Privacy

Privacy Policy

Last updated 4 September 2026Operated by Aiydo

Written in plain language

We have written this to be read, not to be survived. It is not legal advice. If you have any question about how your data is handled, email us anytime.

The short version

  • We collect what the platform needs to work: your email, your progress, and what you write.
  • Stripe takes the payments. We never see or store your card details.
  • What you type into the AI assistant is sent to an AI provider to answer you. Keep confidential material out of it.
  • No tracking cookies, no advertising, and we never sell your data.
  • Ask us to see, export, or delete your data and we will action it within 30 days.
01

Who we are

Aiydo is an online course platform, operated by an individual (sole trader) trading under that name. In this policy, “we”, “us” and “our” mean Aiydo, and “you” means the person using the platform. You can reach us anytime at privacy@aiydo.academy.

This policy covers everything on the platform: browsing the site, creating an account, learning, taking part in discussions, and buying a course. It also covers the early-access list we ran before the courses went on sale, which is closed to new signups but which we still hold. We handle personal information under the Australian Privacy Act 1988 and the Australian Privacy Principles.

In plain terms

Aiydo is the business behind this platform, and this page covers the whole of it - not just one corner.

02

What we collect

We collect different things depending on what you do:

  • Your account - your email address, your display name, and the learning track you pick. Your email is how you sign in and how we reach you.
  • Your learning - which lessons you have finished, your quiz and exercise answers, your XP and streak, your private notes, your capstone submissions, and the certificate you are issued when you finish a course.
  • What you post - your lesson discussion posts and replies, which other learners in that lesson can see, along with any report you file about a post.
  • What you type into the AI features - your messages to the practice assistant and the capstone work you submit for feedback.
  • Your purchases - which courses you own and when you bought them. Stripe handles the payment itself and gives us back a confirmation, never your card number.
  • Your timezone and language - so that streaks, daily activity, and dates land on the right day for you, and the interface appears in your language.
  • The early-access list, if you joined it - your email, optionally your role, how you arrived (referring page and any campaign tags), and - only if you opted in - a record of the exact consent wording and when you agreed to it. The list is closed, so nothing new is being collected here; what we hold was given to us while it was open.
  • Technical diagnostics - when something breaks, an error report that can include the page you were on and your account identifier, so we can find and fix the fault.
  • An invitation, if someone invites you - when an organisation admin invites you to one of their seats, we store the email address they typed in, so the invitation can be matched to you if you sign up. We hold it whether or not you ever create an account, and we do not email you about it: the admin passes the invitation link on themselves.
  • How you found us - if you arrived through a link we published, the campaign tags on that link and the site that referred you. It is recorded once, for the first page you ever landed on, and never changed afterwards, so it tells us which post or page brought people to the course and nothing about what you did once you were here. We store the referring site, not the page's address.

Some of this is visible to someone other than you. Your discussion posts are visible to other learners in that lesson. Your certificate is verifiable by anyone holding its number - the verification page shows your display name, the course, and the date it was issued, without anyone signing in, which is what makes a certificate worth sending to an employer. And if an organisation bought your seat, its admin can see part of your progress; the section on organisations below sets out exactly which part.

We do not collect or store your payment card details, and we do not build advertising profiles about you.

In plain terms

The things the platform needs to work: who you are, what you have learnt, what you wrote, and what you own. No card numbers, no ad profiles.

03

Why we use it

We use your information to:

  • Give you access to the courses you own and remember where you got up to.
  • Run the parts of the course that need it - quizzes, streaks, certificates, discussions, and AI feedback.
  • Take payment, confirm it, and handle refunds.
  • Keep the platform safe and fair - rate limits, moderation, and fixing errors.
  • Send launch updates and news - but only if you opted in.
  • See which of the things we publish actually bring people to the course, so we know what is worth writing next.

Most of this we do because it is necessary to provide the service you asked for. Marketing emails rely on your consent, which you can withdraw at any time. We do not make any automated decisions that have a legal or similarly significant effect on you, and we never sell your information.

In plain terms

To run the course you signed up for, take payment for it, and keep it working. Marketing only if you asked.

