Privacy Policy
1. What data we collect
When you register and use the Service, we may process, among other things: your email address, name (if provided), year of birth (only if you have provided it yourself — the field is optional), gender (only if you have provided it — the field is optional, including a “prefer not to say” choice; used solely to address you with the correct grammatical form in messages), account data and technical data needed for the site to work (for example, browser type, the IP used when contacting the server — to the extent set by the hosting and analytics settings).
Site stability statistics. We keep aggregate stability statistics — plain counters (how many page loads and technical failures, grouped into broad device and browser categories, and by failure type — with no error text and no page addresses; we display only groups of at least five page loads). These counters contain no identifiers (no IP address, no session, visitor or account identifier) and cannot, alone or combined, identify or single out any individual; they do not relate to any identifiable person and are therefore not personal information. Separately from these aggregate counters, we measure technical performance metrics (load times, layout stability): these are tied to your session and handled together with the rest of the web analytics on the basis of your cookie consent.
Help us fix problems (optional). If you are signed in and have turned on “Help us fix problems”, then when a technical error happens in your browser (for example, a page fails to load) we store your device type, browser and operating system, the page address (as a template, without parameters) and the error text — to find and fix the problem. The record is linked to your account. We do not store the IP address for these errors, and personal data is removed from the error text. We keep them no longer than 30 days. Like the rest of your data, these records are included in our encrypted backups (see §4 “Storage and security”). The feature is optional and off by default; you can withdraw consent anytime under “Communications” — we then stop collecting and delete the error records already collected.
2. Purposes of processing
The data is used to:
- create and maintain your account;
- provide access to courses after payment or on other grounds (a promo code, a gift, etc.);
- contact you about access, security and support;
- match programs and form study groups by experience level (in de-identified summary statistics);
- confirm that you are of legal age (18+). If you choose to enable your public master page (see §17), we use the year of birth you provided to check that you are 18 — the public page is available only to adults. This specific use of your year of birth is an individual eligibility check. If no year of birth is on file, or the age is under 18, we will not let you enable the page; your year of birth itself is not shown on the page. We either take the year from the optional field you provided earlier or ask you to enter it at the moment you enable the page;
- comply with legal requirements.
3. Sharing data with third parties
We do not sell your personal data. For the platform to operate, your data may be processed by the following services:
- Stripe Inc. (USA) — payment processing.
- Resend Inc. (USA) — sending email messages.
- Hostinger International Ltd (USA) — hosting of the application and database (servers located in a data center in the United States).
- Cloudflare, Inc. (USA) — content delivery network (CDN), reverse proxy, and attack protection; processes visitors’ IP addresses and network requests.
- Google LLC (USA) — Google Drive is used for encrypted backups of the database and file storage (diplomas, invoices) for disaster-recovery purposes. Backups are encrypted before upload; the keys are stored separately from Google Drive.
- Anthropic PBC (USA) — the Claude language model that powers the «Проводник» (Provodnik) AI assistant; processes the text of your chat messages to generate a reply, under its standard commercial API terms of service. See §19 for details.
All of these partners operate in line with applicable data-protection standards. Transfers of data to the USA are made on the basis of contractual safeguards (Data Processing Agreements / Standard Contractual Clauses).
Quebec residents have the right to request additional information about such transfers under section 17 of Law 25 by writing to [email protected].
Public master page and social-media links (cross-border aspect). If you enable the public master page (§17), it becomes publicly accessible across the internet and is indexed by search engines — meaning the data on it (the name you choose, the year you joined the academy, your work, the fact that you earned diplomas and contest wins) may be viewed and cached by people and services outside Canada. When the page is published we also generate a branded social-share card (a preview image with a link to the page, the name you chose, the count of works/diplomas/wins, and the first photo from your portfolio): when you or anyone shares the link, the platforms themselves (for example Facebook, Instagram, X, LinkedIn) fetch and cache that card, typically outside Canada. If you add links to your social-media profiles, following them takes the visitor to third-party platforms (the public page displays all links you add from the supported set: Instagram, TikTok, Pinterest, Facebook, YouTube, VK, Threads), typically located in the USA or other countries. The academy does not control these platforms and is not responsible for their processing of data; no separate adequacy mechanism is designated for them — the visitor leaves by your own decision to publish the page and add the links. Enabling the page and adding links is your explicit choice (opt-in); until you enable them, no such transfer takes place.
Transfer of data in a payment dispute (chargeback). If a dispute arises over a payment through your bank or payment system, we may transfer to the payment provider (Stripe Inc., USA) your personal data to the extent necessary to defend our contractual rights: the IP address and user agent at the time the purchase was confirmed, billing data, email address, information about the purchased product, and records of communications with your account (where applicable). The transfer is made under art. 17 of Law 25 (cross-border transfer where adequate protection exists — the Stripe DPA complies with Law 25 + GDPR). The list of data transferred for a specific dispute is available on request via [email protected]. Access to the evidence-export function is restricted to the super-admin account and is logged in an immutable audit log.
4. Storage and security
We take reasonable organizational and technical measures to protect data against unauthorized access, alteration or disclosure. The retention period is determined by the need to provide the services and by legal requirements.
