Privacy policy
This copy is a starting point written for an online course business. Have a lawyer review it for your country and business model before you launch.
What we collect. Account details you give us: your name, email address, and a hashed password. Learning activity: which lessons you have started and finished, where you stopped in each video, and any notes you write, plus questions you post to instructors. Commerce records: your plan, its price and renewal dates, and a reference to the payment so we can reconcile it. Technical data: session identifiers and coarse request logs needed to keep the site secure and running.
What we do not collect. We never see or store your payment card details. Card and wallet payments are handled entirely by PayPal; we only receive a confirmation that a payment succeeded. We do not sell your personal information, and we do not build advertising profiles about you.
Why we use it. To run your account and let you log in, to show your own progress and notes back to you, to take payment and grant the access you paid for, to answer support questions, and to keep the service secure and available. We rely on legitimate interests and contract performance as our lawful bases, and consent where we ask for it.
How long we keep it. Account and learning data lives for as long as your account is open. Commerce records are kept for as long as tax and accounting rules require. Technical logs are kept for a short, fixed period and then deleted.
Who we share it with. Payment confirmation with PayPal, and hosting, database, and email providers who process data only on our instructions and are contractually bound to protect it. We will also disclose data if we are legally required to. We do not sell or rent it to anyone else.
Your rights. Depending on where you live you may have the right to see your data, correct it, delete it, restrict or object to its use, or receive a portable copy. To use any of these, email us. If you are in the EEA or UK you can also complain to your local data protection authority.
Cookies. We use one strictly necessary cookie holding an opaque session id so you stay logged in. We do not run advertising cookies, cross-site trackers, or third-party analytics pixels on this site.
Security. Passwords are stored as salted hashes and never in plain text, and sessions are tracked server-side so access can be revoked immediately. No system is perfect; if you think your account is compromised, change your password and tell us.
Contact and changes. Questions or requests about your data go to the email address on our contact page. If this policy changes we will update this page and, for material changes, tell active members by email.
Last updated 29 Sep 2026.