04

Who we share it with

We share your information only with the service providers that help us run the platform, and only so they can do that job:

  • Supabase - stores your account, progress, notes, and posts (database, hosted in Australia).
  • Vercel - hosts and serves the site, and provides cookieless visit analytics.
  • Stripe - takes and processes payments, and holds the card details we never see.
  • OpenRouter - routes your messages to the AI model, both for the in-lesson practice assistant and for the written feedback on capstone submissions.
  • Anthropic - makes the model that writes the feedback on capstone submissions.
  • Google - makes the model behind the in-lesson practice assistant and the capstone coach, and one side of the workbench's model comparison.
  • OpenAI - makes the model on the other side of the workbench's model comparison.
  • Resend - sends your confirmation, account, and opted-in emails.
  • Sentry - receives error reports so we can diagnose faults.

These providers process data on our behalf under their own terms, and are not permitted to use it for their own purposes. Our database runs in Supabase's Sydney region, so your account, your progress, your notes, your posts, and your submissions are stored in Australia. Stripe, OpenRouter, Anthropic, Google, OpenAI, Sentry, and parts of Vercel operate servers outside Australia, in the United States and the European Union, so the information those services need is processed overseas. Resend, which sends your emails, processes data in Japan. We take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles. We do not sell or rent your information to anyone.

In plain terms

A short list of tools that run the database, take the payment, send the email, and answer your AI questions. The database is in Sydney; several of the others are overseas. Nobody buys your data from us.

05

If an organisation bought your seat

Some seats are paid for by an employer or a team rather than by the learner. If you joined that way - by accepting an invitation from an organisation admin - that admin can see how you are getting on, because they are the one accountable for the seat.

  • What the admin can see - which lessons you have completed and when, and the name and email address on your account. That is the whole list, and the database is what limits it: the permissions that once let an admin read quiz answers and capstone checklist ticks have been removed, so it is not a matter of our code choosing not to ask.
  • What the admin cannot see - your quiz answers, your capstone checklist, your private notes, the capstone work you submit for feedback, and what you type into the AI features. Those stay readable by you alone.

If you would rather nobody at work saw your progress, buy your own seat instead of accepting an invitation: access you buy yourself is not attached to an organisation. And if you are an admin, the email addresses you invite are personal information about people who have not agreed to anything yet - please only invite people who are expecting it.

In plain terms

An employer paying for your seat can see which lessons you finished and when. Not your quizzes, not your checklist, not your notes, not your submissions, not your AI conversations.

06

What happens to what you type into the AI

Two features send your words off the platform to generate a response: the practice assistant inside lessons, and the AI feedback on capstone submissions. When you use them, your message - along with the lesson context it belongs to - is sent to OpenRouter, which passes it to the AI model that writes the reply. Those models are made by Google, Anthropic and OpenAI, so your message reaches whichever company made the model that answers it. Which one that is depends on the feature: the in-lesson practice assistant and the capstone coach use a Google model, the written feedback on capstone submissions uses an Anthropic model, and the workbench's side-by-side comparison deliberately sends the same prompt to a Google model and an OpenAI model so you can see the difference.

We do not use anything you type to train models, and we ask our providers not to either. We cannot, however, control their systems, and no AI provider can guarantee that a prompt is never retained for abuse monitoring. Please do not paste confidential, personal, or client information into these features.

Your own capstone submissions and assistant usage counts are stored on our database so your work and your daily limit survive a page refresh.

In plain terms

Your question leaves the platform so an AI can answer it. It is not training data, but treat it like anything else you send to a third party - confidential material does not belong in it.

07

How long we keep it

We keep information only as long as it is doing a job:

  • Your account and learning data - until you ask us to delete it. Nothing removes it on a timer: closing your account in Settings is what deletes it, and it goes then rather than in some later sweep.
  • Purchase records - for seven years after the purchase, which Australian tax law requires us to keep.
  • The early-access list - until you unsubscribe or ask us to delete your entry. The list is closed to new signups, and the one-click unsubscribe link in the emails we already sent still works.
  • Invitations - an invitation to an organisation seat stays in our database after it expires. Nothing removes it on a timer, and an admin revoking it marks it dead rather than deleting it. Closing your account through Settings deletes any invitation you sent, and any invitation addressed to you, straight away; otherwise, email us if you want one removed sooner.
  • Rate-limit and error records - short-lived operational data, kept only as long as it is useful for security and debugging.

