Privacy Notice
What the academy collects, why it is used, and what happens when paid work is processed by AI.
Draft prepared July 16, 2026 · Effective date: [OPERATOR TO SET]
1. Who is responsible
[OPERATOR: INSERT FULL LEGAL BUSINESS NAME, BUSINESS FORM, MAILING ADDRESS, AND PRIVACY CONTACT ROLE] operates DigixData Learning. Privacy questions can be sent to support@digixdata.com.
2. Information we collect
- Account information: your email address, account identifier, sign-in and security records.
- Learning activity: enrollments, lesson progress, quiz results, completed work, Trust Level, and certificate records.
- Paid-tier content: artifact submissions, grading results, revision history, and Mission Control chat messages.
- Support information: messages, screenshots, and other details you choose to send us.
- Purchase records: offer, price, checkout, payment status, access, and refund identifiers. Stripe handles payment-card details; the academy does not receive or store your full card number.
- Technical and analytics information: page views, route, referrer, approximate location, browser, device, operating system, timestamps, request metadata, and security logs.
3. How we use information
We use this information to:
- authenticate you, operate your account, and save progress;
- deliver courses, downloads, paid access, grading, coaching, Trust Levels, and certificates;
- send requested sign-in links, resource deliveries, receipts, and service messages;
- answer support requests, prevent abuse, troubleshoot, and secure the academy;
- measure aggregate use and improve the learning experience;
- comply with applicable law and enforce our terms.
We do not add your sign-in email to a marketing list unless you separately choose to opt in, and we do not use authentication emails for marketing.
4. Paid-tier AI processing
Plain-language disclosure: paid-tier artifact submissions and Mission Control chat are processed by third-party AI services. For each model-inference request, the application requires OpenRouter to use a zero-data-retention endpoint and to route only to providers that do not collect user data. OpenRouter says ZDR providers cannot train on that data.
The application sends no OpenRouter tools, explicitly disables the plugins that could otherwise process learner content, and disables OpenRouter response caching for these requests. OpenRouter explains that its ZDR routing rule covers model inference, not optional plugins or tools; the operator must therefore keep account-level extensions off before launch. OpenRouter also offers a separate Broadcast observability feature that can forward prompts and completions to external destinations; this draft must not be published until the operator confirms Broadcast and Input and Output Logging are disabled for the production key. A service-specific user identifier and non-content usage metadata may accompany the request for abuse prevention and cost accounting.
Do not put passwords, API keys, payment-card data, health records, client secrets, or other sensitive personal information into a submission or chat. You can read OpenRouter’s current Zero Data Retention documentation.
5. Cookies and analytics
We use first-party cookies that are necessary to keep you signed in, refresh your session, and protect account access. Blocking those cookies may prevent sign-in or saved progress from working.
We use Vercel Web Analytics for page views and aggregate site insights. Vercel states that Web Analytics stores anonymized data, does not use cookies, and resets its visitor-identification hash after 24 hours. Do not place sensitive information in URLs because page paths can be part of an analytics event.
6. Service providers and disclosures
We use vendors to run the academy: Supabase for accounts and academy data, Vercel for hosting and analytics, OpenRouter and routed model providers for paid AI features, Stripe for checkout and refunds, and Resend for service email. They process information under their own terms and our configuration. We may also disclose information when required by law, to protect people or the service, or as part of a business transaction subject to appropriate safeguards.
We do not sell personal information.
7. Retention and security
We keep information only as long as needed for the purposes above, to maintain transaction and learning records, resolve disputes, and meet legal obligations. [OPERATOR/COUNSEL: INSERT SPECIFIC RETENTION PERIODS FOR ACCOUNT DATA, SUBMISSIONS/CHAT, SUPPORT, ANALYTICS, AND FINANCIAL RECORDS BEFORE LAUNCH.]
We use reasonable technical and organizational safeguards, but no online service can promise absolute security.
8. Your choices and requests
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, or to object to some processing. Email support from the address on your account so we can verify the request. Some records may need to be kept for security, payment, tax, or legal reasons.
For service help, see the Support page. [OPERATOR/COUNSEL: ADD REQUIRED REGION-SPECIFIC NOTICES, APPEAL RIGHTS, DATA-PROTECTION CONTACTS, AND CHILDREN’S-PRIVACY TERMS BEFORE LAUNCH.]
9. Changes
We may update this notice as the academy or the law changes. We will change the date above and provide additional notice when required.