AI Academy Privacy Policy

Last updated: April 2026

1. Introduction

AI Academy ("we," "us," or "our") operates the website learnwithaiacademy.com. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website and services. By accessing or using our website, you agree to the terms of this Privacy Policy.

2. Information We Collect

We collect the following categories of personal information:

Account Information: When you create an account, we collect your email address and password (stored as a bcrypt hash with 12 rounds of salting). You may optionally provide your name. If you register or log in via a social provider (such as Google or GitHub), we store your provider type and provider ID. We do not receive or store your social account password.

Payment Information: We do not directly collect or store credit card numbers or payment details. All payments are processed securely by Stripe. We store your Stripe customer ID and records of your purchases, including the course purchased, Stripe session ID, Stripe product ID, and timestamp of the transaction.

Course Progress: We track which lessons you have completed within each course. This data is stored on our servers and cached locally in your browser using localStorage.

Usage Data: We use the Meta Pixel (Facebook Pixel) to collect anonymized usage data including page views and purchase conversion events. This data is used for advertising measurement and optimization.

3. How We Use Your Information

We use your personal information for the following purposes:

  • To create and manage your account
  • To process your course purchases via Stripe
  • To provide access to purchased courses and track your learning progress
  • To measure the effectiveness of our advertising campaigns via the Meta Pixel
  • To communicate with you about your account or purchases when necessary
  • To detect and prevent fraud, abuse, or security incidents
  • To comply with legal obligations

We do not sell, rent, or trade your personal information to third parties.

4. Cookies and Local Storage

Our website uses the following cookies and browser storage:

Authentication Cookie: We set one httpOnly cookie called "auth_token" containing a JSON Web Token (JWT). This cookie expires after 7 days, is transmitted securely in production (Secure flag), and uses the SameSite=Lax attribute. This cookie is essential for keeping you logged in and cannot be disabled.

Local Storage: We use localStorage to cache your course progress locally in your browser under keys formatted as "progress:{courseId}". This improves performance so your progress loads instantly.

Session Storage: We use sessionStorage to store a temporary flag that prevents the Meta Pixel purchase event from firing more than once per transaction. This data is cleared when you close your browser tab.

We do not use any other cookies, including third-party advertising cookies or Google Analytics.

5. Meta Pixel (Facebook Pixel)

We use the Meta Pixel, a tracking technology provided by Meta Platforms, Inc., to measure the effectiveness of our advertising on Facebook and Instagram. The Meta Pixel collects the following data:

  • PageView events on all pages of our website
  • Purchase conversion events on our order confirmation page (including purchase value and currency)

This data is sent to Meta and may be used by Meta in accordance with their own data and privacy policies. The data collected by the Meta Pixel may include your IP address, browser type, and browsing behavior on our site.

To opt out of Meta Pixel tracking, you can:

  • Use a browser extension that blocks tracking scripts (such as uBlock Origin)
  • Adjust your ad preferences in your Facebook account settings at https://www.facebook.com/adpreferences
  • Enable "Do Not Track" in your browser settings
  • Use browser privacy/incognito mode

6. Third-Party Services

We share data with the following third-party service providers:

Stripe (stripe.com): Processes all payments. Stripe receives your payment card details, email address, and transaction information. Stripe's privacy policy governs their handling of your data: https://stripe.com/privacy

Meta Platforms (facebook.com): Receives anonymized browsing and conversion data through the Meta Pixel as described in Section 5. Meta's privacy policy: https://www.facebook.com/privacy/policy

Unsplash (unsplash.com): We use Unsplash to host course imagery. Unsplash may collect usage data through their CDN. Unsplash's privacy policy: https://unsplash.com/privacy

7. Data Security

We implement reasonable security measures to protect your personal information, including:

  • Password hashing using bcrypt with 12 rounds of salting
  • HTTPS encryption for all data in transit
  • HttpOnly and Secure cookie flags for authentication tokens
  • Rate limiting on login and registration endpoints (10 registration attempts and 20 login attempts per IP address per 15-minute window)
  • CORS restrictions limiting which domains can make requests to our servers
  • Separate authentication middleware for administrative routes

While we strive to protect your information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your data.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with our services. Specifically:

  • Account information is retained until you request account deletion
  • Purchase records are retained indefinitely for legal and accounting purposes
  • Course progress data is retained for the lifetime of your account
  • Authentication tokens expire after 7 days and are not stored on our servers

9. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Right to access the personal information we hold about you
  • Right to correct inaccurate personal information
  • Right to request deletion of your personal information
  • Right to object to or restrict processing of your personal information
  • Right to data portability

We do not currently offer an automated account deletion process. To exercise any of these rights, please reach out to us through the website. We will respond to your request within 30 days.

10. International Users

Our services are operated from Australia. If you are accessing our website from the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, please note that your information may be transferred to and processed in Australia and other countries where our service providers operate.

For users in the EEA and UK: Our legal basis for processing your personal information is (a) the performance of our contract with you (account management, course delivery, payment processing), (b) our legitimate interests (advertising measurement, security), and (c) your consent where required (Meta Pixel tracking).

For users in California: Under the California Consumer Privacy Act (CCPA), you have the right to know what personal information we collect, request deletion of your information, and opt out of the sale of your information. We do not sell your personal information.

11. Children's Privacy

Our services are not directed to children under the age of 13 (or 16 for users in the European Economic Area). We do not knowingly collect personal information from children under these ages. If we discover that we have collected personal information from a child under the applicable age, we will delete that information promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the "Last updated" date at the top of this page. Your continued use of our website after any changes indicates your acceptance of the updated policy.