Code of ethics
What we will and won’t do with a classroom’s data
An AI gateway sits in an unusually trusted position: between a student’s thinking and a machine that answers. These are the commitments that position obliges — written as constraints on us, not aspirations about the technology.
-
Student work belongs to students
We do not use student prompts, responses, or projects to train AI models — ours or anyone else’s. We do not sell student data, profile students for advertising, or share records with anyone but the institution that holds them. A classroom is not a data source.
-
Privacy is the default, not a setting
Sentinel Hub records what it needs to enforce limits and answer support questions: model, time, tokens, cost, status, request ID. It does not retain what students write or what models answer. An institution can enable content logging for legitimate reasons, but it is off until they turn it on, and it must be disclosed to the people it affects.
-
The institution holds the controls
Faculty and administrators decide which models appear in their catalog, which students have access, and what the limits are. We do not make pedagogical decisions on a campus’s behalf, quietly change what a course can reach, or route requests to a provider the institution hasn’t approved.
-
Oversight is not surveillance
Administrators can see usage — how much, which models, which keys — because budgets and safety require it. They do not get a window into what individual students are thinking. We build reporting that answers institutional questions without turning a coursework tool into a monitoring system.
-
Access should not depend on who can afford it
Metered institutional access exists so that a student’s ability to use serious AI tools doesn’t depend on personal subscriptions. We price and design for the whole roster — including students for whom a stack of monthly subscriptions was never realistic.
-
Accessibility is a requirement, not a roadmap item
Every surface we ship targets WCAG 2.1 Level AA. When a criterion isn’t met yet, we say so plainly with a date attached rather than claiming conformance we haven’t tested. A tool that some students can’t operate isn’t finished.
-
We support academic integrity, we don’t adjudicate it
Faculty set the rules for AI use in their courses; we give them the means to enforce those rules — model permissions, per-course catalogs, usage visibility. We do not sell AI-detection scores or algorithmic judgments about whether a student cheated, because those tools are unreliable and the consequences land on students.
-
We tell the truth about what we are
We do not claim certifications we don’t hold. Our compliance documentation states what is built, what is planned, and what is inherited — and where we are early-stage, it says so. AI output can be wrong, and we say that to students rather than letting a confident interface imply otherwise.
-
Security failures are disclosed, not managed
If student records are exposed, the institution hears it from us promptly and completely — not after we’ve decided how it looks. Every request carries an identifier so problems can be traced without asking a student to hand over a key or a prompt.
-
Learning comes before usage
We measure our success by whether students can build things they couldn’t build before, not by how many tokens they consume. We will not design features whose purpose is to increase spending, and we will tell an institution when a cheaper model would serve a course just as well.
Holding us to it
A code nobody can check is a slogan
Most of these commitments are enforced by architecture rather than good intentions. Provider credentials never leave the gateway, so we couldn’t hand them out if we wanted to. Content logging is off by default in the code, not in a policy document. Model catalogs are per-tenant, so an institution’s approved list is the only list its students can reach.
The rest are contractual, and they belong in the service agreement — not only here. Our compliance documentation states these same commitments in the vocabulary each framework uses, and we make our architecture available for technical review by university IT. If you find a place where our behavior and this page disagree, tell us: hello@sentinelhub.app.
We would rather lose a sale than quietly weaken one of these commitments to win it.
Questions welcome
Disagree with something here?
These commitments get sharper when institutions push on them. If your campus has a standard we haven’t met — or a principle we’re missing — we want to hear it before you adopt anything.
