Resources

Privacy Policy

A plain-language description of what this platform stores about you, who can see it, and why.

Last updated 4 September 2026

What we store

Account information: your name, email address and password (stored only as a secure hash, never in plain text). You may add optional profile details such as date of birth, mobile number, profession and organization; these are always editable from My Profile.

Employment details, when your organization uses the training-operations features: department, job role, location, employee id, hire date, your manager and, if you leave, a termination date. These are entered by an administrator or imported from your employer’s HR system; you can see them on your transcript but only an administrator can change them.

Learning records: the courses you enroll in and why (your own choice, an administrator, or a training assignment), per-unit progress and scores, time spent learning, activity statements reported by course content (xAPI), quiz attempts with your answers and results, and certificates you earn with a verification code.

Training obligations: for each training assigned to you, a record of when it was assigned, its due date, its state (assigned, in progress, completed, exempt or cancelled), completion date, reminders and nudges sent, and any exemption request with its reason, evidence link and decision.

Content you write: course reviews and ratings, instructor replies, and (for instructors) the courses, questions and quizzes you author.

Notifications: the in-app inbox messages sent to you and whether you have read them. Nothing you type into the AI tutor is stored beyond the conversation shown to you.

Operational records: an audit log of administrative actions (who changed what, when, from which address), and a request log for calls made with API keys, from the API console or from the public playground sandbox, holding the method, path, status, duration and IP address. Login and password-reset codes are stored hashed and expire within minutes.

Who can see what

Access follows role-based permissions; nobody sees more than their role allows. You can always see your own profile, progress, certificates, training plan, transcript and notifications.

Instructors see the progress, quiz results and reviews of learners in their own courses. Content reviewers see courses submitted for approval.

Your manager (and anyone they delegate to for a period) sees your training compliance: which assignments are open, due or overdue, your course progress and completions. Managers never see your quiz answers or the text of reviews you write.

Training managers and administrators see organization-wide compliance, transcripts, assignments and exemptions. Auditors have read-only access to the same, plus audit and request logs. Super administrators can see everything on the installation.

Your leaderboard rank and points are visible to other learners unless you hide yourself under My Profile; administrators can also hide accounts. Depending on settings, other learners may see only your initials.

Reviews you publish are visible to everyone who can open the course, together with your name; administrators can moderate or hide them.

How it is used

Your data exists to run the platform: resuming courses where you left off, grading quizzes, computing progress and issuing certificates, evaluating training assignments and sending their reminders, and giving instructors, managers and administrators the reporting their roles permit.

Reminders, escalations, nudges and decisions on exemptions are delivered to your in-app inbox and, when the installation has email delivery configured and the administrator has enabled it, by email to your account address.

The AI tutor and AI question drafting send your question or the course outline to an AI service to generate a response. AI features can be switched off by the administrator, in which case nothing is sent.

Anonymous usage statistics are not collected and no data is sold or shared with advertisers.

Certificate verification

Each certificate has a public verification page reachable by its unique link. It shows the certificate’s validity (including revocation or expiry), the holder’s name and the course title, so employers and institutions can confirm authenticity. Only someone with the link can view it.

API keys, integrations and the public playground

Administrators may create API keys so other systems (for example an HR system or a reporting tool) can read or write data on their behalf. A key can never do more than the administrator who created it, is limited to the scopes chosen at creation, and every request made with it is logged and can be reviewed and revoked.

The public Developer Playground lets visitors try the API. Without credentials they can only reach public endpoints. If your organization enables a sandbox, visitors receive a short-lived, read-only session as a designated demo account; no real learner’s data is exposed through it. Sandbox requests are logged with the visitor’s IP address.

Cookies and browser storage

The platform sets one essential cookie: a secure, httpOnly refresh token that keeps you signed in. There are no advertising or third-party tracking cookies.

Some pages keep small conveniences in your browser’s local storage: the API console’s request history and any API key you paste into it, and the public playground’s recent requests. These never leave your browser and you can clear them with your browser’s site data.

Retention

Learning and training records are kept for as long as your account exists so that completions, certificates and compliance history remain provable. Deactivating an account (for example when you leave an organization) preserves its history but ends its access; open training assignments are cancelled.

Audit and API request logs are retained for operational and compliance review. Sandbox sessions expire after fifteen minutes; sign-in tokens after fifteen minutes with a refresh cookie valid for up to thirty days.

Your choices

You can edit your profile details, opt out of the leaderboard and manage your reviews at any time from the learner portal. For account deactivation, corrections to employment details, data questions or a copy of your records beyond the transcript download, contact your organization’s platform administrator, who manages accounts on this installation. If a support email is configured, it appears on the sign-in page.