Data Handling, Security and Accessibility
What the Conversational Assessment LTI tool receives from Canvas, Moodle or another LMS, where it goes, who can see it, and how long it stays. Reviewed 2026-10-09.
Two Kinds of Commitment
A registration is one LMS's installation of the tool. An institution's agreement covers its registration, so some commitments are settings on that registration. The rest hold for every user of the tool.
| Commitment | Applies to |
|---|---|
| A retention window: student attempts are deleted a set number of days after their last activity | Per registration, set by the site administrator. Without a window, data is kept until someone deletes it. |
| Hosted models only: attempts run on the models described below, never on an instructor's own AI endpoint | Per registration, set by the site administrator |
| Export, then destroy, everything a registration holds when an agreement ends | Per registration, on request |
| Instructor deletion of one attempt or a whole course's data | Every registration |
| Encryption in transit, access control, no prompt storage at the model gateway, no analytics or advertising | The whole service |
University of Illinois. The Canvas@Illinois registration will have a 365-day retention window and hosted models only. Both are set when Canvas@Illinois creates the registration, before the first student launch.
What the Tool Receives and Stores
Students never create an account. The LMS identifies them in a signed launch, and the tool keeps only what it needs from that launch. The registration asks Canvas for privacy level public, which is what makes Canvas send a name and email.
| Data | Where it comes from | Why it is kept |
|---|---|---|
LMS user ID (the opaque sub) | Every launch | Tells one student's attempt from another's |
| Name and email | Every launch, when the LMS sends them | So the instructor can see who took the assessment. Without them the results page shows the LMS user ID. |
| LMS roles | Every launch | Decides whether a launch sees the student page or the instructor results |
| Course ID, code and title; assignment ID and title; deployment ID | Every launch | Ties attempts to the right course and assignment |
| Gradebook service addresses | Every launch | Where to post the score |
| The conversation: the student's messages and the interviewer's replies | Created in the tool | It is the assessment, and the evidence for its grade |
| The evaluator's per-turn notes, the grade, portion grades, feedback, and a review flag | Created in the tool | Grading, and instructor review of the grade |
| The score sent to the gradebook, with the grade and feedback as a comment | Created in the tool | The request and the LMS's response are kept 7 days after sending, to answer “where is my grade”, then cleared |
| Launch records | Every launch | Verifying the launch. Deleted once they expire, within hours. |
| Model usage: model name, token counts, cost | Created in the tool | Spend accounting. No message content. |
Not kept: the LMS's signed launch token itself, student ID numbers or other SIS identifiers, photos, and the course roster.
The tool asks for four LTI scopes, all for the gradebook (Assignment and Grade Services): lineitem, lineitem.readonly, result.readonly and score. It does not ask for the roster (Names and Role Provisioning). The site uses no analytics, advertising or third-party trackers. The only cookie a launch sets binds the launch to the browser and is cleared when the launch completes.
Who Can See What
| Who | What they can see or do |
|---|---|
| A student | Their own conversation, grade and feedback. Never the rubric, the answer key, or anyone else's attempt. |
| The instructor who connected the course | Every attempt in that course: name and email, status, grade, review flag, transcript, and whether the score reached the gradebook. They can delete one attempt or all of the course's student data. They see per-criterion progress only for assessments they wrote. |
| Others with a teaching role in the LMS course (co-instructors, TAs, designers) | The same results and transcripts, opened from the LMS. They cannot delete. |
| The LMS gradebook | The score, with the grade and feedback as a comment |
| The site administrator (one person, the project lead) | Registration settings, export and destroy, and the database, for operations and support |
No vendor, advertiser or other third party receives student data, with two exceptions: the language models receive conversations as described next, and database backups are copied to Illinois Box, the University's Box service.
Where It Is Processed
- Application and database. A Kubernetes cluster on University of Illinois virtual machines, provided by Technology Services and managed by Engineering IT Shared Services, in a university datacenter. TLS terminates on a university web server,
cs124-frontend-01.cs.illinois.edu. - Language models. On hosted models, every turn calls two models: an interviewer (
gpt-6-luna) and an evaluator (gpt-6-sol). They run on an Azure OpenAI resource in the University of Illinois Microsoft tenant, provisioned by the Illinois GenAI Solutions Hub (Technology Services), in the North Central US region. The application reaches them through a model gateway in the same cluster. - What the models receive. The conversation so far and the instructor's assessment: the questions, and for the evaluator only, the rubric and answer key. Never the student's name, email or LMS ID.
