Skip to main content
01

Scope and responsible company

MechaTraining LLC, a Kentucky company, is responsible for the personal information described here unless a signed institutional agreement identifies a different role. This policy covers public pages, account registration, Dashboard, Academy, support, protected web applications, Android applications and companions, and future iOS or other applications only when they are released and link to this policy.

Current covered products include Mech CNC Mill; the protected Industrial Robotics web simulator; the CNC Android companions distributed under com.mechatraining.cncmrtutor and com.mechatraining.cncxrmode.volumetric; and Industrial Robotics Android Phone XR under com.mechatraining.industrialrobotics. A test, legacy or future package is covered only while MechaTraining actually distributes it and it links to this policy. Mentioning a future app or platform does not mean that it is currently available. An institution may provide an additional notice for a managed deployment.

Public self-service registration, app requests and protected training are available internationally to adults where applicable law and an authorized distribution channel permit the service. Mobile distribution can vary by country, store and device. This privacy notice, the Legal Center, account-deletion tools and evidence-verification pages remain publicly available worldwide.

02

Information we process

Account and contact

Name, email, organization, claimed and verified role, declared country or region of residence, language, account status, support messages and communication preferences.

Credentials and legal records

Protected password credentials, hashed verification and activation-code records, account and app sessions, legal-document versions, acceptance time, source, locale and IP and browser security hashes. Passwords and one-time codes are not stored in readable form.

Academic verification

Institution name and domain; institution and public-directory URLs supplied by an instructor; directory-check date, result, reason, verification and expiration times; manual-review status; and a cryptographic evidence hash. We store the result and hash, not a copy of the directory page. Instructor eligibility is rechecked at least annually before a new instructor grant may start.

Applications and licenses

App requests, activation and renewal events, role at request, term length, first launch, expiration, revocation, license identifiers and app or device pairing status.

Learning and simulation

Enrollments, modules, activities, quiz responses and scores, lab attempts, simulator events, warnings, alarms, completion, time in the Dashboard or simulator, submission identifiers, evidence hashes and instructor feedback when those features are used.

Files and outputs

G-code, CNC project, tool, material, machine, robot, image, STL, PDF, ZIP, manifest, response or assignment files only when the user selects a feature that processes or uploads them. Files processed locally are not uploaded merely because the app opens them.

Device, network and security

Session cookies or tokens, app version and package, limited device enrollment identifiers stored as hashes, browser or app technical data, request times, IP-derived security hashes, coarse country signal, trusted-device token, administrator actions and security logs.

First-party usage measurement

Authenticated surface, session start, last activity and active seconds used to understand reliability and adoption. We do not use this measurement to collect keystrokes, local simulator files, camera frames or advertising identifiers.

Cookies and local storage

The current service does not use advertising cookies or third-party behavioral analytics. It uses only storage needed to provide or secure the requested service and remember a user choice: mt_account_session (account session, normally 30 days), mt_access_session (licensed simulator session, normally 8 hours), mt_admin_mfa (administrator verification, normally 8 hours), __Host-mt_admin_trusted_device (optional and revocable administrator device trust, normally 30 days), and mt_lang (saved language choice, normally one year). The Dashboard and simulator may also use first-party browser storage to coordinate the one-active-session rule, a live simulator window and account deletion or sign-out events.

Strictly necessary storage is used without an optional-consent banner where applicable because the requested account, security or language function cannot operate reliably without it. If MechaTraining later introduces nonessential analytics, advertising or similar tracking, it will update this notice and obtain prior consent where required, with a choice to reject that is as easy to use as acceptance.

03

Where information comes from

Information comes from the user; an authorized administrator, instructor or institution; the user's browser, app and interactions; public institutional pages the applicant supplies for role verification; and service providers that deliver hosting, security, email, mobile distribution or XR functions. We do not buy consumer-marketing profiles.

