Privacy Policy
Effective date: August 13, 2026
This Privacy Policy explains how Koursa (“Koursa,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use koursalearn.com and related services (the “Service”). By using the Service, you agree to the collection and use of information as described here.
Koursa is currently operated as an individual venture, not through a separately registered legal entity. Nothing in this Policy limits your statutory rights under the data protection law that applies to you.
1. Information We Collect
1.1 Account & profile information
- Name, email address, and password (stored as an irreversible cryptographic hash, never in plain text) — or, if you sign in with Google, your name, email address, and profile picture as provided by Google.
- Profile picture, bio, headline, website, and social media links (Twitter, LinkedIn, YouTube) — all optional and instructor-facing.
- Country, used to determine regional course pricing.
- For instructor applicants: areas of expertise, years of experience, teaching approach, and portfolio link.
- For organization inquiries: contact name, company name, company size, email, phone number, and message content.
1.2 Payment information
We never store your raw card number or bank account number ourselves. Payments are processed by Stripe, Paystack, or Flutterwave, and we only retain an opaque reference token from these providers together with non-sensitive display details (such as the card brand and last four digits). Where a payout provider’s API requires a bank account number to be supplied on each transfer, that number is encrypted at rest (AES-256-GCM) and only briefly decrypted at the moment a transfer is actually initiated.
1.3 Learning activity
Course enrolments, lesson progress and completion, quiz attempts and scores, discussion posts, course reviews, and certificates earned.
1.4 Live classes, events, and recordings
When you join a live class or event, we record your attendance (join/leave time and duration) but the audio/video stream itself is never stored on Koursa’s own servers. Course live classes may be recorded to the cloud at the instructor’s choice; those recordings live exclusively on our video-infrastructure provider’s (Daily.co) servers, are automatically and permanently deleted after 7 days, and are never copied anywhere else. Org-wide events, when recorded, are saved only to the room owner’s own device and never touch our servers at all.
1.5 Communications
When you contact support, we receive and store your message, and if you send an attachment, its metadata (our email provider retains the attachment file itself). We also send transactional email (welcome messages, receipts, course announcements, and account notifications) related to your use of the Service.
1.6 Cookies
- Session cookie — keeps you signed in. Strictly necessary for the Service to function.
- Affiliate referral cookie (
koursa_ref_{courseId}) — set only when you follow an affiliate referral link, and only for the specific course that link points to. It stores the referring affiliate’s code so that affiliate can be credited if you later purchase that course, and expires after the platform’s configured attribution window (90 days by default). It does not identify you personally and is never set if you don’t click a referral link.
We do not use third-party advertising or analytics cookies.
2. How We Use Your Information
- To create and maintain your account, and to authenticate you (including via Google Sign-In).
- To process purchases, calculate regional pricing, and pay out instructors and affiliates.
- To deliver course content, live classes, certificates, and progress tracking.
- To send transactional communications (receipts, welcome emails, course/lesson updates, security notices).
- To attribute affiliate-driven sales and calculate commissions.
- To detect and prevent fraud, abuse, and security incidents (for example, rate-limiting login attempts by IP address, and checking new passwords against known data breaches using a privacy-preserving method that never transmits your actual password).
- To comply with legal obligations, including financial record-keeping.
3. How We Share Your Information
We share information with the following categories of service providers, solely to operate the Service:
- Payment processors (Stripe, Paystack, Flutterwave) — to process purchases and instructor/affiliate payouts.
- Video infrastructure (Daily.co, Mux) — to host live classes and lesson video content.
- Email (Resend) — to send transactional email and manage our support inbox.
- File storage (Supabase) — to store profile pictures, course thumbnails, org logos, and lesson attachments you upload.
- Authentication (Google) — if you choose to sign in with Google.
- Infrastructure — rate-limiting (Upstash), hosting (Vercel), and database (Supabase Postgres) providers that process data on our behalf under their own confidentiality obligations.
We do not sell your personal information, and we do not share it with third parties for their own independent marketing purposes.
If you belong to an organization on Koursa, your organization’s administrator can see your membership, course progress, and enrolment within that organization’s workspace.
4. Data Retention
- Account and learning-activity data is retained for as long as your account is active.
- Live-class cloud recordings are automatically deleted 7 days after creation; the fact that a class occurred (title, date, duration) is retained, but the recorded video itself is not.
- Purchase and transaction records are retained as required for accounting and legal purposes, even if an account is later closed.
5. Your Rights & Choices
You can review and update most of your profile information directly within your account settings. To request correction, export, or removal of your personal data, contact us at support@koursalearn.com.
When we process a deletion request, we anonymize your identifying information (name, email, and login credentials are replaced or removed) while retaining purchase, transaction, and certificate records under the anonymized identity, as required for financial and legal record-keeping. This means a deletion request removes your personal identity from our systems, but does not erase the underlying transaction history itself.
Depending on where you live, you may have additional rights under local data protection law, including the right to access, correct, restrict, or object to certain processing of your information. Contact us using the details above to exercise these rights.
6. Data Security
We use industry-standard measures to protect your information, including encrypted connections (HTTPS), hashed passwords, encryption at rest for sensitive payout details, and access controls limiting who within Koursa can view personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Children’s Privacy
The Service is not directed at, and is not intended for use by, anyone under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
8. International Data Transfers
Koursa’s infrastructure and service providers may process and store data in countries other than your own. Where required, we rely on our providers’ own contractual and technical safeguards for cross-border data transfers.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, notify you directly.
10. Governing Law
Koursa is not yet operated through a formally registered legal entity, so a specific governing jurisdiction for this Policy has not yet been designated. This section will be updated once one is established.
11. Contact Us
Questions about this Privacy Policy can be sent to support@koursalearn.com.