The administrative action log (audit log) is kept under a two-tier retention policy:
- Financial events (issuing invoices, payments, course access, issuing gift codes, promo codes) — ~6 years in accordance with the requirements of the Canada Revenue Agency (Books and Records Retention Requirement) and the Consumer Protection Act (section 263).
- Other administrative events (content moderation, security incidents, news, polls) — ~2 years, which corresponds to a reasonable PIPEDA retention policy for handling possible complaints.
The audit log contains references to actions (for example, “admin changed a user’s role”) but does not contain payment data. A hard delete of a user keeps the audit rows intact with a nulled actorUserId — this is required for a compliance audit (Law 25 art. 14 does not block retention with a lawful, justified purpose).
Test results and attempts are kept under a three-tier retention policy based on their role in issuing diplomas:
- Attempts on tests that affect a diploma (tests flagged as “required to obtain a diploma”) — ~6 years from completion, in accordance with the requirements of the Canada Revenue Agency (CRA Books and Records Retention) and for possible diploma verification by employers / regulators. We keep your answers, the final score, the “pass/fail” mark, and a point-in-time snapshot of the test state at the moment of the attempt (the questions and options as they were shown to you).
- Attempts on regular tests (with no diploma gate) — ~2 years, which corresponds to a reasonable PIPEDA retention policy. After this period, attempts are deleted automatically.
- Abandoned attempts (started but not submitted) — 90 days. If the attempt is not resumed within that time, it is deleted without a trace.
When you delete your account, we delete the text fields of your answers (free text) in the same transaction as the account itself (Law 25 art. 14 — the right to erasure). Numeric indicators (scores, the pass mark, the test identifier) are kept in de-identified form (with a nulled userId) for aggregate analytics and auditing, if those attempts related to diploma tests and their retention period has not expired.
Admin test previews (runs in “as a student would see it” mode) are flagged with isAdminTest=true and are not counted in test statistics. They are deleted on the same schedule as regular attempts (90 days for abandoned ones, 2 years otherwise).
Practical-work video recordings. If you attach a short video to your work (optional, up to ~60 seconds), it is collected solely for the review of your work by the instructor. The video is stored on our server, is accessible only to you and the instructor, and does not appear in public areas (gallery, contest). The file is deleted automatically within 7 days after review (or, if the work was not reviewed, no later than 21 days after upload); technical metadata, including geolocation, is removed when the video is processed. Before automatic deletion you can download your own video from your account; after deletion the recording is no longer available — this is part of our data-minimisation policy. The server is physically located in the United States (see section 3 on cross-border transfer). Any use of the video for advertising is governed by the Terms of Service (the “User content” section): materials in which a specific person can be identified are not used in advertising without your separate consent.
Photos of practical work and instructor feedback. The photos you attach to a submission are kept while your paid access to the course is active — that is, until the end of the course; once access ends they are deleted automatically. If the instructor never reviews the work, its photos are deleted in any case no later than 180 days after submission. The instructor’s feedback stays available in your account: text comments remain as a record of your mistakes; voice notes and marked-up photos are kept for up to 90 days. All of this is stored on our server in the United States (see section 3), is visible only to you and the instructor, and is never shown in public areas.
Final work and course review. If a course ends with writing a review (a condition for the diploma), your review together with the attached final work becomes part of the course’s reviews section and is kept indefinitely for as long as it stays published — so it is not auto-deleted on a schedule. The basis is your voluntary review and proof that you completed the course. A review approved as a diploma condition cannot be removed from your account on your own; you can request its removal as part of deleting your account (see §5) or by contacting us using the details in the data-protection-officer section. A review is published by your own action and after moderation.
5. Your rights
Depending on the applicable law, you can request the clarification, correction or deletion of your data, and withdraw consent to mailings (if used). For requests, use the contacts listed in the section on the person responsible for personal-data protection.
As part of operating the platform, the administration may keep internal incident notes — for example, in support requests, while observing breaches of community rules, or following complaints about your account — and may assign your profile internal classification labels (tags) — for example, the source you came from, or your engagement status with the academy. Under art. 9 of Law 25, these notes and labels are considered your personal data and are available in the export through your account (Export my data) or on request at [email protected].
Program suggestions and recommendations (including diagnostic results and internal labels) are advisory: they are not decisions made solely by automated means that produce legal or similarly significant effects for you — labels are assigned and reviewed by a person. You can ask about them at [email protected].
If you believe your personal-data rights have not been respected, you may contact the person responsible for personal-data protection (see section 6) and, if you are not satisfied with the response, file a complaint with the Commission d’accès à l’information du Québec (CAI).
6. Person responsible for personal-data protection
In accordance with section 3.1 of Law 25, the person responsible for personal-data protection (the Privacy Officer) at ZANAILS Academy is Oleksii Patiutko. This person handles requests for access to, correction of and deletion of data and is responsible for compliance with the applicable personal-data legislation.
For any matters relating to personal data, including requests for access, correction or deletion, contact: [email protected]. We will respond within 30 days.
7. Changes
This policy may be updated; the current version is always on this page. Related documents: Terms of Service.
