Data Handling, Security and Accessibility

What the Conversational Assessment LTI tool receives from Canvas, Moodle or another LMS, where it goes, who can see it, and how long it stays. Reviewed 2026-10-09.

Two Kinds of Commitment

A registration is one LMS's installation of the tool. An institution's agreement covers its registration, so some commitments are settings on that registration. The rest hold for every user of the tool.

CommitmentApplies to
A retention window: student attempts are deleted a set number of days after their last activityPer registration, set by the site administrator. Without a window, data is kept until someone deletes it.
Hosted models only: attempts run on the models described below, never on an instructor's own AI endpointPer registration, set by the site administrator
Export, then destroy, everything a registration holds when an agreement endsPer registration, on request
Instructor deletion of one attempt or a whole course's dataEvery registration
Encryption in transit, access control, no prompt storage at the model gateway, no analytics or advertisingThe whole service

University of Illinois. The Canvas@Illinois registration will have a 365-day retention window and hosted models only. Both are set when Canvas@Illinois creates the registration, before the first student launch.

What the Tool Receives and Stores

Students never create an account. The LMS identifies them in a signed launch, and the tool keeps only what it needs from that launch. The registration asks Canvas for privacy level public, which is what makes Canvas send a name and email.

DataWhere it comes fromWhy it is kept
LMS user ID (the opaque sub)Every launchTells one student's attempt from another's
Name and emailEvery launch, when the LMS sends themSo the instructor can see who took the assessment. Without them the results page shows the LMS user ID.
LMS rolesEvery launchDecides whether a launch sees the student page or the instructor results
Course ID, code and title; assignment ID and title; deployment IDEvery launchTies attempts to the right course and assignment
Gradebook service addressesEvery launchWhere to post the score
The conversation: the student's messages and the interviewer's repliesCreated in the toolIt is the assessment, and the evidence for its grade
The evaluator's per-turn notes, the grade, portion grades, feedback, and a review flagCreated in the toolGrading, and instructor review of the grade
The score sent to the gradebook, with the grade and feedback as a commentCreated in the toolThe request and the LMS's response are kept 7 days after sending, to answer “where is my grade”, then cleared
Launch recordsEvery launchVerifying the launch. Deleted once they expire, within hours.
Model usage: model name, token counts, costCreated in the toolSpend accounting. No message content.

Not kept: the LMS's signed launch token itself, student ID numbers or other SIS identifiers, photos, and the course roster.

The tool asks for four LTI scopes, all for the gradebook (Assignment and Grade Services): lineitem, lineitem.readonly, result.readonly and score. It does not ask for the roster (Names and Role Provisioning). The site uses no analytics, advertising or third-party trackers. The only cookie a launch sets binds the launch to the browser and is cleared when the launch completes.

Who Can See What

WhoWhat they can see or do
A studentTheir own conversation, grade and feedback. Never the rubric, the answer key, or anyone else's attempt.
The instructor who connected the courseEvery attempt in that course: name and email, status, grade, review flag, transcript, and whether the score reached the gradebook. They can delete one attempt or all of the course's student data. They see per-criterion progress only for assessments they wrote.
Others with a teaching role in the LMS course (co-instructors, TAs, designers)The same results and transcripts, opened from the LMS. They cannot delete.
The LMS gradebookThe score, with the grade and feedback as a comment
The site administrator (one person, the project lead)Registration settings, export and destroy, and the database, for operations and support

No vendor, advertiser or other third party receives student data, with two exceptions: the language models receive conversations as described next, and database backups are copied to Illinois Box, the University's Box service.

Where It Is Processed

Retention and Deletion

Security

Accessibility

Every page that loads inside the LMS, and the instructor pages around it, was evaluated against WCAG 2.2 Level A and AA. The evaluation used axe-core on nineteen page states, scripted keyboard, reflow, text-spacing, contrast and reduced-motion checks, and code review. They run in the test suite, so a regression fails the build. The result is a VPAT 2.5 (WCAG edition) Accessibility Conformance Report.

Read the full conformance report (PDF). To report a barrier, write to challen@illinois.edu.

Incidents and Contact

Geoffrey Challen, Siebel School of Computing and Data Science, University of Illinois Urbana-Champaign, runs the service. Write to challen@illinois.edu to report a security or privacy concern, an accessibility barrier, or to ask for data to be exported or deleted. The Canvas configuration is at https://dev-api.conversationalassessment.org/lti/canvas.json; setup is on the Canvas page.