04

Camera, augmented reality and Phone XR sharing

Industrial Robotics Android version 1.1.0, package com.mechatraining.industrialrobotics, is a Phone XR companion to the licensed PC simulator. The current CNC XR companion, including com.mechatraining.cncxrmode.volumetric, uses the same temporary pairing model with its own application data and package identity. The PC remains authoritative. Individual Control admits one phone and permits the supported simulated controls; Classroom Casting admits up to 30 read-only viewers. Neither mode controls physical equipment.

The signed-in PC host must have the matching active application license and current legal acceptance. The host deliberately creates a QR invitation. A person holding that QR can authorize a compatible app installation; this is a temporary capability, not proof that the person has a separate account or that their age or identity has been verified. Share it only with intended, authorized participants. Hosts must explain the shared content and obtain any required participation permissions; institutional and minor-use restrictions below still apply. The invitation expires after 10 minutes, an unused connection token expires after 60 seconds, and the session ends after at most 30 minutes. Reconnecting does not extend that deadline. Closing the session revokes its connections.

After the in-app notice and Android camera permission, ARCore processes camera and motion-sensor inputs to detect surfaces and track the phone and locally placed robot. Optional MediaPipe hand tracking processes camera images on the phone to turn hand landmarks and pinches into interface input; it is not used to identify a person. Local placement, anchors and viewer calibration support AR and stereo presentation. These releases do not request microphone or precise-location permission, use Cloud Anchors or the Geospatial API, or upload an environment mesh. Sound is generated by the simulator, not recorded from the microphone.

The temporary relay carries simulated joint and coordinate values, program text and selected lines, speed and safety states, allowed control requests and results, tracking/placement status, and connection metadata. QR authorization uses an app-generated installation identifier, package and version; MechaTraining does not request a hardware serial, Android ID, advertising ID, email or password from the companion. The relay stores token and installation-identity hashes and limited session metadata until expiration cleanup. Live simulator state is replaced in memory. The new QR companion keeps its connection capability in memory and does not require a renewable, permanent Dashboard device enrollment. Local settings may retain the installation identity, acknowledged notice version, audio preferences and viewer calibration.

Optional camera casting: in an individual session, when the phone user or paired PC host deliberately enables CAST, the app transmits a composed camera/AR view, which can include bystanders, surroundings, the robot, program text and interface controls. H.264 WebRTC sends encrypted video to the paired PC; connection signaling and statistics pass through the relay. A reduced-resolution JPEG fallback sends frames through the encrypted relay. Connection negotiation can disclose network addresses to the paired endpoint and network traversal providers. The MechaTraining relay forwards this content transiently in memory and does not write camera/video frames to its database or object storage. Stop CAST, leave XR or end the session to stop transmission. The receiver or operating system can independently capture its screen; do not point the camera at private spaces, confidential material or people who have not agreed to appear. Read-only classroom viewing does not enable a student's camera feed to be cast to the host.

The signed Android apps use Google Play Services for AR (ARCore), provided by Google. Its functionality is subject to the then-current Google Terms of Service and Google Privacy Policy. Google processes service and diagnostic data under its own notice; data collected depends on the AR features used. Read how Google Play Services for AR handles data. Local AR processing is distinct from the optional composed-view transmission described above.

Legacy Robotics Android 1.0.0–1.0.1 was a standalone simulator without camera/ARCore; that description does not apply to version 1.1.0. Legacy installations may retain revocable device-license credentials encrypted with a non-exportable Android Keystore key and locally saved project text. Any retained legacy browser viewer is read-only; current Robotics Phone XR invitations launch the native companion. Package-specific legacy behavior must not be assumed for the current release.

05

Purposes and legal bases

  • Provide the requested service and perform the agreement: create and secure accounts, verify roles, issue app access, maintain sessions, operate simulations, courses, evidence, XR pairing and support.
  • Legitimate operational and security interests: prevent duplicate-access abuse, fraud and attacks; investigate integrity or safety problems; maintain audit records; measure first-party usage; troubleshoot and improve reliability. We balance these interests against user rights.
  • Permission or consent where required: enable camera/XR functions, optional communications, or another use for which applicable law requires a separate affirmative choice. A device permission is not consent to unrelated processing.
  • Legal obligations and claims: respond to lawful process, protect rights, keep required records and establish, exercise or defend legal claims.

