We use essential account and service data to operate LearnAI Studio. We do not sell personal data or use advertising trackers.
1. Who we are
LearnAI Studio is operated by Digital Creative Academy LLC, established in Switzerland. We are the controller for personal data processed to provide the Service. Our registered address is available on request. We process personal data under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR, UK GDPR, and UK Data Protection Act 2018.
Contact: learning-support@digital-creative-academy.com
Where an employer or other organisation assigns learning and determines how learner information is used, that organisation may also act as a controller. Contact your organisation for questions about its own use of your learning records.
2. What data we collect
We collect the following personal data when you register and use the Service:
- Account data: your display name, username, and email address
- Authentication data: a securely hashed version of your password (we never store your password in plain text)
- Content data: the source materials, microlearning content, and settings you create within the platform
- Learning and collaboration data: assignments, pathway and section progress, completion status, scores, ratings, time spent, due dates, comments, reviews, group membership, invitations, and reminder history
- Usage and security data: projects created, content generated, features used, login and activity timestamps, and security or diagnostic logs
- Payment data: processed securely by Stripe — we do not store card details
- Technical data: IP address, browser and device information, request metadata, and essential cookie or browser-storage identifiers used to deliver and secure the Service
3. How we use your data
We use your personal data to:
- Provide and maintain your account and the Service
- Send transactional emails such as account verification and password reset codes
- Enable team workspaces, collaboration, reviews, public Library publication, assignments, reminders, learner progress, certificates, and administrator reports or exports
- Generate and improve content when you request AI features, and record whether content was AI-generated or AI-assisted
- Improve the Service through aggregated, anonymised usage analysis
We do not sell your personal data to third parties and do not use it for advertising purposes.
4. Legal basis for processing
Where GDPR or UK GDPR applies, we rely on:
- Contract: processing necessary to provide the Service you signed up for (account management, content delivery, billing)
- Legitimate interests: service security, fraud prevention, support, debugging, product improvement, collaboration, and proportionate learning administration, balanced against your rights
- Legal obligation: where we are required to retain records for tax, legal, or regulatory purposes
- Consent: where we specifically request it for an optional activity and consent is the appropriate legal basis; you may withdraw it prospectively
We do not use learner scores or AI features to make solely automated decisions producing legal or similarly significant effects. Automated moderation may flag content for review or restrict publication; contact us if you believe a decision is incorrect.
5. Data security
We take the security of your data seriously:
- Passwords are hashed using bcrypt (cost factor 12) — your actual password is never stored or readable
- Authentication tokens are signed JWTs with a 30-day expiry
- Verification codes are hashed before storage. Email-verification codes expire after 30 minutes; password-reset codes expire after 10 minutes
- All data in transit is protected by HTTPS/TLS
6. Third-party processors
To provide the Service, we share data with the following processors:
- OpenAI — for content generation, moderation, feedback, translations, and podcast audio. Relevant prompts, source material, course content, and generated output are processed. We do not intentionally append account profile fields, but material you submit may itself contain personal data. API data may be retained for limited abuse monitoring where applicable under our provider configuration and terms. See OpenAI's Privacy Policy
- Perplexity — for research and video discovery. Topic, objective, or search queries may be processed; do not include personal or confidential data unless authorised. See Perplexity's Privacy Policy
- Pexels — for stock image sourcing. Image search terms are sent to retrieve suitable media
- Stripe — for payment processing. We do not store your card details; all payment data is handled by Stripe directly. See Stripe's Privacy Policy
- Google Workspace — for transactional email, including verification, password reset, invitations, billing notices, and learning reminders
- Render — for application hosting and managed database infrastructure
- Cloudflare — for DNS, CDN, DDoS protection, traffic delivery, and R2 object storage used for generated audio and related files
Each processor is bound by their own data processing terms. We recommend reviewing their privacy policies if you have concerns about specific data types.
7. International data transfers
Because we and our processors operate internationally, personal data may be processed in Switzerland, the United Kingdom, the European Economic Area, the United States, or other locations where a provider operates. Where required, we use recognised safeguards such as an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, and the Swiss data-transfer clauses, together with supplementary security measures where appropriate.
8. Team, administrator, and public visibility
If you join a Team workspace or receive assigned learning, authorised owners, administrators, assigners, and relevant content owners may see your name, username, email, group membership, assignments, due dates, progress, completion, scores, ratings, time spent, comments, and recent activity. They may export relevant learning records to CSV and send reminders. Access is limited by workspace role and content relationship.
If a creator publishes a lesson to the public Library, its title, description, category, tags, cover image, language versions, content preview, and AI provenance may be visible to Library users. Learner enrolment and progress are not public. Creators can remove their lesson from the Library or revoke its public link.
9. Data retention
We keep personal data only as long as needed for the purposes above, legal obligations, disputes, security, and service operation. Current operational periods are:
Our platform runs automated daily maintenance to manage content and protect storage. The following automated actions apply to your content:
- Unverified accounts: removed after 48 hours if email verification is not completed
- Verification and reset codes: removed after expiry; verification codes last 30 minutes and reset codes 10 minutes
- Sessions: authentication tokens expire after 30 days and can be revoked earlier
- Learning event analytics: detailed event records are retained for 90 days; current assignment, progress, completion, score, rating, and certificate records remain while the account, assignment, or workspace requires them
- Draft projects: Projects left in draft status for more than 90 days are automatically archived. Archived projects remain in your account but are no longer listed in your active workspace.
- Deleted content (trash): Content you move to trash is permanently purged after 30 days with no recovery possible.
- SCORM exports: We retain a maximum of 3 SCORM export files per project. Older exports beyond this limit are automatically removed.
- Inactive free accounts: accounts without paid access or recent activity for approximately 14 months may be scheduled for deletion after at least 30 days' email warning
- Invitations, comments, and reviews: retained while needed for the relevant workspace, content, or account, then deleted or anonymised when no longer required
- Billing records: retained for the period required by tax, accounting, fraud-prevention, and other applicable laws
When you delete your account, personal resources are deleted unless shared or Team resources must remain with the workspace or transfer to an authorised owner. Provider backups are isolated from normal use and removed according to provider backup-rotation schedules. AI processors may retain API inputs for limited security or abuse-monitoring periods where applicable under their terms.
10. Your rights
Depending on the law that applies, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict processing in certain circumstances
- Data portability (receive your data in a machine-readable format)
- Withdraw consent where processing relies on consent
- Complain to a competent data-protection authority
To exercise any of these rights, contact us at learning-support@digital-creative-academy.com.
You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC). If EU GDPR or UK GDPR applies, you may also complain to the supervisory authority in your country, including the UK Information Commissioner's Office (ICO) where relevant.
11. Cookies and browser storage
We use a strictly necessary HttpOnly session cookie to maintain login securely. We also use limited local or session storage for interface preferences, notification state, and in-progress outline data. We do not use advertising cookies or third-party behavioural analytics cookies.
12. Children
The Service is intended for users aged 16 or over. Organisations assigning learning are responsible for confirming they have an appropriate legal basis and any required authorisation for younger users.
13. Changes to this policy
We may update this Privacy Policy for legal, security, operational, or product reasons. We will notify registered users of material changes where required and publish the updated date on this page.
14. Contact us
Digital Creative Academy LLC, Switzerland. Registered address available on request. For privacy enquiries or rights requests, contact learning-support@digital-creative-academy.com.