Skip to content

Privacy Policy

Last updated: 2026-09-13

We keep data collection minimal and use it only to run the courses.

What we collect

  • Account: your name and email (passwords are stored hashed by our auth provider — we never see them).
  • Learning data: your enrollments, purchase records, and lesson progress.
  • Analytics: the pages you open and how long you stay, your approximate location (city and country), your device, browser, operating system and screen size, and where you arrived from — including any campaign tag on the link you clicked.
  • Your IP address: stored alongside the visit, and used to look up the approximate city above. Like the rest of the analytics it is deleted after 90 days.
  • A browser identifier: a first-party cookie that lets us tell that the same browser has been here before. See Cookies below.
  • Session recordings: we use Microsoft Clarity to record how the public pages are used — mouse movement, clicks, scrolling, and the content shown on screen — so we can see where the site is confusing. Text you type into forms is masked and is not recorded. The admin area is never recorded.

If you are signed in, the visits made in that browser are linked to your account.

How we use it

  • To give you access to purchased courses and track your progress.
  • To understand which lessons and pages people actually use, and improve them.
  • To keep the Platform working — rate limiting, and blocking abuse.
  • We do not sell your data, and we do not use it for advertising or share it with ad networks.

Processors we rely on

  • Supabase — authentication and database (your account, progress, purchases).
  • Bunny Stream — video hosting and delivery.
  • Microsoft Clarity — session recordings and heatmaps for the public pages.
  • Hosting, email, and rate-limiting providers as needed to operate the site.

Retention & your rights

  • Account and learning data: kept while your account is active.
  • Analytics: deleted automatically after 90 days.
  • You may request access to, or deletion of, your data — contact us via the Connect page.

Cookies & local storage

  • ec-did — a first-party cookie holding a random identifier, set the first time you open the site and kept for one year. It is HttpOnly, which means no script on the page can read it. We use it for two things: recognising a returning browser in our own analytics, and blocking abuse without having to block an entire shared network.
  • _clck and _clsk — set by Microsoft Clarity, to tell one session apart from the next.
  • Local storage — your sign-in session and preferences, such as theme and language.
  • We run no advertising and set no advertising cookies. Nothing described here goes anywhere except our own systems and the processors named above.
  • You can clear cookies and local storage at any time in your browser settings.

Contact

Connect with any privacy questions.