Skip to content

Privacy Policy

Last updated: October 7, 2026

Coursory is currently an invitation-only private preview. This policy describes what the preview does today and will be reviewed again before public availability.

1. What we collect

When you use Coursory, we collect what you give us and some records the service creates while it runs:

  • Account information: email address, name, avatar, company and job title if you add them, and a one-way hash of your password. We never store the password itself.
  • Project content: course outlines, lesson text, storyboards, the prompts you write, uploaded source files (PDFs, slides, documents), generated images, narration audio and code-lab content.
  • Reviewer responses: the reviewer names and emails a course owner enters when creating a review link, and the comments and approvals reviewers submit through it.
  • Audit records: most actions that create, change or delete data while you are signed in are recorded with your account ID, the time, your IP address and your browser identifier.
  • Credit records: credit grants, holds and charges for AI actions, linked to your account.
  • Usage records: while you are signed in, our server records some actions, such as opening a project or lesson, exporting and searching. Administrators use them to see how the product is used. They stay on our own server and are not sent to an analytics service.
  • Google sign-in data: if you sign in with Google, Google gives us your email address, name and a Google account ID. We do not ask for your contacts or other profile data.
  • Access requests: if you ask for an invitation we store your name and work email, any role, company, team size, LMS and use case you enter, whether you ticked the consent box, which page the request came from, a hashed form of your IP address (not the address itself) and the first 255 characters of your browser identifier.
  • Support messages: the emails you send to support and our replies.

2. Why we use it

We use the information above for these purposes:

  • Accounts and access: to verify it is you and to decide which projects and features you can reach.
  • Course authoring: to render, store and version the courses you create.
  • AI generation: to send your prompts, course context and selected source content to the AI providers listed below, for drafting, images and narration.
  • Credits and usage: to apply credits to AI actions and show you and your administrators what was used.
  • Running the product: to see which features are used and to find problems.
  • Invitations: to review access requests and invite people.
  • Support: to investigate issues you report and to reply to you.
  • Security and legal: to detect abuse and respond to lawful requests.

3. Sharing & subprocessors

We do not sell your personal data. We share data with outside services only to run the features you use. Each service handles data under its own terms and privacy policy, which we do not control and which are linked below.

Hosting

AI providers

When you run an AI action, the prompt, the course context and any source content you selected are sent to the provider that handles that action. The results come back to your project and are stored on our server. The operator of the preview chooses which providers are switched on, so not every provider handles every account's content.

Used only if switched on

These providers may process data outside India. No advertising or web-analytics service is used. If a provider is added, this list is updated.

4. Data retention

Active accounts: we keep your account data and project content while your account is active.

Deleted accounts: when you delete your account from your profile, your name, email address, avatar and password hash are removed from the account record straight away and the account can no longer sign in. What happens to your projects depends on your workspace. If another active administrator exists, ownership of your projects transfers to the administrator who joined earliest, and the projects stay in the workspace. If not, your projects are marked as deleted and hidden.

A daily clean-up job is meant to remove usage records, course-brief conversations and AI job records tied to a deleted account after 30 days, and to detach your account ID from audit entries. Treat the 30 days as a target, not a guarantee. We do not currently promise a date by which the content of hidden projects is permanently erased. If you need that content removed, email us and we will tell you what we can remove.

Audit records: they are kept. There is no automatic expiry today.

Credit and AI usage records: they are kept after an account is deleted and carry only an internal account ID.

Access requests: they are kept until we delete them. There is no automatic expiry today.

Review links: they expire after 30 days unless the course owner chooses another period, and the owner can revoke them.

Backups: scheduled backups are being set up and are not yet part of the preview. Until they are, we make no promise about backup copies or how long they would be kept. When backups are running, this page will describe their schedule and retention.

5. Your rights

You can ask for the following. Most of it you can do yourself from your profile:

  • Access and export: download a JSON file from your profile with your account details, a list of your projects (title, type, status and dates), your audit entries, your usage records and your course-brief conversations. It does not include the full content of your courses. Export each course from its project.
  • Correction: change your name, company, job title and avatar in your profile. To change your email address, write to us.
  • Deletion: use Delete account in the Danger zone of your profile. You confirm with your password, so if you only sign in with Google, write to us instead. Data retention explains what happens next.
  • Withdrawing consent: where we rely on your consent, such as an access request, write to us and we will stop using it.

6. Cookies & browser storage

We use strictly necessary cookies and browser storage. We do not use advertising cookies, cross-site tracking pixels or web analytics.

  • Sign-in session: kept in your browser's local storage, not in a cookie, and removed when you sign out.
  • Google sign-in state: a short-lived HttpOnly cookie (10 minutes) that protects the sign-in step. On pages where Google sign-in is switched on, Google's own script also loads and Google may set its own cookies.
  • Course preview session: an HttpOnly cookie that lasts 4 hours and keeps one person's answers together when they work through a course preview. It needs no account.
  • Preferences: local-storage entries remember that you dismissed the cookie notice, your theme and similar interface choices.

7. Children

Coursory is a tool for working professionals. It is not aimed at children, and accounts are not meant for them.

8. Contact

Questions, complaints or rights requests: email support@coursory.ai. We aim to reply to verified rights requests within 30 days. More ways to reach us are on the contact page.

More about Coursory