Consent records may be kept a little longer than the thing they relate to, where we need them to show that consent was given. When you delete your account, your discussion posts are anonymised rather than removed, so the threads other learners took part in still make sense.

In plain terms

As long as it is useful, then gone. Purchase records are the exception - the tax office requires seven years.

08

Your choices and rights

You are in control of your information, and the two most common requests need no email at all:

  • Export a complete copy of the data tied to your account any time, from Settings. The export downloads immediately, and it covers what we keep or de-identify as well as what we would delete - the full picture, not only the parts we would erase.
  • Close your account any time, from Settings, by typing DELETE. If you administer a team that other people have joined, closing would leave them with nobody to manage their access, so that one case isn't self-serve yet: email privacy@aiydo.academy and we will arrange it with you. If you run a team on your own, it is closed along with your account, and closing is immediate either way: your profile, progress, notes, achievements and submissions are removed with no grace period and no undo. Your purchase records stay on file for seven years, de-identified, because tax law requires it; your discussion posts stay up with your name removed, so the conversations they're part of still read clearly; and any certificates you have earned keep verifying without naming you.
  • Unsubscribe from marketing email using the one-click link in its footer, or withdraw your consent at any time.
  • Edit or delete your own discussion posts directly in the lesson.

For anything Settings doesn't cover yet - correcting information beyond what you can already edit there, or a request you would rather send by hand - email privacy@aiydo.academy from the address on your account and we will action it within 30 days. There is no charge, and you never have to justify the request. If you are in Australia and are not satisfied with our response, you can also contact the Office of the Australian Information Commissioner (OAIC).

In plain terms

Want a copy of your data, or want to close your account? Both take seconds in Settings, no email needed - unless you administer a team that other people have joined, in which case email us and we will handle it with you by hand. Anything else, email us and it is done within a month - no fee, no explanation required.

09

Cookies and analytics

We keep tracking light. We set the cookies needed to keep you signed in and to remember your language - without those the platform cannot work. Your theme choice is not a cookie at all: it lives in your browser’s local storage and is never sent to us. For analytics we use Vercel Analytics, which is cookieless and does not follow you across other sites. We do not use advertising or cross-site tracking cookies anywhere. One thing of ours does live in local storage and is sent to us: the campaign tags on the link you first arrived through, held until you create an account so we can tell which post brought you here, and then sent once. Nothing else in local storage leaves your browser.

In plain terms

Sign-in and language cookies only - your theme never leaves your browser. Privacy-friendly, cookieless analytics just to count visits. No ad tracking. One note of how you arrived, sent once if you sign up.

10

How we protect it

Your data sits in a database where every table carrying personal information is protected by row-level access controls, so one account cannot reach another's data. Payments run through Stripe, so no card details ever touch our systems. Connections are encrypted in transit. No online service can promise perfect security, but we limit what we collect, who can reach it, and how long it lives.

A small number of people who run Aiydo can reach your information, and only to do the job in front of them: answering a question you have posted, investigating a fault, handling a refund, or seeing which of the things we publish brought people to the course. That last one is read as counts per post, not as a list of who arrived from where. We do not read your private notes, and nobody outside that group has access at all.

In plain terms

Access controls on every table, no card details to lose, and everything encrypted on the way. A few of us can look at your data to answer a question or fix a fault, and not for anything else.

11

Children

Aiydo is intended for working professionals and is not directed at anyone under 16. We do not knowingly collect information from children. If you believe a child has given us their information, email us and we will delete it.

In plain terms

This is for adults at work, not kids.

12

Changes to this policy

We will update this policy as the platform grows. When we do, we will update the date at the top of this page, and where a change materially affects how we use your information we will tell you by email before it takes effect.

In plain terms

Policy changes. Anything that actually affects you gets an email first, not a silent edit.

13

Contact us

Questions about your privacy, or want to make a request? Email privacy@aiydo.academy.

Aiydo is a sole trader, ABN 79 036 984 466.

In plain terms

Reach us at the email above.