Privacy Policy
This policy is written from the SmartKourse codebase rather than from a template. Every provider and data element listed below is one we actually use.
Effective date: July 25, 2026Last updated: July 25, 2026
Published by SmartKourse
1. Short summary
- We collect what is needed to run accounts, sell and deliver digital courses, pay instructors, answer support requests, and keep the platform secure.
- We do not sell personal information and we do not run behavioral advertising, ad pixels, or retargeting.
- Stripe handles payment card data. We never receive or store full card numbers, and we do not even store a Stripe Customer ID against your account.
- Lesson progress is kept mostly in your own browser, not as a server-side record of what you watched.
- Traffic analytics use Vercel Analytics and Speed Insights (part of our hosting). SmartKourse does not currently write first-party per-visit analytics records to PostgreSQL.
2. Scope of this policy
This policy covers the SmartKourse website, learner and creator accounts, and the SmartKourse API. It does not cover third-party sites you reach through course links, or the independent practices of instructors who use information you provide to them directly.
3. Who is responsible
SmartKourse is responsible for the personal information described here. The operating legal entity name and registered address are pending owner configuration and will be published before public launch; until then, privacy correspondence should go through the contact form on this website.
Privacy contact: Contact form on this website (email address pending owner configuration).
4. What we collect, in detail
The table below is generated from our internal data inventory, so it stays in sync with what the application actually stores.
Account and authentication
- Data: Email address, Password hash, Account status, and Email verification state.
- Collected from: User registration and account settings.
- Used to: operate the service, security and abuse prevention, send transactional messages, and legal and tax compliance.
- Stored or shared with: our managed PostgreSQL database, Hostinger SMTP, and Resend.
- Retention: Retained while the account is active; soft-deleted on account deletion. Unverified accounts may be hard-deleted after approximately 30 days.
Account and authentication (browser-only)
- Data: HttpOnly session cookies (access + refresh), Readable CSRF cookie for double-submit protection, Non-sensitive readable session-hint cookie (sk_session_hint=1), and Optional sessionStorage display snapshot (name/email for chrome only; not auth tokens).
- Collected from: Login and session refresh.
- Used to: operate the service, and security and abuse prevention.
- Stored or shared with: no external recipients.
- Retention: HttpOnly access/refresh cookies until logout or expiry. Readable CSRF and session-hint cookies are cleared with the session. Optional display snapshot lives in sessionStorage for the tab only. Tokens are never stored in localStorage.
Profile
- Data: Display name, Avatar image URL, Bio, Timezone, Locale / language preferences, and In-app notification category preferences.
- Collected from: User profile settings, and avatar upload.
- Used to: operate the service, and send transactional messages.
- Stored or shared with: our managed PostgreSQL database, and Vercel.
- Retention: Retained with the account; soft-deleted on account deletion.
Creator / instructor
- Data: Public creator slug and profile, Headline, bio, social links, Stripe Connect account identifier, and Payout balances and trust / hold settings.
- Collected from: Creator onboarding, Stripe Connect, and admin risk tools.
- Used to: operate the service, process payments and payouts, content moderation, and legal and tax compliance.
- Stored or shared with: our managed PostgreSQL database, Stripe, and Vercel.
- Retention: Retained while the creator account exists; subject to tax and ledger retention needs.
Course content
- Data: Course titles, descriptions, curriculum, Lesson metadata and video source identifiers, Thumbnails, External resource URLs, and Access plans and discount codes.
- Collected from: Instructor uploads and listings.
- Used to: operate the service, content moderation, and legal and tax compliance.
- Stored or shared with: our managed PostgreSQL database, Vercel, YouTube, and instructors (limited).
- Retention: Retained while published or as needed for access, disputes, and legal obligations.
Purchases and billing
- Data: Purchase and subscription records, Amounts, currency, and statuses, Stripe Checkout Session, PaymentIntent, Charge, Invoice, Subscription, Refund, Dispute, Transfer, and Payout identifiers, and Discount code usage.