We do not use student work, private files, telemetry or camera data to train a general-purpose artificial-intelligence model, publish research about identifiable users or market unrelated products unless a separate, specific authorization and an appropriate institutional or legal basis are in place. General account acceptance is not consent to participate in human-subject or identifiable-user research; such research requires a separate study notice and affirmative consent, and any required institutional or ethics approval.

06

Service providers and other disclosures

We disclose only the information needed to provide a selected function, follow the user's or institution's authorized instruction, secure the service, address a transaction or comply with law. Current categories of providers include:

  • Cloudflare for domain, hosting infrastructure, database and object storage, traffic security, bot protection, email routing and temporary XR relay functions.
  • OpenAI Sites for application source deployment and web hosting infrastructure used to serve the MechaTraining portal.
  • Resend for transactional account, app activation, security, support and administrative-report email. After MechaTraining completes an account deletion and sends the required completion notice, a durable outbox submits an idempotent processor-erasure instruction for the affected recipient address, message content and delivery records and records that submission.
  • Google for Google Play distribution, Android platform services and ARCore on compatible Android devices.
  • Apple only if a future app is distributed through Apple services; Apple processes store and device information under its own notices.
  • Authorized institutions or instructors for course, roster, submission, progress or assessment information only when the user participates in a managed educational feature and the required agreement or authorization exists.

MechaTraining relies on each provider's applicable service terms and, when available or legally required for the deployment, its data-protection addendum or other written safeguards. MechaTraining evaluates the provider's stated confidentiality, security, retention and deletion commitments before assigning covered processing. An institutional deployment will not be represented as satisfying institution-specific contractual or international-transfer requirements until any required agreement is actually in effect. Providers that act independently, such as an app-store operator for its own store account, also process information under their own notices and legal obligations.

We may disclose information in a business reorganization subject to appropriate protection, or when reasonably necessary to comply with law, protect safety and rights, or investigate fraud or security incidents. MechaTraining does not sell personal information, does not share it for cross-context behavioral advertising and does not use an advertising ID or targeted advertising in the current apps.

07

Country signal, language and regional operation

The user separately declares a country or region of residence during final account acceptance and later material legal acceptance. That declaration supports regional notices, privacy-rights routing and lawful distribution decisions. Users must keep it accurate after a permanent move. It is not independently verified merely because it was selected.

At the network edge, the service also receives a coarse two-letter country code associated with the request. MechaTraining uses it to select an available language, support fraud and security review, record the network context of legal acceptance and apply a specific legal or authorized distribution restriction when required. It is not device GPS, is not precise location and is not used as a blanket United States-only gate. It can differ from residence because of travel, mobile networks or a VPN. If the country's official language is not supported, the initial language is English. A user can change the language at any time; the saved choice overrides automatic selection.

The legal-acceptance evidence may record the edge-observed country code, acceptance time and limited security evidence described above. Network and security providers may process the source IP under their ordinary security and logging practices; MechaTraining stores a keyed IP hash in legal-acceptance or security evidence where described, rather than the readable IP in the acceptance record. A missing or unknown country signal falls back to browser language and does not by itself block registration or protected use.

08

International processing and transfers

MechaTraining is based in Kentucky, United States. Its providers may process information in the United States and other locations where they operate. MechaTraining uses applicable provider data-processing terms and, where required for a covered transfer, an approved transfer mechanism such as the EU Standard Contractual Clauses, the UK Addendum or another legally recognized safeguard, together with any required assessment and supplementary measures. A user may contact privacy@mecha-training.com for information about safeguards applicable to a particular transfer, subject to lawful confidentiality limits. Provider terms do not replace any additional agreement required for an institution-managed or regulated deployment.

09

Regional privacy rights and supplemental information

EEA and United Kingdom. Depending on the processing, MechaTraining relies on performance of the requested service, legitimate interests in security and reliable operation, legal obligations, or consent where the law requires it. Eligible users may exercise access, correction, erasure, restriction, portability and objection rights, withdraw consent, request review of an automated eligibility result and complain to the competent supervisory authority. International transfers use an applicable safeguard as described above.