8. Cookies and technical data
The site uses three categories of cookies:
- Necessary — they make authentication work, protect against request forgery, and remember the interface language. Always on: without them the Service does not work. This also includes the referral-program cookie
zanails_ref(90 days, HttpOnly, SameSite=Lax): it records the invitation code when you follow a referral link, so that at registration we can credit keys to the person who invited you. It is not used for marketing or analytics purposes and is not shared with third parties — see §12 for more. - Analytics — they collect visit statistics (pages, referral source, device type, session duration) to improve the site. They are enabled only with your consent via the cookie banner. Cookies:
zn_visitor(6 months),zn_session(30 minutes). - Marketing — they may be used by external services (Meta Pixel, Google Ads) for remarketing. They are enabled separately, by your choice in the banner. They are not connected at this time.
You can change your consent at any time: clear the site’s cookies in your browser or delete the zn_consent cookie — the banner will appear again.
9. Visit analytics
With your consent, we store data about visits: pages viewed, referral source (UTM tags, referrer), general country (if it is provided by the hosting infrastructure), device type, browser language and related technical data. In the analytics context, the IP address is not stored in clear form — we keep only a one-way salted hash for deduplication, with no way to recover the original IP.
Other contexts in which an IP address may be stored (without hashing) are described in a separate section below.
Raw events are deleted on an automatic cleanup schedule (as a rule, 90 days). Aggregated, de-identified metrics may be kept longer for analysis.
The data is used solely by us to improve the Service and is not shared with third parties without your separate consent (see §3).
10. IP address: when it is stored in clear form
To comply with legal requirements, protect against fraud and handle disputes, the IP address may be stored in clear form in the following cases:
- Confirmation of consent before payment (the
PurchaseConsentmodel) — the IP and User-Agent are recorded as evidence for handling possible chargeback disputes. For consents that did not lead to a payment, the record is deleted entirely after 180 days. For paid consents, the IP/User-Agent are redacted (nulled) after 180 days — once the Stripe dispute window has closed; consentSnapshotHash and legalBundleVersion are kept as unlinked proof of payment within the tax documentation. - Live-course applications (the
LiveCourseRequestmodel) — a security audit of form submissions. The IP retention period is 30 days (automatic cleanup by a cron job). - Feedback / support requests (the
FeedbackReportmodel) — to protect against abuse and trolling. The retention period is 365 days; the IP and User-Agent are redacted in the first stage of the purge cron after 30 days (the body of the request is kept longer for admin handling). - Server error log (the
ErrorLogmodel) — the IP is kept for forensics during security incidents. PII in text fields (message / stack / route / user-agent strings) is redacted on write (email / phone / tokens / secrets). After 30 days from creation, the raw IP, User-Agent and metaJson are nulled (cron stage 1); the record itself is then deleted 30 days after being resolved, or 180 days for open events. - Anti-fraud rate-limit buckets (the
SecurityRateLimitBucketmodel) — the IP may be part of a bucket key for a short time (minutes to hours) to count the frequency of requests from one IP. Once the window expires (resetAt) the record is nulled and deleted. It is not used for tracking or identification. - Gifting a course (the
GiftInvitationmodel) — the IP is recorded at the moment the invitation is created (createdFromIp) and at the moment it is accepted by the recipient (acceptedFromIp) — this is a requirement of Law 25 art. 8 (forensic triangulation in case of a dispute over an unauthorized transfer). The IP retention period is 30 days (Stage 1 redaction within thepurge-gift-invitationscron job); addressable PII (the recipient’s email, the message text, the sender’s email snapshot) is kept longer — see §13. - Email change (the
EmailChangeRequestmodel) — the IP is recorded at three points of the double opt-in flow: when the request is initiated (requestedFromIp), when it is confirmed from the new email (confirmedFromIp) and when it is cancelled (cancelledFromIp) — a requirement of Law 25 art. 8. The requests themselves expire automatically after 14 days; the IP fields are nulled when the account is deleted (soft or hard delete).
Storing the IP in these contexts is based on a legitimate business interest: protection against fraud, handling of payment disputes, compliance with the law. The retention period is limited to what is necessary for the purpose of the context and is enforced by a cron cleanup.
Open lesson (the free-lesson lead magnet)
On an open-lesson page (/academy/[course]/open) anyone — including visitors who are not signed in — can watch one lesson of a course for free. To show an honest social counter (“N people watched”) and understand audience interest, we keep a few de-identified counters. The basis is a legitimate interest (our own engagement analytics), with no tracking cookie:
- Views (the
OpenLessonViewmodel) — when the video first starts playing we count one unique view via a per-day pseudonym: a one-way salted hash of your IP address, a coarse device class, and the date. The pseudonym rotates every day and cannot link your visits across days; the original IP cannot be recovered from it. We do not store the IP itself, and the view is not linked to any account. Bots and staff previews are excluded from the count. Retention — 36 months (cronpurge-open-lesson-views). - Reposts (the
OpenLessonSharemodel) — if you share an open-lesson link, we record the fact of the repost with the same per-day pseudonym (virality analytics), for 36 months (cronpurge-open-lesson-shares). If you are signed in, your personal open-lesson link carries a referral code (?ref) so you get reward keys if someone buys the course through it (see §12); in that case we link the repost record to your account (auserId) — to credit the keys and so you can access or delete that record; the identifier is nulled when your account is deleted. A guest repost carries no referral code and is not linked to an account. - “Watched → bought” attribution — if you go to checkout for a course from its open-lesson page, we mark that fact with a server-side, cookie-free marker and store it on your order (the
openLessonAttributedSlugfield — the course slug) to measure the magnet’s conversion. This is not cross-site tracking: the marker lives only inside our own funnel and is not shared with third parties beyond what is needed to complete payment (see §3, §11).
