Skip to content

BNKR Privacy Notice

This Privacy Notice describes how BNKR handles information about the people who use the BNKR institutional banking simulation: learners who play scenarios, instructors and facilitators who configure and grade them, and the institutional buyers who license the platform. When BNKR is delivered through an institutional engagement, the licensing institution is the controller of learner records and BNKR acts as a processor on its behalf under a written engagement agreement.

BNKR collects only what the service needs to operate: account information (name, work email, institutional affiliation, role, sign-in identifier); buyer and prospect information from request-a-demo and pilot-request submissions; simulation telemetry (the decisions a learner makes, the quarters they advance, scoring outputs, debrief content, free-text reflections); instructor and facilitator configuration (scenarios, custom packets, rosters, rubrics); support communications; and technical and usage data including IP address, device and browser information, error reports, and a small number of first-party cookies for sign-in and accessibility preferences. BNKR does not use cross-site advertising trackers and does not collect real consumer financial data, real loan-application data, or real customer records from a licensing institution.

We use this information to operate the simulation, generate AI-written executive briefings and debriefs, give instructors and program admins the dashboards and exports they need, respond to support and demo requests, produce aggregated and de-identified analytics that improve the service, detect abuse and security incidents, and meet legal, accounting, and audit obligations. We do not sell personal information and we do not use learner simulation telemetry to train third-party foundation models.

BNKR uses a small set of vetted sub-processors: Replit for application hosting, deployment, and authentication; Neon for managed PostgreSQL database hosting; and OpenAI for generation of executive briefings and debrief language. Each sub-processor handles only the data needed for its function and is bound by a written agreement.

Retention windows: active accounts for the life of the account; learner simulation telemetry for the duration of the licensed engagement plus the grading and dispute window the instructor specifies (default 12 months after course end); buyer and prospect records up to 24 months after the last interaction if no engagement is signed; support communications up to 24 months after resolution; audit, billing, and tax records for the period required by law (typically up to 7 years). When an engagement ends, BNKR deletes or returns learner records on the timeline specified in the engagement agreement.

BNKR shares personal information only with the licensing institution and authorized instructors, with the sub-processors listed above under written terms, when required by law or valid legal process, or in connection with a corporate transaction subject to confidentiality.

You may have the right to access, correct, export, or delete the personal information BNKR holds about you, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, email privacy@bnkr.game from the address associated with your account, or contact your program administrator if your account was provisioned by your institution. We will verify the request and respond within the time required by applicable law (and in any event within 45 days).

BNKR is operated from the United States and its sub-processors process data in the United States. International transfers rely on standard contractual clauses or other lawful mechanisms where required. BNKR is not directed to children under 13; K-12 deployments are scoped to grades 9-12 and configured with the licensing district under a written engagement agreement.

BNKR uses role-backed authentication, encrypted transport (HTTPS) for all traffic, encryption at rest for the production database, the principle of least privilege for staff access, audit logging on administrative actions, and dependency, static-analysis, and credential scanning in its build pipeline. Suspected incidents should be reported to privacy@bnkr.game.

We will update this notice when our practices change or when required by law. The effective date will reflect the most recent revision. For privacy questions or data-subject requests, contact privacy@bnkr.game; for general legal questions, contact legal@bnkr.game.