Privacy Policy

Last Updated October 1, 2026

1. Who we are and what this policy covers

Bedrock Knowledge, Inc. (“Bedrock,” “we,” “us”) provides a professional learning platform with courses, serious games, intelligence feeds, social learning, and competency analytics. Our address is 1010 Wisconsin Ave NW, Washington, DC 20007.

Effective date: October 1, 2026

This policy explains how we collect, use, share, and protect personal information when you:

  • visit thebedrock.co or other sites that link to this policy (the “Website”)
  • use the Bedrock platform, apps, games, and related services (the “Platform”)
  • contact us, request a demo, or attend our events.

If your organization gave you access. Many people use Bedrock through an employer, agency, or other organization (a “Customer”). In that case, the Customer decides what Platform data is collected about you and how it is used, and we process it on the Customer’s behalf under our agreement with them. That agreement controls where it differs from this policy. Questions about your organization’s use of Bedrock are best directed to your organization first, and we will help them respond.

This policy does not cover third-party sites or services we link to. Their own policies apply.

2. Information we collect

  • Account and profile. Name, work email, organization, role, or job title, team, or unit, login credentials. Source: you or your organization.
  • Learning activity records. Courses started and completed, modules viewed, time spent, audio playback, game sessions and moves, recorded as learning activity statements (for example, xAPI). Source: generated as you use the Platform.
  • Assessment and competency data. Answers, written responses, scores, rubric results, test-out attempts, competency ratings, Mastery Scores, XP, badges, certificates. Source: generated from your activity and responses.
  • Social learning content. Comments, discussion posts, questions, answers, in-game and Platform chat messages. Source: you.
  • Contact and sales information. Name, work email, organization, and message when you request a demo or contact us. Source: you.
  • Device and usage information. IP address, browser, and device type, pages visited, referring page, approximate location derived from IP. Source: collected automatically on the Website and Platform.

We do not ask for sensitive personal information such as Social Security numbers, health information, or financial account numbers. Please do not post it in discussions, chat, or written responses.

Classified and controlled information. The Platform is not approved for classified information or Controlled Unclassified Information. Do not enter it anywhere on the Platform.

3. How we use information

We use personal information to:

  • provide the Platform, including courses, games, intelligence feeds, discussions, and certificates
  • record your learning activity and calculate competency ratings and Mastery Scores against the Bedrock Competency Model
  • show you and authorized administrators your progress, and roll individual results up into team and organization views
  • recommend courses, games, and briefs relevant to your competencies
  • provide AI-assisted features, such as feedback on written responses and grading against rubrics
  • respond to demo requests, support questions, and other messages
  • secure the Website and Platform, detect abuse, and troubleshoot problems
  • improve our content and features using aggregated or de-identified data
  • comply with law and enforce our agreements.

What Mastery Scores are. A Mastery Score summarizes the evidence of your competency that the Platform has recorded. It reflects only activity on Bedrock and is not a complete measure of your abilities. Bedrock does not make hiring, promotion, discipline, or other employment decisions.

AI-assisted features. Some features send your written responses to third-party AI model providers to generate feedback or scores. [Our agreements prohibit these providers from using your data to train their models.] We do not use your personal information to train AI models.

We do not sell personal information, and we do not use Platform data for targeted advertising.

4. What your organization can see

If you use Bedrock through a Customer, administrators your organization authorizes can see:

  • your profile, team, and assigned learning campaigns
  • your progress, completions, scores, competency ratings, Mastery Scores, and certificates
  • team and organization roll-ups that include your results.

Administrators can also export learning records to your organization’s other systems, such as a learning management, HR, or readiness system. Once exported, the Customer’s own policies govern that copy.

Other users can see your name, profile details you choose to show, and content you post in shared discussions or games. Customer spaces are private to that Customer unless it enables cross-organization community features.

5. How we share information

We share personal information only as follows:

  • With your organization, as described in section 4.
  • With service providers that host, secure, and support the Platform, such as cloud hosting (Microsoft Azure and Cloudflare for the Website), AI model providers, email delivery, form handling (Formspree), and Website analytics (Plausible). They may use the information only to provide services to us, under written confidentiality and security obligations.
  • For legal reasons, when we believe in good faith that disclosure is required by law, subpoena, or court order, or is needed to protect the rights, safety, or property of our users, Customers, Bedrock, or others. Where the law allows, we will notify the affected Customer before disclosing its data.
  • In a business transfer, such as a merger, acquisition, or sale of assets, subject to this policy’s protections.
  • With your consent or at your direction.