These counters are pseudonyms (personal data under Loi 25) and cannot be reversed without our secret salt. Views and guest reposts are not linked to your account; a repost by a signed-in user additionally stores your identifier (see above) and is included in your data export. For access to, or to object to, this processing you may contact our Privacy Officer (§6). The full technical retention spec is in docs/DATA-RETENTION-POLICY.md.
11. Email address observed by the payment processor
On the Stripe Checkout page you can change the email tied to the payment — Stripe uses it to build its own payer profile and (with the corresponding Stripe-account setting) to send its own receipt independently of us. After the payment is completed, Stripe passes this email to us as part of the webhook (checkout.session.completed).
What we do with this email:
- We use it for fallback matching of a payment to an account, if the primary session identifier (
client_reference_id, which we pass to Stripe when launching checkout) is missing for some reason. This is needed so that we can activate your course access even after a non-standard checkout flow. - We do not store it in clear form in the main business tables of the database. The ZAnails email receipt is sent only to the email of your billing profile (the one you entered yourself at registration or when filling in the billing form), not to the email entered in Stripe Checkout.
- We log the discrepancy for admin observability. If a customer session is successfully matched to your account by
client_reference_idbut the email from Stripe differs from your account email, we additionally record this fact in the audit log (theAuditLogmodel, thestripe.customer_email_mismatchevent). The audit record stores only the other party’s domain and a SHA-256 hash prefix (12 hex characters) of the full email — this is enough to investigate possible fraud / misconfiguration as a correlation (the same hash → the same email), but does not allow the original email to be recovered. - We do not use it for marketing mailings. CASL (Canada’s Anti-Spam Legislation) requires explicit consent for commercial electronic messages, and we have consent only from your account email. Emails observed in Stripe receive no CEM from us.
Stripe independently processes the customer_email in accordance with its own privacy policy.
12. Keys program and referral program (ZANAILS Rewards)
The Service includes a keys program and a referral program. As part of this program we process the following data:
- Balance and award history — the
RewardLedgerEntrytable: the event type (course purchase, referral, manual adjustment), the number of keys, the status (pending / available / cancelled / reversed), a snapshot of the rule at the time of the award. The link touserIdis kept until a request to delete the account — after that the FK is nulled (ON DELETE SET NULL), and the text fieldsreasonandmetaJsonare replaced with the placeholder[REDACTED:erased-pii]. The records of amounts are kept as financial data for up to 6 years in accordance with CRA requirements (Income Tax Act §230) for the purposes of refunds and tax reporting. - Referral code — the
ReferralCodetable: a unique token of the formZR-XXXXX. The code is tied to your userId. When the account is deleted, the code is deleted immediately as part of the overall erasure operation (Law 25 art. 14): the record itself disappears, and in historical ledger rows any mention of the code is replaced with the marker[REDACTED:erased-pii]. - Referral attribution — the
ReferralAttributiontable: the “referrer ↔ invitee” link. When one of the parties is deleted, the FK is nulled; the event itself (status + qualifiedAt) remains as an aggregate indicator for calculating the annual limit. - Referral cookie
zanails_ref— set when you follow a referral link. It contains only the referral code (no PII). HttpOnly, SameSite=Lax, Secure in production, lifetime 90 days. Cleared after a successful registration. - Vault unlock (RewardRedemption) — the
RewardRedemptiontable: a record of spending keys to unlock a Vault material. Fields: the number of keys spent, the course ID, the status (confirmed / cancelled), a first-view markconsumedAt, timestamps. When the account is deleted, theuserIdis nulled (FK SetNull); the admin commentcancelReasonis replaced with the marker[REDACTED:erased-pii]. Numeric fields (the amount spent, the status, the idempotency key) are kept as a financial record for 6 years in accordance with the CRA. - Partner perks (Phase 3) — the
PartnerReward(catalog) andRewardRedemption(spends) tables. When you take a partner perk we store: the partner-perk ID, the number of keys spent, the status (confirmed / fulfilled / cancelled), a short code (codeIssued) — an opaque 8-character token with no PII, presented to the partner, and timestamps. When the account is deleted, theuserIdis nulled; the numeric fields and the code are kept for reconciliation with the partner for 6 years (CRA retention). Transfer of data to the partner: we do NOT pass the partner your name, email or other personally-identifying data without explicit per-redemption consent. The partner sees only the code you present to them — they have no ID for your account in our system.
