CALLIOPE protects assessment work through clear boundaries, role controls, and accountable AI use.
CALLIOPE combines a product-facing website with an authenticated platform runtime for transcripts, source uploads, AI-assisted assessment, review, and usage controls.
Data minimization
CALLIOPE should collect the oral transcript, assessment, media, account, and telemetry data needed for the active workflow, not unrelated personal data.
Human review
AI-generated scores remain drafts until an authorized educator reviews and publishes them to the assigned learner.
AI boundaries
AI features process selected rubric context and voice streams to answer a request. Private user content is not used for public model training by default.
Architecture boundary
calliopespeak.com serves product and policy pages alongside authenticated CALLIOPE runtime paths. The runtime uses the shared LearnAdapt backend for accounts, assessment history, transcripts, AI requests, credits, and security controls.
What stays shared
- User accounts and roles.
- Dialogue transcripts, source uploads, rubrics, and assessment history.
- Credits, usage logs, and billing events.
- Consent records and available security or usage logs.
- AI provider controls and safety checks.
Encryption and transport
Authenticated sessions and platform traffic should use HTTPS/TLS. Storage services should use managed encryption and access controls appropriate to the environment.
Role-based access
Students, educators, researchers, administrators, and system administrators should receive only the permissions needed for their role and project context.
Auditability
Important service actions, AI requests, uploads, role changes, consent records, and administrative actions should be logged for investigation and compliance.
Privacy and legal alignment
CALLIOPE's governance model is designed to support Singapore PDPA principles such as accountability, consent, purpose limitation, notification, access and correction, protection, retention limitation, transfer limitation, and breach notification. For international use, CALLIOPE should also support GDPR/UK GDPR rights, applicable U.S. state privacy notices, and education-specific requirements in institutional agreements.
Incident response
If a security or data incident occurs, CALLIOPE should investigate, contain, document, and notify affected users, institutions, regulators, or authorities where legally required. Notification timing depends on the applicable law and the risk of harm.
AI and media safeguards
- AI features should use only the rubric context needed for the requested task.
- Microphone audio is processed for transcription and speech interaction; the current prototype does not intentionally retain the raw session recording.
- Educator-provided text and public web sources may be processed to support the assessment.
- Users should avoid uploading confidential, regulated, or third-party content unless authorized.
- Research exports should include only consented data and approved study fields.
Report a concern
Report security, privacy, account, or data protection concerns to nizam.kadir@learnadaptresearch.org. Include the affected account, assessment, timestamp, and a clear description where safe to do so. Do not send passwords or highly sensitive files by email.