Security and data handling
What is in place in the Coursory private preview today, what is not, and how to report a problem.
Coursory is an invitation-only private preview. This page describes the preview as it runs now. It makes no claim of certification, and it is updated when the product changes.
What we store
- Account details: your name, email address, optional company and job title, and an avatar if you add one. Passwords are never stored. We keep a one-way hash (Argon2) so we can check a password you type.
- Course content: projects, uploaded source files, generated images and narration audio, and review comments.
- Records of activity: an audit log of actions, and a ledger of credit grants and charges.
The database and uploaded files live on a server hosted with Amazon Web Services in the ap-south-1 (Mumbai, India) region. The Privacy Policy gives the full list of data and of the outside services that can receive it.
Encryption
- Traffic between your browser and Coursory is sent over HTTPS.
- AI service API keys and LMS connection keys that an administrator saves in Coursory are encrypted (AES-256-GCM) before they are stored. After saving, the app shows only a masked version.
We have not verified how the server's disks and database storage are encrypted, so this page makes no claim about it.
Who can access what
- Roles: each account has a role (administrator, manager, author, reviewer or viewer). Reviewers and viewers can read course content but not change it. The server checks the signed-in account on each request.
- Projects: a project can be opened by its owner, by people the owner adds as collaborators, and by administrators of the same workspace.
- Review links: a link you create for a reviewer lets whoever holds it open that course without an account and, depending on the permission you set, comment or approve. Links expire (after 30 days unless you choose otherwise) and can be revoked. Treat them like passwords.
- Sign-in: email and password, or Google sign-in where the operator has switched it on.
- Audit log: most actions that create, change or delete data while you are signed in are recorded with your account, the time, your IP address and your browser identifier.
The preview runs as one shared workspace that every invited account joins. Separating different customer organisations from one another is planned and not built yet. If you need that separation, talk to us before you upload confidential material.
AI providers
When you run an AI action, the prompt, the course context and any source content you selected are sent to the provider that handles that action. Each provider processes that content under its own terms. Do not upload material you are not allowed to share with them. The provider list is in the Privacy Policy.
Backups and availability
Scheduled backups of the database and uploaded files, stored away from the server, are being set up. Until they are running and tested we make no promise about how often copies are made, how long they are kept or how quickly the service could be restored. The preview has no uptime commitment.
Reporting a vulnerability
Email support@coursory.ai with the subject “Security report”. Say what you found, the address or screen where you found it, and the steps to reproduce it.
- Do not read, change or delete other people's data.
- Do not disrupt the service or run automated tests that generate heavy load.
- Do not publish details until we have replied.
There is no bounty programme.
What we do not claim
- No security certification or independent audit report. We hold none and publish none.
- No enterprise single sign-on. Sign-in is email and password, or Google where it is switched on.
- No separation between customer organisations (planned, not built).
- No promise about disk encryption, backups, uptime or recovery time.