What we show the referrer. When you arrive via another student’s referral link and register, we show them in their rewards panel your first name and the first letter of your last name (for example, “Maria K.”), the fact of registration and the fact of a first payment, as well as the number of keys credited to them. Your full last name, email and information about which courses you bought are not shared. This is reasonable de-identification by industry standard (Uber, DoorDash, LinkedIn) with PI minimization under Law 25 art. 12. If you prefer to hide even a partial name, write to [email protected] and we will switch your record to the anonymized “Student” mode.
Annual referral-program limit — 50 qualified referrals per calendar year. The limit is set in line with the CRA’s (Canada Revenue Agency) treatment of regular referral awards as income from self-employment above a certain threshold. It resets on January 1. More on the page “How keys work”.
The right to delete program data — as part of an overall account-deletion request (see §5). Financial records of key amounts are kept for 6 years (CRA §230); PII in these records is anonymized on deletion.
13. Gifting a course (Gift Course Transfer)
If you pay for a course “as a gift for a friend”, the Service processes the additional personal data described below. The purpose of processing is stated for each category separately — this is a requirement of article 4 of Law 25 (Quebec).
- Recipient’s email (
toEmail) — collected to send the invitation. The recipient sees that the invitation came from you (a snapshot of the sender’s email in the message). The recipient’s email is kept while the invitation is pending, plus 180 days after a terminal status (accepted / expired / revoked / recipient_already_owns); after that the email is redacted to[redacted](Stage 2 cronpurge-gift-invitations). - Your personal message to the recipient (
buyerMessage, up to 500 characters) — optional, shown to the recipient in the invitation email. Kept under the same policy as the recipient’s email; redacted 180 days after a terminal status. - Creation and acceptance IP addresses (
createdFromIp,acceptedFromIp) — Law 25 art. 8 forensic triangulation (see §10). Retention period — 30 days (Stage 1 redaction). - Snapshot of the sender’s email at the moment the invitation is created (
fromEmailSnapshot) — shown to the recipient in the email and on the acceptance landing page (with domain masking). Kept 180 days after a terminal status, then redacted.
Legal nature of the transfer. Gifting a course is a stipulation pour autrui within the meaning of art. 1444 of the Civil Code of Québec: a contract for the benefit of a third party with conditional performance. This is not a gift card within the meaning of art. 187.4 of the Consumer Protection Act — no value-bearing token is transferred to the recipient, and the fact of payment is registered to you as the buyer. If the invitation is not accepted within the 30-day period, the course stays with you — no one loses any money. No refund is issued for a gifted course (see Terms of Service §11).
What we do not show. The recipient does not see your IP. You do not see the recipient’s IP. No one (other than you and the recipient) sees your message.
The right to revoke. You can revoke a pending invitation at any time via “Gifts” in your account. After revocation, the course stays with you.
The right of access (Law 25 art. 27) — a list of all your invitations (sent and accepted) is available in the export via Export my data (the giftInvitations section).
14. Changing the account email address
Changing the email tied to the account is implemented through double opt-in with additional security safeguards.
- What is collected: the new email address; the sha-256 hashes of two one-time tokens (for confirmation and for cancellation) — the tokens are stored in clear text only in the body of the emails. The token itself is not written to the database.
- IP addresses at three points of the flow (see §10). The purpose is Law 25 art. 8: investigating an incident if it later turns out the email was changed not by you.
- Dual notification (Law 25 art. 17): the email with the confirmation link goes to the new email, and the email with the cancellation link goes to the old one. If someone tries to change the email on your behalf, you will receive a notification and can cancel the request.
- Request validity period — 14 days. After that, both tokens become invalid automatically.
- The right to cancel — the “Cancel request” button in your profile or the link from the email sent to the old address.
- After confirmation the Service automatically ends all your active sessions (including mobile apps), and you will need to sign in again using the new email — this protects against session hijacking at the moment of the email change.
The right of access — the history of email-change requests (including IP addresses) is available in Export my data (the emailChangeHistory section).
The right to erasure (Law 25 art. 14) — the IP fields are nulled when the account is deleted (both soft and hard delete); the request records themselves are deleted automatically together with the account (FK cascade).
15. Inactivity reminders
If you have not opened any learning materials for more than 30 days in a row, we may send you one reminder that your course access is preserved and that there is something new in the academy.
- Frequency: no more than one email every 30 days. This is ensured by the
lastInactivityReminderSentAtfield with a server-side CAS lock — a repeat send within the 30-day window is technically impossible. - What is used: your account email address and your name (the first word of User.name, if provided). No other personal data goes into the email.
- Legal basis: CASL §6(2)(c) — implied consent for your own customers (you are our customer, so no separate opt-in is required). In addition, we include a visible unsubscribe link in the body of every email (CASL §6(2)(c) + RFC 8058 One-Click headers).
- The right to turn it off: at any time via the toggle on the “Emails” page or the “Unsubscribe” link in any of the emails. After opt-out, the cron no longer counts your account for this channel.
- Who it is not sent to: users with the status blocked / soft-deleted; users with
inactivityReminderOptOut=true; users with activity in the last 30 days.
This is not a marketing mailing about new courses — for that there is a separate consent (marketingEmailOptIn). The inactivity reminder is a service notice about your unused access.
