1. Information We Collect
When you use Course Foundry, we may collect the following information:
- Account information: email address, name, and profile details when you create an account.
- Waitlist information: email address when you join our waitlist.
- Usage data: information about how you interact with our platform, collected via Vercel Analytics.
- Content: course materials and files you create within the platform.
2. How We Use Your Information
- To provide, maintain, and improve our services.
- To send you updates about our platform (you can opt out at any time).
- To process AI-assisted features using third-party AI providers (Anthropic).
- To analyse usage patterns and improve the user experience.
3. Data Storage and Security
Your data is stored securely using Supabase (PostgreSQL) with row-level security enabled. We use industry-standard encryption for data in transit (HTTPS) and authentication tokens.
4. Third-Party Services (Sub-processors)
We use the following third-party services to operate the platform. A complete sub-processor list with transfer mechanisms is available on our Trust page.
- Supabase (USA) — authentication and database hosting.
- Vercel (USA + Edge Network) — application hosting and analytics.
- Anthropic (USA) — AI Forge features. Anthropic's commercial API terms prohibit training on your data.
- GitHub (USA) — version control and course publishing via GitHub Pages (customer-owned repositories).
- Stripe (USA) — payment processing. CourseFoundry never stores card details.
- Resend (USA) — transactional email delivery.
- Zotero (USA) — reference library sync, only when you enable the Zotero integration.
5. Your Rights
Under GDPR and applicable data protection law, you have the right to:
- Access & portability (Art. 15, 20): Download all your data from Settings → Export My Data.
- Erasure (Art. 17): Delete your account in Settings. All data is permanently removed within 30 days.
- Rectification (Art. 16): Update your profile in Settings at any time.
Enterprise customers can request a signed Data Processing Agreement (DPA). See our DPA template.