Information We Collect
We collect information that you provide directly to us, information we obtain automatically when you use our platform, and information from third-party sources.
Information You Provide
- Account information such as your name, email address, and password
- Profile information including your role, institution, and profile photo
- Course content, assignments, grades, and feedback you create or submit
- Communications you send through the platform, including messages and comments
- Payment and billing information processed through Stripe
Information Collected Automatically
- Device information such as browser type, operating system, and screen resolution
- Log data including IP address, access times, and pages viewed
- Usage data such as features used, courses accessed, and time spent on the platform
- Cookies and similar tracking technologies (see our Cookie Policy for details)
How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve our educational platform and services
- To create and manage your account, authenticate your identity, and control access
- To process enrollments, track course progress, record grades, and issue certificates
- To process payments, manage subscriptions, and send billing-related communications
- To send transactional notifications such as enrollment confirmations and grade updates
- To generate analytics and reports for institutional administrators
- To detect, prevent, and address technical issues, fraud, and security threats
- To comply with legal obligations and respond to lawful requests
Data Storage and Security
Your data is stored and processed using Cloudflare's global infrastructure, which provides enterprise-grade security and performance.
- Cloudflare D1 — our primary database for structured data including user accounts, course records, enrollments, grades, and platform configuration. Data is replicated across Cloudflare's edge network for reliability and low-latency access.
- Cloudflare R2 — object storage for files such as course materials, documents, profile photos, and uploaded assignments. R2 provides S3-compatible storage without egress fees.
We implement industry-standard security measures to protect your personal data, including:
- Encryption in transit using TLS 1.3 for all connections
- Encryption at rest for all stored data
- Role-based access controls and principle of least privilege
- Regular security audits and vulnerability assessments
- Automated backups and disaster recovery procedures
Third-Party Services
We share your information with the following third-party service providers who assist us in operating our platform:
- Cloudflare — infrastructure, content delivery, edge computing, database, and storage services.
- Stripe — payment processing, subscription management, and fraud prevention. Payment card details are handled directly by Stripe and are never stored on our servers.
We do not sell your personal data to third parties. We only share data with service providers who are contractually obligated to protect your information and process it solely on our behalf.
Your Rights
Under the General Data Protection Regulation (GDPR) and other applicable data protection laws, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete personal data.
- Right to erasure — request deletion of your personal data under certain circumstances.
- Right to restrict processing — request that we limit how we use your data.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing of your data based on legitimate interests.
- Right to withdraw consent — withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us using the information provided below. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority.
Data Retention
We retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
- Active accounts — data is retained for the duration of your account and subscription.
- Deleted accounts — personal data is deleted within 30 days of account deletion, except where retention is required by law.
- Billing records — payment and transaction records are retained for up to 7 years to comply with financial and tax regulations.
- Usage logs — anonymized usage data may be retained indefinitely for analytics and platform improvement.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at [email protected].