Privacy Policy
Last updated: October 7, 2026
Coursory is currently an invitation-only private preview. This policy describes what the preview does today and will be reviewed again before public availability.
1. What we collect
When you use Coursory, we collect what you give us and some records the service creates while it runs:
- Account information: email address, name, avatar, company and job title if you add them, and a one-way hash of your password. We never store the password itself.
- Project content: course outlines, lesson text, storyboards, the prompts you write, uploaded source files (PDFs, slides, documents), generated images, narration audio and code-lab content.
- Reviewer responses: the reviewer names and emails a course owner enters when creating a review link, and the comments and approvals reviewers submit through it.
- Audit records: most actions that create, change or delete data while you are signed in are recorded with your account ID, the time, your IP address and your browser identifier.
- Credit records: credit grants, holds and charges for AI actions, linked to your account.
- Usage records: while you are signed in, our server records some actions, such as opening a project or lesson, exporting and searching. Administrators use them to see how the product is used. They stay on our own server and are not sent to an analytics service.
- Google sign-in data: if you sign in with Google, Google gives us your email address, name and a Google account ID. We do not ask for your contacts or other profile data.
- Access requests: if you ask for an invitation we store your name and work email, any role, company, team size, LMS and use case you enter, whether you ticked the consent box, which page the request came from, a hashed form of your IP address (not the address itself) and the first 255 characters of your browser identifier.
- Support messages: the emails you send to support and our replies.
2. Why we use it
We use the information above for these purposes:
- Accounts and access: to verify it is you and to decide which projects and features you can reach.
- Course authoring: to render, store and version the courses you create.
- AI generation: to send your prompts, course context and selected source content to the AI providers listed below, for drafting, images and narration.
- Credits and usage: to apply credits to AI actions and show you and your administrators what was used.
- Running the product: to see which features are used and to find problems.
- Invitations: to review access requests and invite people.
- Support: to investigate issues you report and to reply to you.
- Security and legal: to detect abuse and respond to lawful requests.
4. Data retention
Active accounts: we keep your account data and project content while your account is active.
Deleted accounts: when you delete your account from your profile, your name, email address, avatar and password hash are removed from the account record straight away and the account can no longer sign in. What happens to your projects depends on your workspace. If another active administrator exists, ownership of your projects transfers to the administrator who joined earliest, and the projects stay in the workspace. If not, your projects are marked as deleted and hidden.
A daily clean-up job is meant to remove usage records, course-brief conversations and AI job records tied to a deleted account after 30 days, and to detach your account ID from audit entries. Treat the 30 days as a target, not a guarantee. We do not currently promise a date by which the content of hidden projects is permanently erased. If you need that content removed, email us and we will tell you what we can remove.
Audit records: they are kept. There is no automatic expiry today.
Credit and AI usage records: they are kept after an account is deleted and carry only an internal account ID.
Access requests: they are kept until we delete them. There is no automatic expiry today.
Review links: they expire after 30 days unless the course owner chooses another period, and the owner can revoke them.
Backups: scheduled backups are being set up and are not yet part of the preview. Until they are, we make no promise about backup copies or how long they would be kept. When backups are running, this page will describe their schedule and retention.
5. Your rights
You can ask for the following. Most of it you can do yourself from your profile:
- Access and export: download a JSON file from your profile with your account details, a list of your projects (title, type, status and dates), your audit entries, your usage records and your course-brief conversations. It does not include the full content of your courses. Export each course from its project.
- Correction: change your name, company, job title and avatar in your profile. To change your email address, write to us.
- Deletion: use Delete account in the Danger zone of your profile. You confirm with your password, so if you only sign in with Google, write to us instead. Data retention explains what happens next.
- Withdrawing consent: where we rely on your consent, such as an access request, write to us and we will stop using it.
7. Children
Coursory is a tool for working professionals. It is not aimed at children, and accounts are not meant for them.
8. Contact
Questions, complaints or rights requests: email support@coursory.ai. We aim to reply to verified rights requests within 30 days. More ways to reach us are on the contact page.