Privacy Policy

Effective September 18, 2026 · Eden Platforms LLC, hello@edeneducate.io

Privacy at a Glance

TopicSummary
Information we handleAccount and billing-status information; academy content; and, for Academies, student account, learning, discussion, and purchase data. Stripe handles card numbers.
WhyTo run the platform, deliver courses, support users, secure the service, and send service messages and Academy-directed communications.
Who receives itThe service providers listed below, acting to provide the platform. We do not sell personal data or use student data to advertise Eden to students.
AIAI quiz and support features process the content needed to provide that feature. Do not submit sensitive information to AI features.
Your choicesAcademy users can contact us about access, correction, or deletion. Students should contact their Academy first.

This is a short summary. The sections below, including the service-provider list, retention, and rights information, control if there is a difference.

1. Who This Covers

Eden Educate is a platform where training businesses (“Academies”) run branded course sites for their students. This policy covers two groups:

  • Academy users, owners and admins who subscribe to and operate the platform. For your data, Eden is the responsible party (controller).
  • Students, people who enrol and learn on an Academy’s site. Students are customers of their Academy, not of Eden. We process student data on the Academy’s behalf to run their training site (Eden acts as a service provider / processor; the Academy is the controller of its student relationships). Students with questions about how their data is used should contact their Academy first.

2. What We Collect

From Academy users: name, email, phone (optional), password (stored as a secure hash by our authentication provider), profile photo (optional), academy branding and content, subscription and billing status. Payment card details are collected and stored by Stripe, never by Eden.

From students (on behalf of their Academy): name, email, password hash, course enrollments, module progress, quiz attempts and scores, certificates earned, discussion posts, and purchase records for that Academy’s courses. Student payment cards are handled by Stripe (including saved-card upsell functionality where the student authorizes it); Eden never stores card numbers.

Automatically: authentication session cookies (required for login), and standard server logs (IP address, timestamps, requests) kept for security and reliability. Our public marketing site uses PostHog in cookieless mode: it records page views in aggregate and stores nothing in your browser, so no identifier persists between visits and there is no cross-site tracking. Inside the signed-in owner dashboard, PostHog also records which product features are used, using a first-party cookie limited to the dashboard host; it never runs on academy sites.

3. How We Use Data

To operate the platform: authenticate users, deliver courses and video, track progress, generate certificates, run quizzes, host discussions, process subscriptions, send the emails the platform exists to send (receipts, certificates, course notifications, discussion replies, marketing automations configured by the Academy, and account/security messages), prevent abuse, and provide support.

Emails students receive from the platform are sent on behalf of their Academy (for example: certificates, cross-sell offers, re-engagement reminders, and announcements the Academy composes). The Academy controls these; Eden provides the delivery machinery.

We do not sell personal data. We do not use student data to advertise Eden to students.

4. AI Features

Two features involve AI processing: AI quiz generation (course video captions/transcripts are processed to draft quiz questions) and an AI support assistant. Content sent to these features is processed by the AI providers listed below under our agreements with them; we do not permit them to use this content to train their public models. Please do not submit protected health information, payment-card data, or other sensitive information to AI features.

5. Service Providers (Subprocessors)

We use these providers to run the platform:

ProviderPurpose
SupabaseDatabase, authentication, file storage
StripeSubscription billing and student payment processing (Stripe Connect)
Amazon Web ServicesApplication hosting (United States, us-east-2)
VimeoCourse video hosting and streaming
ResendTransactional and platform email delivery
OpenAIAI quiz generation
AnthropicAI support assistant
SentryError monitoring (application errors only, not customer data)
PostHogCookieless page-view analytics on our marketing site; product analytics inside the owner dashboard
GoDaddy / DNS providersCustom domain routing (domain names only)

Data is stored and processed in the United States. If you access the platform from outside the U.S., your data is transferred to the U.S.

6. Retention

  • Active accounts: retained while the account operates.
  • When an Academy’s subscription ends: student access continues for the 45-day grace period; certificates already issued remain permanently downloadable via the links delivered at issuance. Academy data is retained for export for 30 days after the grace period ends, after which it may be deleted in the ordinary course.
  • Security logs: retained for a limited period for abuse prevention.
  • Deletion requests: honored as described in Section 7, except where retention is legally required (e.g., billing records).

7. Your Rights

Academy users may access, correct, or delete their account information by contacting us or using in-product settings. Students should direct requests to their Academy (the controller of their data); we support Academies in fulfilling them, and where the law grants students direct rights against us, we honor them.

Depending on where you live (for example, California or the UK/EU), you may have additional rights, access, deletion, correction, portability, and the right not to be discriminated against for exercising them. To exercise any right: hello@edeneducate.io.

8. Security

Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access to production data is restricted. Two-factor authentication is available to all dashboard users. No system is perfectly secure; we will notify affected users of a breach as required by law.

9. Cookies

On our marketing site we set no analytics cookies: page-view analytics there is cookieless and stores nothing in your browser. In the signed-in owner dashboard we use cookies for authentication and session security, plus one first-party analytics cookie (PostHog) limited to the dashboard host; you can opt out by enabling Do Not Track in your browser, which we honor. We do not use third-party advertising cookies. Academy sites run no analytics scripts from Eden.

10. Age

The platform and academy sites are intended for adults (18+). Professional training in this industry is adult education; we do not knowingly collect data from children. If we learn we have, we will delete it.

11. Changes

We will post updates here and, for material changes, notify Academy account emails at least 30 days in advance.

12. Contact

Eden Platforms LLC, hello@edeneducate.io