Privacy
Last reviewed 29 July 2026.
Data used for course access
The service stores the normalized purchase email, Stripe customer and transaction identifiers, plan and entitlement state, subscription dates, hashed one-time access codes, revocable browser-session hashes, rate-limit records and security audit events. Raw access codes, card details and Stripe secrets are not stored in the browser or course database.
Processors
- Stripe processes checkout, billing, refunds and disputes.
- Cloudflare hosts Pages, Functions and D1.
- The configured transactional-email provider delivers one-time access codes.
Security and logs
Protected pages and downloads are authorized against D1. Normal application logs must not contain raw customer email, access codes or session tokens. Security records may contain keyed hashes of network identifiers and limited user-agent data.
Measurement
The site emits first-party funnel events. Advertising measurement is enabled only when an operator-configured client is present; this source does not embed an advertising account identifier. Browser privacy controls may limit measurement.
Requests
Use the support contact on the Stripe purchase record for an access, correction or deletion request. Financial and security records may be retained where required for fraud prevention, accounting or law.