- Collected from: Checkout, Stripe webhooks, and admin refund workflows.
- Used to: process payments and payouts, operate the service, legal and tax compliance, and respond to support requests.
- Stored or shared with: our managed PostgreSQL database, and Stripe.
- Retention: Payment and tax-relevant records are retained as needed for accounting, disputes, and legal obligations. SmartKourse does not store full payment card numbers.
Learning activity
- Data: Last viewed lesson and completed-lesson markers (browser localStorage), and Server-side course access entitlements.
- Collected from: Learning player, and fulfillment after purchase.
- Used to: operate the service.
- Stored or shared with: our managed PostgreSQL database.
- Retention: Progress markers are primarily client-side. Access grants are retained while entitlement is valid or as needed for disputes.
Learning activity
- Data: Course ratings, Review text, Comments, and Favorites.
- Collected from: Learner interaction.
- Used to: operate the service, and content moderation.
- Stored or shared with: our managed PostgreSQL database, and instructors (limited).
- Retention: Soft-deleted with related content or account actions where implemented.
Communications
- Data: Email verification and password-reset tokens, Transactional email content, and In-app notifications.
- Collected from: Auth flows, and product events.
- Used to: send transactional messages, security and abuse prevention, and operate the service.
- Stored or shared with: our managed PostgreSQL database, Hostinger SMTP, and Resend.
- Retention: Auth tokens expire; email delivery logs depend on the configured provider.
Device, log, and first-party analytics
- Data: Locale preference cookie, Anonymous traffic metrics via Vercel Analytics / Speed Insights, Approximate request metadata used by hosting, Contact form user-agent (truncated) and hashed IP, and Admin audit log IP addresses (plaintext) for staff actions.
- Collected from: Browser, API requests, admin tools, and Vercel Analytics.
- Used to: operate the service, first-party usage analytics, security and abuse prevention, and respond to support requests.
- Stored or shared with: our managed PostgreSQL database, and Vercel.
- Retention: Locale cookie lasts about one year. Production traffic measurement uses Vercel Analytics / Speed Insights (hosting). SmartKourse does not currently write first-party per-visit analytics records to PostgreSQL.
Support and rights requests
- Data: Contact form name, email, topic, subject, message, Purchase cancel / refund request narratives, and Privacy and copyright request records (when submitted).
- Collected from: Contact and rights-request forms, and subscription cancel flows.
- Used to: respond to support requests, legal and tax compliance, and content moderation.
- Stored or shared with: our managed PostgreSQL database, Hostinger SMTP, and Resend.
- Retention: Retained as needed to resolve requests and meet legal obligations.
Security and administration
- Data: Admin audit logs (actor, action, target, before/after snapshots, reason), Creator risk / trust level and manual review settings, and Fraud rule configuration (manual; no automated scoring pipeline in code).
- Collected from: Admin console, and risk tools.
- Used to: security and abuse prevention, content moderation, legal and tax compliance, and process payments and payouts.
- Stored or shared with: our managed PostgreSQL database, and Stripe.
- Retention: Retained for security, dispute, and compliance review.
5. Where the data comes from
Most information comes directly from you: registration, profile settings, creator onboarding, course authoring, checkout, contact forms, and reviews. The rest is generated automatically as you use the service (request metadata, hosting analytics via Vercel, audit entries) or received from Stripe through webhooks confirming payment, subscription, refund, dispute, and payout events. We do not buy personal information from data brokers or enrich profiles from external sources.
6. Why we process it
- Operate the service: authenticate you, show your courses, grant and enforce access entitlements, and run creator tooling.
- Payments and payouts: take payment through Stripe, reconcile ledger entries, calculate platform fees, and transfer instructor earnings.
- Transactional communication: email verification, password reset, purchase and subscription notices, refund decisions, and policy updates.
- Security and fraud prevention: detect abuse, investigate chargeback fraud, and keep staff audit records of administrative actions.
- Moderation: review reported content, enforce the Content and Acceptable Use policies, and handle copyright notices.