- What the gateway keeps. Usage metadata only (model, token counts, cost), for 90 days. It is configured not to store prompts or responses.
- Microsoft's terms. Microsoft states that Azure OpenAI prompts and completions are not available to OpenAI or other customers and are not used to train models (Data, privacy, and security for Azure OpenAI).
- Instructors' own endpoints. An instructor may connect their own AI endpoint. On a registration set to hosted models only, that endpoint is never used for its attempts.
Retention and Deletion
- Retention window (per registration). Attempts are hard-deleted a set number of days after their last activity, with their transcript, grades and score record. Student identities with nothing left are deleted too. A registration without a window keeps data until someone deletes it.
- Instructor deletes. The instructor who connected a course can delete one attempt from its page, or every attempt in the course from the dashboard. Grades already posted stay in the LMS gradebook.
- End of an agreement. The administrator exports everything a registration holds (attempts, transcripts, grades, courses and LMS users) as JSON, then destroys it all, including the registration.
- Backups. Deleted data can remain in database backups for up to 60 days; see Backups under Security.
- Requests. Students and instructors can ask for deletion at challen@illinois.edu.
Security
- In transit. Every browser and LMS connection uses HTTPS, and so do calls from the model gateway to Azure. Behind the university web server, the hop into the cluster and traffic inside it are plain HTTP on the university network. Sign-in email reaches the university mail relay over TLS, with the relay's certificate verified. That TLS is opportunistic: if the relay stopped offering it, mail would be sent unencrypted.
- Secrets at rest. The tool's LTI signing key and any instructor's endpoint key are sealed with AES-256-GCM under separate secrets. Microsoft sign-in tokens are not stored.
- Launches. Every LTI 1.3 launch is a token signed by the LMS and verified against the LMS's published keys, issuer, audience, nonce and expiry. Each launch can be used once.
- Instructors. Illinois instructors sign in with Illinois Microsoft Entra ID. Accounts are approved by an administrator.
- Outbound requests. Every request to an LMS or an instructor's endpoint must be HTTPS to a public address, follows no redirects, and is capped in size and time.
- Privileged access. One person, the project lead, administers the cluster, the database and the model gateway, and is the site's only administrator. Engineering IT staff administer the underlying virtual machine hosts.
- Backups. The database is dumped nightly. Dumps on the cluster are deleted after 30 days. Each dump is also copied to Illinois Box, and Box copies are deleted after 30 days too. Box keeps a deleted copy in its trash for 30 more days, then removes it, so data deleted from the tool is gone from every backup within 60 days.
- Assessment integrity. The interviewer that talks to the student never receives the answer key. A separate evaluator holds it and steers the conversation. The grade comes from a blind read of the finished transcript against the rubric. When it disagrees with the evaluator's own read, the attempt is flagged for the instructor.
Accessibility
Every page that loads inside the LMS, and the instructor pages around it, was evaluated against WCAG 2.2 Level A and AA. The evaluation used axe-core on nineteen page states, scripted keyboard, reflow, text-spacing, contrast and reduced-motion checks, and code review. They run in the test suite, so a regression fails the build. The result is a VPAT 2.5 (WCAG edition) Accessibility Conformance Report.
- All Level A and AA criteria that apply are Supported, except three that are Partially Supported.
- 2.2.1 Timing Adjustable. A conversation has no time limit. The launch behind a page expires 4 hours after launch without warning. Reopening the activity from the LMS resumes the same attempt, and nothing a student wrote is lost.
- 3.3.4 Error Prevention. Enter sends an answer at once, with no review step. A student can correct or add to it in the next turn, and the grade reads the whole conversation.
- 4.1.3 Status Messages. Status, error and conversation updates use live regions, verified in the accessibility tree but not yet with a screen reader.
Read the full conformance report (PDF). To report a barrier, write to challen@illinois.edu.
Incidents and Contact
Geoffrey Challen, Siebel School of Computing and Data Science, University of Illinois Urbana-Champaign, runs the service. Write to challen@illinois.edu to report a security or privacy concern, an accessibility barrier, or to ask for data to be exported or deleted. The Canvas configuration is at https://api.conversationalassessment.org/lti/canvas.json; setup is on the Canvas page.