1. Home
  2. Wonder Security & Trust

Wonder Security & Trust

Data Protection & Privacy

Data Protection & Privacy

EncryptionData We ProcessFile & Content ProtectionData Retention & DeletionSensitive Data & Analytics
Encryption
Data We Process
File & Content Protection
Data Retention & Deletion
Sensitive Data & Analytics

Encryption

Imagine protects data in transit and at rest using a combination of transport encryption, managed cloud encryption, and application-level encryption for selected sensitive identifiers.

ControlConfiguration
Public application trafficHTTPS with TLS 1.2 / TLS 1.3 to the AWS Application Load Balancer
HSTSEnabled, including includeSubDomains
Backend transportTLS terminates at the AWS Application Load Balancer before traffic is forwarded to the application service
Redis / Valkey in transitEncrypted using TLS (rediss)
AWS S3 at restServer-side AES-256 encryption
MongoDB Atlas at restEncrypted storage enabled
Sensitive institutional identifiersAdditional application-level encryption before database storage
Redis / Valkey at restEncrypted at rest using AWS-managed encryption

Data We Process

Depending on the features used by the institution, Imagine may process the following data types:

CategoryExamples
User & IdentityName, email address, role and permissions, organizational affiliation, encrypted personal/student identifier, authentication and account-security data
AcademicCourses and syllabi, course enrollments, attendance, groups and academic structure
Submissions & AssessmentsAssignments and exams, submissions, grades, feedback
Learning ContentDocuments, presentations, PDFs, videos, transcripts and other learning materials
Meetings & RecordingsOnline meeting information, class recordings, transcripts and attendance data
User-Generated ContentAssignment responses, code, forum content, messages and AI chatbot interactions
Support & CommunicationsSupport requests, ticket attachments, in-app communications and transactional email
Usage & Learning AnalyticsLogin and activity information, resource views, submissions, forum activity, attendance, media activity, AI tool interactions and IP addresses in security logs

File & Content Protection

Imagine stores institutional files in private AWS S3 storage, with institution-scoped organization, controlled content delivery, encryption, versioning, and malware protection.

ControlConfiguration
File storagePrivate AWS S3 storage
Institution separationInstitution-scoped object namespaces
Encryption at restServer-side AES-256 encryption
VersioningS3 Versioning enabled
Public access protectionS3 Block Public Access enabled for private storage
Private content deliveryAWS CloudFront signed URLs
Malware protectionAWS GuardDuty Malware Protection for S3

Data Retention & Deletion

Imagine's retention model is designed to follow each institution's academic, legal, and operational retention requirements.

Data / ProcessRetention & Deletion
Academic recordsRetained according to the institution's retention requirements.
User deactivationDeactivation prevents account access while allowing required academic records to be retained.
AI chat historyRetained until deletion is requested by the institution.
Usage & learning analyticsRetention is determined by the institution.
Individual deletion requestsPersonal data can be deleted or anonymized at the institution's request, subject to applicable academic and legal retention requirements.
Institutional offboardingInstitutional data is retained for up to 90 days following termination to support data export and transition, after which it is deleted from Imagine systems.

Sensitive Data & Analytics

Imagine processes academic and learning activity data to provide students and authorized academic staff with learning and course analytics.

TopicHandling
Personal identifiersInstitutional personal/student identifiers are encrypted at the application level
Accessibility preferencesAccessibility display preferences are stored locally in the user's browser and are not maintained as a health or disability profile
Student analyticsIndividual and aggregate analytics may include grades, submissions, attendance and learning activity
Analytics accessIndividual and course analytics are available to authorized course staff; students can access their own academic information
Automated decisionsLearning analytics do not automatically change enrollment, access or student status
Dropout predictionUnder development; the current implementation prepares academic and engagement features but does not generate student risk scores or take automated actions
Privacy at WonderHow we process dataWonder Security & Trust|© 2026 Wonder. All rights reserved.