We may share aggregated or de-identified information that cannot reasonably identify you or your organization.

6. Cookies, analytics, and similar technologies

Website analytics. We use Plausible Analytics to count visits to the Website and see which pages are used. Plausible is cookieless: it sets no cookies, stores nothing on your device, and does not identify or track you across sites. It receives your page URL, referrer, browser and device type, and your IP address, which it uses only to derive your country and a daily anonymous visitor count and then discards. In the European Economic Area, the United Kingdom, and Switzerland we run Plausible only after you choose Accept in the banner. Everywhere else it runs by default and you can turn it off at any time with Decline, or later through Cookie settings or Your Privacy Choices in the footer.

Opt-out signals. If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as a Decline and do not run analytics or ask you to choose.

What the Website stores on your device.

  • Consent choice (essential). One first-party cookie, bedrock_consent, remembers whether analytics is on or off for 12 months.
  • Sample course access (essential). If you are approved for a sample course, two signed first-party cookies identify your device and session so the course links can be shown. They are set only when you use that feature.
  • Editor session (essential). Staff who sign in to edit the Website receive a session cookie.
  • Game progress (functional). Browser games such as Thornpass save your progress in your browser’s local storage so you can resume. This stays on your device and is not sent to us.

On the Platform, we use essential cookies and similar technologies to keep you signed in, remember preferences such as theme or audio speed, and secure the service.

We do not use advertising, retargeting, or social-media tracking cookies, and we do not sell or share personal information for targeted advertising. You can block or delete cookies in your browser settings, but the Platform may not work without essential cookies.

7. Security, storage, and retention

Security. Bedrock holds a SOC 2 Type II attestation. We encrypt data at rest with AES-256 and in transit with TLS 1.2 or higher, require multi-factor authentication for access to production systems, grant access by role, and monitor and log our systems. No system is perfectly secure, so we cannot guarantee that information will never be accessed without authorization. If a breach affects your personal information, we will notify you and affected Customers as the law and our contracts require.

Where data is stored. We store Platform data in the United States on Microsoft Azure. Some service providers, such as AI model providers, may process data in other locations under the protections described in section 5.

How long we keep it.

  • Customer Platform data. For the term of the Customer agreement, then deleted or returned within 30 days of termination, unless the Customer directs otherwise.
  • Individual account data. While your account is active, then deleted within 30 days of closure.
  • Security and system logs. 10 years.
  • Backups. Overwritten within 90 days.

We may keep information longer where the law requires or to resolve disputes, and we may keep de-identified data.

8. Your choices and rights

Depending on where you live, including California, Colorado, Connecticut, Maryland, Oregon, other U.S. states with privacy laws, the European Economic Area, and the United Kingdom, you may have the right to:

  • know what personal information we hold about you and how we use it
  • get a copy of it in a portable format
  • correct inaccurate information
  • delete it
  • opt out of its sale, its sharing for targeted advertising, and profiling that produces legal or similarly significant effects (we do none of these)
  • limit the use of sensitive personal information (we do not collect it)
  • withdraw consent where processing is based on consent, such as Website analytics in the EEA, UK, and Switzerland
  • not be treated differently for exercising these rights.

Data minimization. We collect only the information reasonably necessary to provide the Website and Platform as described in sections 2 and 3, and we do not collect precise geolocation or sensitive personal information.

How to make a request. Email [email protected] or use the form at thebedrock.co/contact. We will verify your identity before acting, usually by confirming control of the email on your account. You may use an authorized agent with your written permission. We will respond within 45 days, and we will tell you if we need up to 45 more. If we decline a request, we will tell you why, and you may appeal by replying to our response; we will answer your appeal within 45 days and tell you how to contact your state attorney general if you disagree with the result. EEA, UK, and Swiss residents may also complain to their local data protection authority.

Your Privacy Choices. The Cookie settings and Your Privacy Choices links in the Website footer let you turn analytics on or off at any time. Browsers sending a Global Privacy Control signal are opted out automatically.

If your organization gave you access, we will refer requests about Customer Platform data to your organization and help it respond, as our agreement requires.

Email. You can unsubscribe from marketing email with the link in any message. We will still send service messages about your account.

9. Children, changes, and contact

Children. Bedrock is for people 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us information, email [email protected] and we will delete it.

Changes. We will post any update here with a new effective date. For material changes, we will notify account holders by email or in the Platform before the change takes effect.

Contact. Questions about this policy or your information:

  • Email: [email protected]
  • Mail: Bedrock Knowledge, Inc., Attn: Privacy, 1010 Wisconsin Ave NW, Washington, DC, 20007