- First-party / hosting analytics: understand which pages are used, primarily via Vercel Analytics and Speed Insights that ship with hosting.
- Legal and tax compliance: keep records required for accounting, disputes, and responses to lawful requests.
7. Data kept in your browser, not on our servers
Some information stays on your device. This is a deliberate design choice and it has consequences worth understanding.
- HttpOnly session cookies (access + refresh), Readable CSRF cookie for double-submit protection, Non-sensitive readable session-hint cookie (sk_session_hint=1), and Optional sessionStorage display snapshot (name/email for chrome only; not auth tokens) — HttpOnly access/refresh cookies until logout or expiry. Readable CSRF and session-hint cookies are cleared with the session. Optional display snapshot lives in sessionStorage for the tab only. Tokens are never stored in localStorage.
- Lesson progress markers, including your last viewed lesson and completed-lesson checkmarks, are held primarily in browser local storage. We do not build a server-side record of every lesson you watched.
Because of this, clearing your browser storage or switching devices can reset your visible progress. Your purchased access itself is stored server-side and is not affected.
Prefer a preference control instead of clearing everything? Use Cookie Settings below, or read the full inventory in the Cookie Policy.
Cookie Settings
SmartKourse uses essential HttpOnly session cookies and first-party operational storage only. We do not write first-party per-visit analytics records to our database. Vercel Analytics / Speed Insights (when enabled on the deployment) are separate hosting telemetry and are not controlled by this panel. See the Cookie Policy.
8. Payment data and Stripe
Card details are entered into Stripe’s hosted checkout and are processed by Stripe. SmartKourse does not receive, store, or log full card numbers, CVCs, or bank credentials. What we keep is the transaction record: amounts, currency, status, and Stripe reference identifiers for checkout sessions, payment intents, charges, invoices, subscriptions, refunds, disputes, transfers, and payouts.
We do not persist a Stripe Customer ID on your account record. Instructors who take payouts complete Stripe Connect onboarding, and the identity and tax information that process requires is collected and held by Stripe, not by us; we store the resulting Connect account identifier and payout status. On the SmartKourse creator profile we collect country only (not a street address) so we can prompt instructors about Stripe payout support for their region.
9. Service providers we actually use
Stripe, Inc.
Payment processing, Stripe Checkout, Stripe Connect payouts
- Payment card details (handled by Stripe; not stored by SmartKourse)
- Transaction amounts and statuses
- Stripe payment, subscription, invoice, refund, dispute, transfer, and Connect identifiers
- Creator identity/tax information required by Stripe Connect onboarding
Vercel Inc.
Application hosting, edge delivery, Vercel Blob object storage, and Vercel Analytics / Speed Insights
- HTTP request metadata necessary to serve the application
- Uploaded avatar and course thumbnail image files
- Anonymous traffic metrics via Vercel Analytics and Speed Insights
Prisma Postgres (or configured PostgreSQL host)
Primary application database
- Account, commerce, content, support, and operational records
Hostinger SMTP and/or Resend (configured SMTP provider)
Transactional email delivery
- Recipient email address
- Message content for verification, password reset, and operational notices
YouTube (Google)
Embedded lesson video playback (privacy-enhanced embeds where used)
- Browser interaction with the embedded player
- Video identifiers supplied by instructors
These providers act on our instructions to deliver the service. Embedded YouTube players are the one component that can set third-party storage in your browser when you interact with a video; we use privacy-enhanced embeds where available, but playback is still governed by Google’s policies.
10. What we do not use
To be explicit, the following are not present in the product today, and we will update this policy before adding any of them:
- Google OAuth (env placeholders only; not implemented in auth flows)
- Sentry or other APM
- Marketing email platforms
- Advertising / retargeting pixels
- Affiliate tracking networks
12. No sale, no targeted advertising
We do not sell personal information for money or other valuable consideration, and we do not share it for cross-context behavioral advertising. We do not knowingly collect or use sensitive personal information for inferring characteristics. There are no ad networks, retargeting pixels, or affiliate tracking scripts in the product.