16. Study journal and calendar sync
In the “Study journal” section you can plan your own sessions for the academy’s courses — add events (date, time, lead reminder, optional notes), mark sessions as done, and, if you wish, subscribe an external calendar (Apple Calendar / Google Calendar / Microsoft Outlook) to these events. This feature is built with a focus on data minimization under article 21 of Law 25.
What is collected
- Planned events: the start date and time (UTC + your time zone from the browser), duration (60 minutes by default), how many minutes before to send a reminder (60 minutes … 14 days), a link to the course/lesson (if provided), optional notes up to 1000 characters.
- A secret token for the webcal subscription (24 bytes of random data, base64url) — created only when you press “Create a calendar link” yourself. Before that there is no secret. The token is part of a URL of the form
/api/account/study-plan/feed/<token>; anyone who knows the URL can read your academy calendar. The link is therefore hidden by default and is shown only when you press “Show link”. - Token usage metadata: the timestamp of the last request by the external calendar (
lastAccessedAt) + a request counter. IP addresses and user agents on requests to the feed are not stored (only a per-token rate limit — 60 requests per hour, in Redis memory, with no logging).
Transfer of data to external calendars (cross-border)
When you add the webcal link to Apple Calendar, Google Calendar or Microsoft Outlook, these services periodically poll our server and store the returned schedule in their data centres:
- Apple Inc. (USA / Ireland) — iCloud Calendar, polling every ~15 minutes (not user-configurable).
- Google LLC (USA / EU) — Google Calendar, polling every ~24 hours (not user-configurable).
- Microsoft Corporation (USA / EU) — Outlook Calendar, polling every ~3 hours (not user-configurable).
This data contains: the course/lesson title, the event title, the date + time, duration, the lead reminder, the time zone. Your personal notes (the “notes” field) are NOT transmitted in the webcal feed — even if you wrote something private there, it is not visible to external calendars. This is an architectural decision following the art. 21 Law 25 minimization principle.
Transfer to the USA/EU is made under art. 17 of Law 25 (cross-border transfer where adequate protection exists — Apple, Google and Microsoft have standard Data Processing Agreements + Standard Contractual Clauses compliant with Law 25 and GDPR). The subscription is opt-in — a cross-border transfer event happens only if you add the webcal link to an external calendar yourself.
Managing and revoking access
- Change the link — at any time in
/account/study-plan. The old link immediately stops working (external calendars will get a 404). - Revoke the link — in the same place. After revoking, you need to explicitly create a new one if you want to return to syncing.
- Automatic revocation on security events: when you change your password, reset your password via an email link, change your email address or activate/deactivate two-factor authentication, all active webcal links are automatically revoked. This mirrors the session-invalidation logic — if one of these factors of your account could have been compromised, we assume the webcal URL could have leaked too.
- Automatic revocation for inactivity: if an external calendar has not accessed the link for more than 180 days in a row, the link is automatically revoked (
revokedReason='inactivity').
After revocation, the webcal service on the Apple/Google/Microsoft side will get a 404 on its next poll. Apple/Google usually remove the linked calendar from the user’s UI within 24–48 hours; Microsoft — up to 7 days (depending on client settings). To remove the calendar immediately, you can do it manually in the UI of the respective provider.
Retention periods
- Past unattended events (startsAt < now − 90 days AND not marked as done) — deleted automatically once a day. 90 days is the “I might still come back to this plan” window.
- Completed events (marked as “done”) — kept while the account is active, as your personal learning history.
- Events for a course whose access was revoked (a refund or admin revoke) — future unattended events are deleted immediately along with the access revocation. You will get one summary notification of how many events were cancelled.
- Revoked webcal links — the secret is kept for another 30 days after revocation (for auditing), then the row is deleted.
- In-app reminder notifications — 24 hours after creation, then deleted from the bell dropdown.
The full technical retention specification is in the file docs/DATA-RETENTION-POLICY.md §2.12. The Privacy Impact Assessment is in docs/PIA-STUDY-JOURNAL.md.
17. Public pages where your data may appear
Some of the Service’s features publish a limited amount of data on publicly accessible pages. Below is exactly what is shown and how to remove it.
- Public diploma verification (
/verify/diploma/<number>) — an exact diploma number confirms its authenticity: the graduate’s name (as on the diploma), the course title, the issue date and the status. This is so that an employer or client can verify a diploma via a link you gave them yourself. The page is not indexed by search engines (noindex), opens only with the full number and is protected by request-rate limiting. On an account-deletion request, public verification stops immediately — without waiting for the 30-day window to end. - Public master page (
/master/<address>) — an open showcase of your work and achievements under a name you choose. It is enabled only with your separate, explicit consent (off by default) and only if you are 18 or older (see §2 — confirmation via year of birth). Unlike diploma verification, this page is open to everyone and indexed by search engines — anyone on the internet can find, open, view and save it. It shows: the name you choose, the year you joined the academy, your work, the fact that you earned diplomas (course title and year, without copies of documents and without the diploma number) and contest wins — without email or contacts. Your year of birth itself is not shown on the page. Legal basis — your consent. We publish this data solely because you gave explicit consent, and you can withdraw it at any time and without giving a reason in your account settings. After withdrawal the page stops opening immediately; search engines may still show a saved copy from their cache for some time — this is outside our control (you may additionally request de-indexing, see below). On account deletion the page is turned off immediately. Links to your social media. If you add links to your social-media profiles, they are shown on this public page and lead to third-party sites that the academy does not control (Instagram, TikTok, Pinterest, Facebook, YouTube, VK and Threads are supported; the page displays all links you add). By following such a link you leave our site and arrive on a platform with its own privacy policy and its own processing of data, including outside Canada (see §3 on cross-border transfers). Any link can be removed in settings at any time. Social-share card. When the page is published we create a branded preview image of it (the name you chose, the count of works/diplomas/wins and the first photo from your portfolio); it can be shared, and social platforms fetch and cache it on their side (see §3). - Course reviews — published only after moderation. The author’s name is shown in shortened form (“First name L.”), with an avatar from the profile (if you uploaded one). When the account is deleted, your review is hidden immediately.
