Privacy Policy
Course Correct is operated by an individual (the "Operator"). This Privacy Policy explains what we collect, why, and how we protect it. Questions? Email support@coursecorrect.app.
1. What we collect
We collect the minimum needed to run the Service:
- Account data: your email address (used for magic-link sign-in).
- Usage data: your practice attempts, answers, mock runs, and resulting per-domain accuracy. This is used to power your own dashboard and analytics.
- Purchase data: a record of which plan you bought and when. Payment card details are never seen or stored by us — they go directly to Stripe.
- Technical data: basic server logs and error telemetry (e.g. timestamps, IP, user-agent) for reliability and security.
2. Why we collect it
- To authenticate you and keep your study data attached to you.
- To show you your mastery and personalise practice.
- To process and honour your purchase and refunds.
- To diagnose bugs and prevent abuse.
3. Who processes your data
We use a small number of trusted sub-processors. Each only sees the data they need:
- Supabase — authentication and database hosting for account, usage, and purchase records.
- Stripe — payment processing. Stripe sees your card details; we do not.
- Hosting provider — for serving the website and API.
- Error telemetry — for capturing crashes and unexpected errors so we can fix them.
We do not sell your personal data. We do not share it with advertisers.
4. Cookies and tracking
We use cookies only where necessary to keep you signed in. We do not use third-party advertising trackers.
5. Data retention
We keep your account and usage data for as long as your account exists. If you delete your account, we delete associated account and usage records within 30 days, except where we are required to keep purchase records for tax or accounting purposes.
6. Your rights
Depending on your location (including under the EU GDPR and the California Consumer Privacy Act), you may have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your data.
- Export your data.
- Object to or restrict certain processing.
To exercise any of these rights, email support@coursecorrect.app from the email address associated with your account.
7. Security
We use industry-standard practices to protect your data, including encryption in transit (HTTPS) and at rest where supported by our providers. No method of storage is 100% secure; we do our best.
8. Children
Course Correct is intended for adults preparing for professional certifications. It is not directed at children under 13 (or under 16 in jurisdictions where that is the threshold).
9. International transfers
Our sub-processors may store or process data in jurisdictions other than your own, including the United States and the European Union. These transfers rely on the safeguards offered by each sub-processor.
10. Changes to this Policy
We may update this Policy from time to time. We'll update the "Last updated" date above. Material changes will be announced on this page.