13. How long we keep things
Retention is set per data type in section 4. In general: account and profile data persist while your account exists and are soft-deleted on account deletion; unverified accounts may be hard-deleted after roughly thirty days; payment, tax, and dispute records are kept as long as accounting and legal obligations require, which typically outlasts the account itself; and security and audit logs are kept for review of staff actions and incidents.
Two candid notes. First, production traffic measurement relies on Vercel Analytics / Speed Insights; SmartKourse does not currently write first-party per-visit analytics records to PostgreSQL. Second, admin audit logs store staff IP addresses in plaintext, while the contact form stores a hashed IP and a truncated user-agent string instead.
14. Security
We hash passwords, use TLS in transit, restrict administrative functions to staff accounts, keep an audit trail of administrative actions, and rely on managed providers for hosting and database infrastructure.
No online service can guarantee absolute security, and we do not claim to. Please use a unique password and tell us at Contact form on this website (email address pending owner configuration) if you suspect your account has been accessed by someone else.
15. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a portable copy of your personal information, and to be free from discrimination for exercising those rights. Regardless of where you live, we offer all users the following:
- View and edit your profile, display name, avatar, bio, and preferences.
- Request a copy of the personal information we hold about you.
- Request account deletion. Note that deleting an account ends access to purchased courses, and records we must keep for tax, dispute, and legal reasons will remain.
- Clear browser-side data yourself, including session cookies (HttpOnly access and refresh, readable CSRF and session hint), optional sessionStorage display snapshot, and lesson progress markers in localStorage.
- Ask us to correct inaccurate information, or to remove a review or comment you posted.
We do not use your data for automated decision-making that produces legal or similarly significant effects. Creator risk levels and manual-review requirements are set by staff, not by an automated scoring pipeline.
16. How to make a request
Send your request to Contact form on this website (email address pending owner configuration), or use the contact form and select the privacy topic. Tell us what you want and use the email address associated with your account so we can match the request to it. We may ask for additional verification before acting on a request involving access or deletion, and we may decline requests we cannot verify or that would compromise another person’s privacy or our legal obligations.
You may use an authorized agent where the law permits; we will ask for proof of authorization. We aim to acknowledge requests promptly and respond within the timeframe the applicable law requires. If we decline a request, we will explain why.
17. California residents
SmartKourse is based in California, and California residents use the service. Our current assessment is that SmartKourse does not meet the business thresholds that trigger the California Consumer Privacy Act as amended by the CPRA, so we do not represent that the CCPA applies to us today. That determination is documented internally and is revisited as the business grows.
Independent of that threshold question, we voluntarily extend the substance of those rights — access, deletion, correction, portability, and non-discrimination — to every user, and we do not sell or share personal information for cross-context behavioral advertising. The California Privacy Notice explains the distinction between what we do as a baseline practice and what would change if the statute became applicable.
18. Children and teens
Accounts require a minimum age of 13. Users under 18 should have a parent or guardian involved in account creation and any purchase. We do not knowingly collect personal information from children below the minimum age. If you are a parent or guardian and believe your child has provided information to us, contact Contact form on this website (email address pending owner configuration) and we will delete it.
19. International users and transfers
The service is operated from the United States, and our hosting, database, email, payment, and video providers may process data in the United States and other countries. If you use SmartKourse from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection law differs from your own. Appropriate transfer mechanisms and processor agreements are part of the pending counsel review.
20. Incident notification
We maintain an internal data-breach response plan. If a security incident affects your personal information in a way that requires notification, we will notify affected users and regulators as applicable law requires, describing what happened and what steps to take.
21. Changes to this policy
We will update this policy when our practices change — including before we add any provider currently listed in section 10. Material changes will be announced by email or in-app notice, and the “Last updated” date at the top will change.
22. Contact
Privacy questions and requests: Contact form on this website (email address pending owner configuration). General support: Contact form on this website (email address pending owner configuration). You may also use the contact form.