- Free-materials comments and reposts. Under free videos (Academy → “Free materials”), registered, email-verified users can post comments and replies. Comments are public — anyone who opens that video on the site can see them, including visitors who are not registered; the author’s name is shown in shortened form (usually “First name L.”). A comment appears immediately, without prior review: we do not screen every comment in advance, but we may (are not obliged to) hide or remove a comment that breaks the law or the rules. You are responsible for the content of your comment — do not post other people’s personal information, insults, or defamatory statements (see Terms of Use, §9). You can delete your own comment at any time. When your account is deleted your comments stop being shown to others immediately, and their text is permanently removed (the personal information it contains is stripped) when the account is finally erased; because the comment was public, others may have seen, quoted, or saved a copy — we remove it from our own pages but do not control copies made by third parties. If you share a video (the “Share” button), we record the fact of the repost — which material, when, and how (your device’s Share menu or a copied link) — to understand which free materials interest the audience (engagement analytics). We keep this record no longer than needed for that purpose, and we do not link it to the people you sent the link to; the link itself contains no personal data about you (no referral code or identifier). If you continue to an external platform (e.g., Facebook), you become subject to its own policy and data processing, including outside Canada (see §3). When your account is deleted this record is de-identified — your identifier is removed from it and it is no longer linked to your profile (only a technical record remains: which material and when). Likes on videos and comments are also recorded and detached from your account when it is deleted. Even without deleting your whole account, you may ask us to remove your comments or repost records — by writing to the email address given below (Law 25 art. 28.1).
- Ambassadors list (
/academy/ambassadors) — only your name is shown, and only with your separate consent (opt-in). Consent can be withdrawn at any time in your account; after withdrawal the name disappears from the page. - Contest and Hall of Fame — the work and the shortened name of prize-winning participants are displayed publicly; during voting the author’s name is hidden. Management and details are in the contest section.
The right to remove public content (Law 25 art. 28.1). Regardless of deleting your whole account, you can request that your public content be removed or de-indexed — a review, a comment under a free material (and repost records), a work, the public master page or an individual social-media link, or excluding a diploma from public verification — by writing to [email protected]. In particular, you can request that the master page be de-indexed (to remove it from search-engine results and cache) and that individual social links be deleted through this same channel. We handle such a request within a reasonable time.
18. Notification of confidentiality incidents
In the event of a confidentiality incident (unauthorized access, loss or disclosure of personal data) that creates a risk of serious harm, we notify the affected users and the Commission d’accès à l’information du Québec (CAI) in accordance with section 3.5 of Law 25, and we keep an internal register of confidentiality incidents. The notification includes a description of the incident, the categories of data affected and the recommended measures to reduce the risk. The internal response procedure is set out in docs/BREACH-RESPONSE-PLAN.md.
19. AI assistant «Проводник» (Provodnik)
“Provodnik” is an AI assistant (a chat) built into the site, available to all visitors, including those not signed in, in Russian, English and French. Use is voluntary: it activates only when you open the chat and send a message yourself. It is informational (how to buy a course and get access, what plans include, diplomas, keys, submitting work, general information on prices and policies) and may make mistakes; it does not replace professional advice and gives no medical, chemical, legal or financial advice. On refund, payment, legal and personal-information questions it states only the general principle and directs you to the relevant policy and to a human.
19.1. Two categories of users. How we handle data depends on whether you are signed in. (A) Anonymous visitors (not signed in): we do not know who you are. The conversation is stored with no account link (no user identifier), in de-identified form, and for a short period. Personalization is off: the assistant accesses no account data. Exposure of personal information here is minimal — provided you do not type unnecessary details into the chat yourself. (B) Signed-in users (with an account): the conversation is stored linked to your account, in de-identified form, for a longer period, and is deleted when your account is permanently deleted. You also have personalization — answers about your own data (§19.2).