California and other United States states. MechaTraining does not sell personal information, does not share it for cross-context behavioral advertising and does not use targeted advertising in the current service. Eligible residents may request access, correction, deletion or portability and may appeal a denied request, subject to verification and lawful exceptions.

Brazil. Users may request confirmation, access, correction, anonymization, restriction, portability or deletion where the LGPD applies, and may ask about the applicable legal basis and international-transfer safeguard. Canada. Users may request access and correction and may challenge compliance through the privacy contact; foreign processors remain subject to contractual and security controls. Japan. Users may request disclosure, correction, suspension of use or deletion where the APPI provides those rights. Other mandatory local rights also remain available.

Submit a request through the deletion page or email privacy@mecha-training.com. MechaTraining verifies identity, responds within the period required by applicable law and does not discriminate against a user for exercising a privacy right.

10

Retention

We retain account, role, license and training records while needed to provide the service, maintain educational and integrity records, administer renewals and resolve support or security issues. Legal-acceptance records are retained for the life of the account. After account deletion, the direct account link, actor, IP hash and device hash are removed; an isolated keyed-pseudonymous record of the accepted document IDs, versions, content fingerprints and time may be retained only until the later of the applicable claim-limitation period, resolution of a documented dispute or legal hold, or expiration of a mandatory statutory retention period. The need is reviewed at least annually and the record is deleted or irreversibly de-identified when no such basis remains. Uploaded assignments or evidence follow the applicable course or institutional retention rule.

  • Account verification codes expire after 15 minutes; app activation codes expire after 30 minutes. Expired or used hash records may remain as limited audit and abuse-prevention evidence.
  • Account sessions normally expire after 30 days. Optional administrator trusted-device records expire after 30 days and are revocable.
  • First-party usage-session records are subject to a weekly retention job that deletes records at a 388-day cutoff, keeping the normal maximum age at or below 395 days. A temporary scheduler or infrastructure outage may delay that operation until service is restored.
  • Account-deletion verification links expire after 30 minutes, and expired unverified requests are removed. Once verified, a request remains in the administrative queue until it is completed, denied under a lawful exception or otherwise resolved and documented; it is not silently discarded because time has passed.
  • Phone XR QR launch capabilities expire after 10 minutes, unused connection tokens after 60 seconds, and each relay session ends after no more than 30 minutes. Browser launch pages remove the temporary capability from the URL fragment and do not persist it in browser storage. Relay capabilities are stored as hashes; session metadata is deleted during expiration cleanup. Current QR companions hold connection tokens in memory. Historical CNC or Robotics device-enrollment credentials, where used by a legacy build, remain revocable and expire at the earlier of 30 days or the related license expiration; those legacy builds encrypt them with a non-exportable Android Keystore key. Do not authorize a shared, rooted or otherwise untrusted device.
  • Detailed personal learning records are subject to a weekly 388-day cutoff, keeping the normal maximum age at or below 395 days. This purge removes assignment text, URLs, files and feedback; individual quiz responses; detailed simulator events, checkpoints and saved snapshots; and submission-integrity records. Summary enrollment, completion, score and badge records may remain while the account is active so the user and authorized instructor can document progress. Instructor-authored course assets remain while the course is maintained. A signed institutional agreement may establish a different lawful schedule.
  • Files scheduled for deletion from private object storage are placed in a durable deletion queue. Account access and database links are disabled or removed first; object deletion is then attempted immediately and retried after a storage outage. During a retry, an unlinked object remains private and unavailable through the application. A temporary scheduler or infrastructure outage may delay final object removal beyond the normal period until service is restored.
  • User-enabled Individual Control camera casting is transient. WebRTC video travels to the paired host; fallback JPEG frames are relayed in memory. MechaTraining does not archive these frames in database or object storage. The paired host or operating system can independently record its screen.
  • Rate-limit and transient security records expire after their configured protection window. Limited incident, fraud, legal or financial evidence may be retained longer when necessary and lawful.

