Privacy Policy
Last updated: 2026-08-08
1. Who we are
learnfeed ("we", "us") is a platform that lets independent instructors and teaching centers ("academies") run their own online academy: student enrollment, attendance, manual payment tracking, quizzes, session recordings, and certificates. The data controller for this website and for academy (instructor) accounts is: Abdelrahman Elsharkawi, UNI Campus H3.01.12, 66123 Saarbrücken, Germany — learnfeed.support@gmail.com. See also our Impressum at /impressum.
2. The two roles we play (important)
For instructor accounts and this marketing site, we are the data controller. For student data inside an academy (names, emails, phone numbers, attendance, quiz results, manually recorded payments, certificates), the academy is the data controllerand we process that data on the academy's behalf as a processor under Art. 28 GDPR. Students should direct privacy requests about their course data to their academy first; we support academies in fulfilling them.
3. What we process
- Instructor account data — name, email, password (hashed by our auth provider), academy name, branding, billing status.
- Student data (processed for academies) — name, email, phone (optional), cohort membership, attendance, quiz attempts and scores, submitted coursework (the text and any links a student submits for a task), manually recorded payment entries (amount, method, status — never card numbers), issued certificates.
- Billing data — platform subscriptions (what an academy pays to learnfeed) are paid by direct bank or wallet transfer and confirmed manually by us; there is no live card or payment-processor checkout. For each payment request we store the plan, the billing term (3, 6, or 12 months), the amount and currency, a short payment reference you quote in your transfer (e.g. LF-7K3M2A), the request status (pending, confirmed, or rejected), an optional transfer receipt you upload, and who confirmed the payment and when. We never see or store card numbers, bank or wallet credentials, or payment-processor tokens.
- Technical data — server logs (IP address, timestamps, requested URLs) for security and abuse prevention, e.g. rate limiting.
4. Legal bases
- Performance of a contract (Art. 6(1)(b) GDPR) — providing the platform, billing, support.
- Legitimate interests (Art. 6(1)(f) GDPR) — securing the service, preventing abuse and fraud.
- Legal obligations (Art. 6(1)(c) GDPR) — tax and commercial record-keeping.
Academies are responsible for having a lawful basis for the student data they enter or collect through their academy pages, including where students are minors (parental consent where required by local law).
5. Cookies
We use only strictly necessary cookies: authentication/session cookies and a language preference. We do not use advertising or third-party analytics cookies, which is why you don't see a cookie consent banner.
6. Processors and recipients
We use the following service providers (processors) to run the platform:
- Supabase — database, authentication, and file storage (including transfer receipts).
- Cloudflare (R2) — storage for uploaded session recordings and other large media. Files are served through short-lived signed links rather than a public URL.
- Vercel — application hosting and content delivery.
- Resend — transactional email (invites, password resets).
- Upstash — rate limiting (short-lived technical keys).
- Vercel AI Gateway— routes our AI requests to the model provider that serves them (currently including Google, OpenAI, Anthropic and Moonshot AI), where an academy uses an AI feature. Which providers may receive an academy's content depends on a setting the academy controls. See section 7.
Where instructors publish session recordings, videos are embedded from YouTube or Google Drive; opening such a page transmits your IP address to Google. Some providers process data outside the EU/EEA; transfers rely on EU Standard Contractual Clauses or an adequacy decision.
7. AI features (Hudhud, draft feedback, generated content)
Several features send text to an AI model: the assistant (Hudhud), draft grades and comments on submitted coursework, quiz generation from your own materials, session summaries, and generated page copy. These run only when someone in the academy actively uses them — nothing is sent in the background.
What we send.Depending on the feature: course, cohort and session titles, task titles and instructions, the student's name, the coursework a student submitted (its text and any link), the text of materials the academy uploaded, and the instructor's own message to the assistant. We do not send student email addresses, phone numbers, payment records, transfer receipts, or data belonging to any other academy.
Who receives it.Requests go through the Vercel AI Gateway, which forwards them to a model provider. Each academy chooses between two routes in Settings → Data & privacy:
- "Use our strongest models" (on by default) — we route to the strongest and most cost-effective models available. Some of these providers reserve the right, under their own published terms, to retain submitted content and use it to improve or train their models. We have no contractual control over that, which is why this page names it plainly rather than burying it.
- Switched off — we route only to a restricted list of providers whose published policy is that submitted content is not used for training. These endpoints cost us several times more per request, so an academy on this setting uses up its monthly AI allowance faster; the price of the plan does not change. We additionally mark these requests as requiring no training on prompt data and zero data retention. That marking is now enforced by refusal: if no provider meeting both conditions can serve the request, it fails rather than being routed to one that does not.
The limit of what we can promise.In both modes we are relying on providers' published policies and on the Gateway's routing. We can choose which providers may receive your content and we do; we cannot audit what they do with it once received. An academy that does not want its students' coursework processed by a third-party model at all should not use the AI features — that remains the only complete answer, and it costs nothing else in the product.
Human review. Generated feedback is stored as a draftfor the instructor to review, edit, or discard; by default nothing generated this way reaches the student until a human approves it. An academy can switch on automatic publishing, in which case the generated grade and comment are released to the student without prior review — that is the academy's decision as controller, and students can ask their academy for a human review of any grade.
8. Certificate verification
When an academy issues a certificate, its verification page (reachable via the certificate's link or code) shows the student's name, the course, and the issue date so third parties can verify authenticity. Academies can revoke certificates, which disables verification.
9. Public student profiles
An academy can enable public student profiles. When it does, each student may separately choose to publish a page at {academy}.learnfeed.app/{their-slug}. Nothing is published until the student turns it on themselves, and every section of it is a separate choice.
What a published page can show, each behind its own switch the student controls: their name and the academy's name and logo, a photo they upload, a short bio, links they add (with contact links such as WhatsApp and email behind an additional switch of their own), certificates the academy has issued them, skills, and the courses they have taken. It never shows an email address, phone number, grade, submitted coursework, attendance, or payment information.
The page is public: it can be read by anyone with the link and by search engines. A student can turn any section off, or take the whole page down, at any time from their portal — and an academy turning the feature off takes every profile in it offline immediately, including ones students had already published. Removing a photo deletes the stored file, not just the reference to it.
10. Retention
Account and academy data are kept for as long as the account exists. Academies can export their data (CSV) at any time and can edit or delete student records. When an account is deleted, associated data is deleted except where statutory retention duties (e.g. invoices under German tax law: up to 10 years) require keeping it. Technical logs are kept only as long as needed for security.
11. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests. You can also lodge a complaint with a supervisory authority — in Germany, the data protection authority of your federal state. To exercise your rights, contact us via the details in the Impressum. If your request concerns your data inside a specific academy, we may refer you to that academy as the controller, and we will assist them in responding.
12. Changes
We will update this policy as the product evolves and note the date above. Material changes will be announced to account holders by email or in-app notice.