Copilot Challenges

Sign-in privacy

We use your email to verify access and send a single-use sign-in link through SendGrid. Google reCAPTCHA checks requests for automated abuse. Essential cookies protect requests and maintain your session.

Links expire after 15 minutes. Sign-in cookies and server sessions persist for 366 days and are renewed on normal visits when less than a year remains. Inactivity alone does not sign you out. Signing out, deleting your profile or losing organisation access ends access. Clearing cookies or using a browser that removes them requires signing in again. No organisation content is available until sign-in is verified.

Full privacy notice and user agreement

User agreement

Copilot Challenges provides short exercises for practising with Microsoft Copilot. By accepting this agreement, you agree to use your own authorised work account and follow the rules below.

  • Use only the fictional inputs provided. Do not submit company secrets, personal information or customer data. Follow your organisation’s rules for using Microsoft Copilot.
  • Work through challenges yourself. Do not share reference answers, automate submissions, impersonate another user or attempt to bypass access controls.
  • Each challenge or stage accepts one final submission. You may skip a challenge for zero points; earlier stage answers remain saved. Your answer, result, points and elapsed time are saved, including incorrect answers. Submissions cannot be replaced.
  • All participating users appear on the private organisation leaderboard. The leaderboard displays your full verified work email address under User. Authenticated colleagues in your organisation can see your email address, rolling scores and activity counts. This value cannot be edited.
  • Scores are for practice and friendly competition. The platform cannot verify which tool produced an answer and is not a proctored assessment or a measure of employee performance.

Privacy notice

Information we store

We store your work email address, sign-in sessions, and challenge activity: start and submission times, submitted answers and elapsed time. We also record the agreement version you accept and when you accept it. We do not use advertising analytics.

Who can see it

Access is restricted to verified work-email domains for your organisation. Authenticated colleagues in your organisation can see your full verified work email address, rolling points, correct/submitted counts and counted time on the mandatory leaderboard. Submitted answer text is not displayed on that board. Your own answers are available in My account. Platform administrators can access submissions to review marking. Reviews record the administrator, previous result, replacement score and explanation. Administrators with database access can access account, agreement and submission records.

Service providers and cookies

Microsoft Azure hosts the database and the application in the United Kingdom (UK South data servers). SendGrid processes your email to deliver sign-in links; email open and click tracking are disabled. Google reCAPTCHA receives browser and interaction signals during sign-in requests to help prevent automated abuse. Essential cookies maintain your session and protect requests. Google may use cookies under its own privacy policy.

AI assessment

Some writing tasks use OpenAI to assess your response against a defined rubric. We send the fictional task, marking criteria and your submitted answer, without your account email or user ID. Email-like text is redacted, but you must not submit personal, confidential or customer information. OpenAI processing may occur outside the United Kingdom, depending on the provider account configuration. Requests disable response storage and are not used for model training by default; provider abuse-monitoring logs may be retained for up to 30 days. AI marking can make mistakes; contact copilotchallenges@zhandos.com for an administrator review. A failed service call leaves a result pending rather than marking it incorrect.

Retention and deletion

Sign-in links expire after 15 minutes. Sign-in cookies and server sessions persist for 366 days and are renewed on normal visits when less than a year remains. Inactivity alone does not sign you out. Signing out, deleting your profile or losing organisation access ends access. Clearing cookies or using a browser that removes them requires signing in again. Scheduled maintenance removes expired sign-in records and rate-limit counters. Your profile, submitted answers, scores, marking reviews and agreement acceptance records remain until your organisation profile is deleted. You can delete that profile from My account; this removes its answers, scores and sessions. Hosting logs and backups follow the operator’s configured retention policy. Rolling leaderboard expiry does not delete your saved results.

Your choices and contact

If you do not wish to accept the user agreement, sign out without continuing. Acceptance is required to access learning content. By acknowledging this privacy notice, you confirm that you have read how the service handles your information; this is not permission for unrelated marketing.

For privacy questions or requests concerning your information, contact copilotchallenges@zhandos.com.

Protected by reCAPTCHA. Google’s Privacy Policy and Terms of Service apply.