for advertising, analytics, educational research, AI responses, or model training. We do not share Google account data, selected-file metadata, or Google Docs content with OpenAI or other AI model providers, advertisers, data brokers, information resellers, or unrelated third parties. Google user data is processed by Google Firebase, Google Cloud, Google Picker, Google Drive, and Google Docs only as necessary to provide authentication and the user-selected document feature.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized, non-personalized, or personalized AI or machine-learning models.
5. Conversation Logs and Voice Input
XR Nook, TechNook, TeachNook, MedNook, and AGSTEM Research Studio keep a record of the conversations held with their virtual characters. When you send a message, we store the text of your message and the text of the character's reply in a Firebase Firestore database operated by Einbrain Lab inside a Google Cloud project administered under Texas A&M University's Google Cloud environment, together with details of the exchange such as a session identifier, your account identifier, the turn number, timing and latency, model token counts, and the scenario, case, or equipment context. This recording happens automatically for every conversation turn and is part of how these research applications operate.
If you use the microphone control, your browser captures a short audio recording of your speech. Depending on your browser, that recording is converted to text either by the browser's own speech-recognition service, which in Google Chrome sends the audio to Google for recognition, or by Google Cloud Speech-to-Text called from our server functions. We do not keep the audio recording; only the resulting text is stored, in the same way as a typed message. Spoken character replies are generated as audio by Google Cloud Text-to-Speech and are not retained. Your browser asks for microphone permission before any recording begins, and you may decline or revoke that permission at any time and type your messages instead.
We keep these logs to support educational research, to evaluate and improve the learning experience, and to maintain the security and reliability of the applications, as described in Sections 2 and 6. Because conversations are stored, please do not enter names, contact details, health information, student records, or other personal or confidential information into a conversation. The virtual characters are simulations intended for practice and do not provide medical, clinical, legal, or other professional advice.
6. Research and Educational Use
Einbrain Lab develops and studies learning technologies. Information collected through our services may be analyzed for research, educational improvement, or publication purposes. Where feasible, we use de-identified, anonymized, or aggregated data. If a project is part of a formal study, additional study-specific consent or disclosure may also apply.
7. Data Sharing
We do not sell personal information. We may share information only in these circumstances:
- With service providers that support authentication, hosting, storage, analytics, security, or AI functionality.
- With affiliated researchers, instructors, or institutions when necessary for an approved educational or research program.
- When required by law, legal process, or to protect rights, safety, and system integrity.
- As part of a de-identified or aggregated research result that does not reasonably identify an individual user.
8. Data Retention
We retain information only for as long as needed for operational, educational, research, security, and legal purposes. Retention periods vary by application and study context. Conversation logs are kept for the duration of the research program that uses them unless you ask us to delete them sooner. De-identified research records may be retained longer for scholarly documentation.
9. Your Choices
You may have the ability to:
- Choose whether to sign in to certain services.
- Request access, correction, or deletion of information associated with your use, where applicable.
- Stop using the service at any time.
- Ask us to delete the conversation logs associated with your account or session by writing to the address in Section 13.
- Decline or revoke microphone permission in your browser and type your messages instead.
- Revoke AGSTEM's Google access through your Google Account third-party connections.
- Remove a remembered Google Docs URL by clearing site data or local storage for
agstem.vividta.com.
Some data may still be retained when required for security, legal compliance, or approved research records management.
10. Children's Privacy
Some Einbrain Lab projects are designed for educational settings that may involve minors. When a service is used in a school, university, or supervised program, access and consent may be managed by the participating institution, instructor, or parent/guardian as required. We do not knowingly collect unnecessary personal information from children.
11. Security
Einbrain Lab data is held in Google Cloud and Firebase projects administered under Texas A&M University's Google Cloud environment, which is governed by the university's agreements with Google and its information-security and research-data policies. Access to conversation logs and research records is limited to authorized Einbrain Lab personnel and approved collaborators, and is protected by university and Google Cloud access controls.
We use reasonable administrative, technical, and organizational safeguards to protect data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date.
13. Contact
For privacy questions or requests, contact:
einbrainlab@gmail.com
Einbrain Lab, Department of Engineering Technology and Industrial Distribution,
Texas A&M University