Transaction and order records may be retained in pseudonymized form only for tax, accounting, fraud, chargeback and legal obligations. Shared or instructor-authored course materials may remain only where an active course, institution or other authorized users have continuing rights to use them; the deleted contributor's identity and personal attribution are removed. Account-exclusive submissions and unreferenced personal assets are deleted.

When the associated account is permanently deleted, personal records are deleted or de-identified unless a limited record must be retained for a stated security, legal or institutional obligation. A legal hold suspends only the deletion of information reasonably necessary for the covered matter. Any retained incident, fraud, financial or legal record is kept only until the later of the applicable claim-limitation period, resolution of a documented dispute or legal hold, or expiration of a mandatory statutory retention period; the need is reviewed at least annually.

11

Rights, choices and automated review

Depending on location and applicable law, a user may request access, correction, deletion, portability or restriction; object to certain processing; withdraw consent without affecting earlier lawful processing; and appeal a denied privacy request. Users may also request manual review or correction of an academic-role decision. We may verify identity before acting and may apply lawful exceptions.

Automated checks may identify an academic domain or compare a supplied public directory page, but inconclusive instructor evidence may be reviewed manually. Contact us to contest an eligibility result. We do not use solely automated processing to make decisions that produce legal or similarly significant effects unrelated to access eligibility.

Browser “Do Not Track” signals are not standardized and do not change current operation. Because we do not sell personal information or use cross-site targeted advertising, there is no such activity to opt out of. We honor legally applicable rights signals for any covered activity if practices change. We do not discriminate against a user for exercising a privacy right.

12

Account and data deletion

Users can initiate deletion without signing in at the public Account and Data Deletion page. We verify control of the registered email before placing the request in a manual administrative queue. Verification does not delete the account by itself. We aim to complete verified requests within 30 days, subject to applicable law and permitted identity, security, institutional-record and legal-hold checks. A completion notice is sent to the registered email and retried if delivery is temporarily unavailable. After that final notice, a separate durable process submits an erasure instruction to the transactional-email processor and records the provider message reference before the live address is pseudonymized in the deletion record. Submission of the instruction is not a representation that the provider has already acknowledged completion; the provider may preserve limited information required by law. Uninstalling a mobile app does not delete the server account.

The deletion page explains the affected data and limited lawful retention. If a mobile app allows account management, its settings or support surface must also provide a clear route to initiate deletion before that version is released.

Open deletion request

13

Children, students and institutional deployments

Direct self-registration is available only to a person who is at least 18 years old and has legal capacity to enter the agreement where that person resides. MechaTraining does not currently offer public self-service accounts for minors and the service is not directed to children under 13. A minor may participate only through a separately provisioned institution-managed deployment after MechaTraining and the institution have completed the required written agreement, authority or consent, data-minimization, supervision, retention/deletion and regional child-privacy controls. Until then, minor access is unavailable.

An institution must contact MechaTraining before sending student records or enrolling minors so the parties can determine roles, permitted educational purpose, direct control, notices, consent, security, retention and deletion requirements. A general account or these public terms alone do not establish FERPA school-official status, COPPA school authorization or compliance with every regional student-privacy law.

14

Security and incident response

Safeguards include HTTPS, protected password derivation, hashing and keyed hashing, expiring tokens, rate limits, bot protection, one-session controls, administrator MFA and trusted-device revocation, access checks, database and object-storage restrictions and administrative audit logs. No system is completely secure. Users should protect credentials and report suspected misuse promptly.

MechaTraining investigates suspected incidents and provides notifications required by applicable law. Do not send passwords, activation codes, private keys or unnecessary sensitive files in a support request.

15

Contact, complaints and policy updates

MechaTraining LLC is based in Kentucky, United States and is the controller or responsible company for the public service described here. Privacy, rights, role-review and data requests: privacy@mecha-training.com. Users may also complain to an applicable privacy or data-protection authority. Where applicable law requires a local representative or additional regional contact, MechaTraining will publish that contact before actively targeting the affected jurisdiction.

We update this policy when products, providers or legal requirements materially change. The page identifies the effective date and version. A material change that also changes the user agreement will trigger a renewed clickwrap acceptance before further protected app use.