Privacy Policy
Last updated: August 2026
1. Introduction
CourseCamp ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what personal information we collect, why we collect it, how it is used, and the rights you have over it.
This policy applies to all users of CourseCamp (app.coursecamp.com) and complies with:
- The EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679
- The UK GDPR and Data Protection Act 2018
- The California Consumer Privacy Act (CCPA) / CPRA
- The EU AI Act (Regulation (EU) 2024/1689) where applicable
2. Data Controller
CourseCamp is the data controller for personal data processed through this platform.
Contact: [email protected]
3. How you sign in
CourseCamp uses email-based accounts. There are two ways to sign in, depending on how your account was created:
- Password account — you create an account with email and password. We also collect first name, last name, and date of birth (to confirm you are 16 or older).
- Login-link account — an instructor invites you with a login link. We store only your email as recognisable personal data. You sign in by requesting a link sent to that email. No password, name, or date of birth is required.
4. What We Save — And What We Don't
CourseCamp only saves what is needed to operate the platform. We save three categories of data for logged-in users:
- Your email address — for login and communications. Password accounts also store name and date of birth. Login-link accounts store email only.
- Your quiz results and course progress — so the platform can show scores and completion. These are linked to a randomized identifier (e.g. user_89f72k) rather than your name or email.
- Your code and run history — Playground files, packages, and a snapshot of your code each time you run it (including whether the change looked typed or pasted). Instructors of courses you joined can review this to evaluate coding exercises.
We do not track you across other sites. We do not sell or rent your data. We do not save your browsing activity outside CourseCamp, your contacts, your location history, or your device identifiers.
Anonymous Playground projects (created without signing in) are kept for 30 days and then deleted automatically. They are linked to no personal data at all.
5. Detailed Data Inventory
| Data | Purpose | Legal Basis (GDPR) | Retention |
|---|---|---|---|
| Email address | Account creation, login, communications | Contract (Art. 6(1)(b)) | Account lifetime + 30 days after deletion |
| Randomized anon_id (user_xxxxxx) | Link quiz results and progress to a non-identifiable ID instead of your name or email | Contract (Art. 6(1)(b)) | Deleted with your account |
| Name, date of birth | Password accounts only — display name and 16+ age check | Contract (Art. 6(1)(b)) | Account lifetime + 30 days after deletion |
| Quiz results, course progress | Delivering the learning service, personalisation | Contract (Art. 6(1)(b)) | Account lifetime + 30 days |
| Code, Playground projects, per-run snapshots | Coding exercises, saving your work, instructor evaluation (typed vs pasted) | Contract (Art. 6(1)(b)) | Account lifetime + 30 days |
| Payment details (card, billing address) | Subscription processing | Contract (Art. 6(1)(b)) | Held by Paddle — see their policy |
| IP address, browser, device info | Security, fraud prevention, error monitoring | Legitimate interest (Art. 6(1)(f)) | 90 days |
| Transaction records | Legal and tax compliance | Legal obligation (Art. 6(1)(c)) | 7 years |
6. In-browser code execution
Python in the Playground runs in your browser (Pyodide / WebAssembly). Code is not sent to our servers to execute. Saving a project or running a course exercise stores files and run snapshots on our servers so you and your instructor can review them.
7. Third-Party Processors
We share your data with the following trusted third parties only to the extent necessary to provide our service. All processors are bound by appropriate data processing agreements (DPAs).
8. International Data Transfers
Some of our third-party processors are based outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable (e.g., UK–EU adequacy decision)
- Data Processing Agreements with each processor
9. Your Rights
Under GDPR and similar laws, you have the following rights regarding your personal data:
To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK, or your national DPA in the EU).
10. CCPA Rights (California Residents)
If you are a California resident, the CCPA/CPRA grants you additional rights:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your rights
We do not sell or share your personal information with third parties for their own marketing purposes.
To submit a verifiable consumer request, email [email protected].
11. Cookies and Tracking
We use cookies and similar technologies. Please see our full Cookie Policy for details on what cookies we use, why, and how to manage your preferences.
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS) for all data
- Encrypted database connections
- CSRF protection on all forms
- Hashed passwords for password accounts (login-link accounts have no password)
- Role-based access controls
- Regular security monitoring via Cloudflare and Sentry
No system is 100% secure. In the event of a data breach that poses a risk to your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Art. 33–34.
13. Why we require you to be 16 or older
CourseCamp is built for adult learners and professionals. Password accounts must confirm they are at least 16 (we collect date of birth at signup). Login-link accounts are created by an instructor invitation and store email only. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has an account, contact us and we will delete it.
In jurisdictions where the minimum age for using an online service is set higher than 16 (for example under certain local data-protection laws), the higher age applies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email or via an in-app notice at least 30 days before the change takes effect. The 'Last updated' date at the top reflects the most recent revision.
15. Contact
For any privacy-related questions or requests:
- Email: [email protected]
- Support form: Contact Support