19.2. What is processed. (a) Conversation content (both categories) — the text of your messages and the assistant’s replies. Please do not enter unnecessary personal information (passwords, card or document numbers, health details); the assistant is not designed for that. (b) Account data — signed-in, email-verified users only. When you ask about your own data (“where is my diploma”, “how many keys do I have”, “did I pass the test”, “when does my access expire”, “was my work reviewed”), the assistant uses read-only internal tools to show your diploma status (including your diploma number and issue date), keys balance, course access and plans, quiz results and the status of submitted work. The tools are strictly scoped to your account: the identifier comes solely from your own direct server session (not from any administrator “view-as-student” mode), no model-supplied identifier is accepted, and another person’s data is never disclosed or compared. The assistant changes, credits and cancels nothing — it only displays. When the assistant retrieves such data for your question, the retrieved information (e.g. diploma status and number, course titles, keys balance) is included in what is sent to the AI provider to compose the reply (§19.5), but without your name and without your account number.
19.3. Purposes: (1) support — answering questions about how the academy works and, for signed-in users, about the status of their own materials; (2) service quality and improvement — from de-identified aggregate statistics about queries (question type, theme, language, date, whether the answer was grounded in the help catalog), kept with no conversation text, no user identifier and no IP address (the AssistantTurnEvent log); (3) security and abuse prevention — rate limiting (for anonymous use, a short-lived hashed technical key that is not stored in the conversation), protection against automated attacks (an “are-you-human” check via the Cloudflare service for anonymous use), and cost control.
19.4. Storage and retention. Conversations are stored de-identified: before writing, recognizable personal information (email addresses, phone numbers, card numbers, SIN) is automatically replaced with markers. This scrubbing is not a cure-all — names and health details are not always caught — so the records are de-identified (Law 25, art. 12), not anonymized within the meaning of art. 23; we therefore do not deny rights over them (§19.9) and also rely on short retention, access control and your own care. Retention: for anonymous visitors — 45 days; for signed-in users — up to 365 days from your last message in a conversation (renewed with each new message) and in all cases until the account is permanently deleted. On expiry, records are deleted automatically by a scheduled job. Diagnostic log. When a signed-in user asks about a diploma, for internal purposes (finding and fixing diploma-eligibility bugs) we may record a technical marker linked to your account: the type of discrepancy, a course identifier, and your question in de-identified form (no more than 200 characters) — with no reply text and no call to the AI model; such markers are kept no longer than 365 days and are deleted when the account is deleted. We may also produce an internal, aggregated summary of frequently asked themes from de-identified question text (from both anonymous and signed-in users) — themes and counts only, no identities; producing that summary involves a further processing of the de-identified text by our AI provider (§19.5) and is triggered only by authorized administration (not on ordinary page loads).
19.5. Transfer outside Quebec (Anthropic, USA) — section 17 of Law 25. To generate a reply, the text of your messages is transmitted for processing to Anthropic PBC (USA), which powers the Claude language model. The text is transmitted essentially as you typed it (only a length limit is applied); the automatic scrubbing in §19.4 applies to the copy we store and does not change what is sent to the AI provider. We do not attach account identifiers to what we send; however, your typed text itself (and, for signed-in users, your own data retrieved for your question, §19.2(b)) is transmitted, so the main safeguard on your side is not to enter unnecessary or sensitive data. Messages we detect as being about refunds, payment, personal information or account deletion are answered from a fixed internal script and are not sent to Anthropic. This is a cross-border transfer (a provider outside Quebec and Canada). Anthropic processes this data as our service provider on our behalf, under its standard commercial API terms of service and its data processing addendum (DPA), which we accept by using the service; under those terms Anthropic by default does not use API data to train its models and retains it only briefly for security and abuse-prevention purposes. Before enabling the assistant, we conducted an internal assessment of the factors of this transfer (sensitivity of the data, purposes, safeguards, the US legal regime) in accordance with section 17 of Law 25.
19.6. Access, security and erasure. Access to stored conversations is restricted to authorized administration (the super_admin role); each viewing of a raw conversation is recorded in an access audit log, and if the access cannot be logged the raw text is not shown. The conversations of different users are never combined into a single model request “about a specific person”. When your account is permanently deleted (after the recovery period), a signed-in user’s conversations and diagnostic markers are erased together with the account (Law 25, art. 14 — the right to erasure); anonymous conversations are deleted automatically on expiry. The transfer to Anthropic and the assistant’s data stores fall within the scope of our privacy-incident response process (sections 3.5–3.8 of Law 25).
19.7. Automated decisions (section 12.1 of Law 25). The assistant makes no decisions about you based exclusively on automated processing that produce legal or similarly significant effects. Personalization is a read-only display of your own data at your request; decisions on access, payment and refunds are made by a person.
19.8. Minors. The Service is intended for persons who have reached the age of majority (Terms of Service, §15); the same threshold applies to personalization and conversation storage. We do not knowingly collect minors’ data through the assistant; if we learn of such data, we will delete it.
19.9. Your rights and contact. You may request access to your stored conversations, their correction or deletion, and stop using the assistant at any time. These rights are exercised through the person responsible for the protection of personal information — Oleksii Patiutko ([email protected]); we respond within 30 days. An anonymous conversation can be identified by its conversation identifier, kept in your browser for the session; absent it, the record is in any event deleted automatically on expiry (§19.4).
20. Governing law
Data processing is carried out in accordance with the applicable laws of Canada and the province of Quebec, unless otherwise provided by the mandatory rules of the applicable law.