1. What this policy covers
This policy explains how we handle personal information when you visit our website, join our newsletter, use account or course features, buy a membership, or contact us. It does not govern a third-party service that has its own privacy policy.
We do not sell personal information or use it to build advertising profiles.
2. Information we collect
- Newsletter information: the email address you submit and subscription events such as signup, confirmation, delivery, and unsubscribe status.
- Account and OAuth information: if you use account features or sign in with Google or GitHub, we may receive your name, email address, profile image, provider account identifier, and authentication status. We do not receive your Google or GitHub password.
- Device-local learning data: the current site saves course-completion progress and module-view preferences in your browser's localStorage. This information remains on your device and is not sent to us. You can remove it using your browser controls. If we later offer optional account-based sync and you enable it, the synchronized progress will become account information handled under this policy.
- Support information: the contents of support requests or other communications you send us.
- Payment and transaction information: when you purchase through Stripe, we receive customer, subscription, invoice, payment-status, billing-address, and tax information needed to provide the service and keep business records. Stripe processes card details; we do not store full card numbers or card security codes.
- Technical information: hosting and security systems may record IP address, browser and device details, request paths, timestamps, referral data, and error or security logs.
3. How we use information
We use personal information to deliver newsletters and purchased services; create and secure accounts; provide an optional account-sync feature if one is offered and you enable it; process subscriptions, invoices, refunds, and tax; respond to support; operate, troubleshoot, and protect the site; understand aggregate service performance; comply with law; and establish or defend legal claims. Where required, we rely on your consent, performance of our agreement with you, legal obligations, or our legitimate interests in operating a safe and useful service.
4. Service providers and disclosure
We disclose only what is reasonably necessary to providers that help us operate the service, including:
- Railway and other hosting, infrastructure, logging, and security providers;
- Buttondown for newsletter signup and delivery;
- Stripe for checkout, billing, fraud prevention, customer-portal, and tax functions;
- Google and GitHub when you choose their OAuth sign-in services; and
- professional advisers, regulators, courts, or law-enforcement bodies when legally required.
We may also transfer information as part of a genuine business reorganisation, sale, or acquisition, subject to appropriate confidentiality and legal protections.
5. Overseas processing
Some providers operate infrastructure or support teams outside Australia, including in the United States and other countries where they or their subprocessors operate. This means personal information may be processed overseas under privacy laws that differ from Australian law. We select established providers and use their contractual and security protections where reasonably available.
6. Security
We use reasonable administrative, technical, and organisational safeguards appropriate to a small online education service. These include managed service providers, access controls, authentication protections, and operational monitoring. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security. Please contact us promptly if you believe your account or information has been compromised.
7. Retention
Our retention periods depend on the type of record and why we need it:
- Newsletter details are kept until you unsubscribe, with a limited suppression record retained as needed.
- Account records are generally kept while your account is active and for a reasonable period afterwards for restoration, support, security, and dispute handling. If optional progress sync is offered and enabled, synchronized progress follows the same retention approach. Device-local progress is controlled through your browser instead.
- Transaction, invoice, and tax records are kept for the periods required by Australian law.
- Support communications and technical logs are kept only as long as reasonably needed for the purpose collected, security, troubleshooting, or legal claims.
8. Your choices and rights
You can unsubscribe from marketing email using the link in each newsletter. You may also ask for access to, or correction of, the personal information we hold about you. You may request deletion or restriction where applicable, or object to particular processing. We may need to verify your identity and may retain information where law, fraud prevention, accounting, security, or legal claims require it.
To make a request, email us at the privacy contact below. We will respond within a reasonable time and explain if we cannot fulfil all or part of a request.
9. Complaints
If you have a privacy concern, contact us with enough detail to investigate it. We will acknowledge and review the complaint and aim to resolve it fairly. If you are not satisfied, you may contact the Office of the Australian Information Commissioner or another regulator available to you.
10. Changes to this policy
We may update this policy when our services, providers, or legal obligations change. We will publish the revised version and effective date here and provide additional notice if a change is material and notice is required.