CourseCamp

Privacy Policy

Last updated: August 2026

1. Introduction

CourseCamp ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what personal information we collect, why we collect it, how it is used, and the rights you have over it.

This policy applies to all users of CourseCamp (app.coursecamp.com) and complies with:

  • The EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679
  • The UK GDPR and Data Protection Act 2018
  • The California Consumer Privacy Act (CCPA) / CPRA
  • The EU AI Act (Regulation (EU) 2024/1689) where applicable

2. Data Controller

CourseCamp is the data controller for personal data processed through this platform.

Contact: [email protected]

3. How you sign in

CourseCamp uses email-based accounts. There are two ways to sign in, depending on how your account was created:

  • Password account — you create an account with email and password. We also collect first name, last name, and date of birth (to confirm you are 16 or older).
  • Login-link account — an instructor invites you with a login link. We store only your email as recognisable personal data. You sign in by requesting a link sent to that email. No password, name, or date of birth is required.

4. What We Save — And What We Don't

CourseCamp only saves what is needed to operate the platform. We save three categories of data for logged-in users:

  • Your email address — for login and communications. Password accounts also store name and date of birth. Login-link accounts store email only.
  • Your quiz results and course progress — so the platform can show scores and completion. These are linked to a randomized identifier (e.g. user_89f72k) rather than your name or email.
  • Your code and run history — Playground files, packages, and a snapshot of your code each time you run it (including whether the change looked typed or pasted). Instructors of courses you joined can review this to evaluate coding exercises.

We do not track you across other sites. We do not sell or rent your data. We do not save your browsing activity outside CourseCamp, your contacts, your location history, or your device identifiers.

Anonymous Playground projects (created without signing in) are kept for 30 days and then deleted automatically. They are linked to no personal data at all.

5. Detailed Data Inventory

Data Purpose Legal Basis (GDPR) Retention
Email address Account creation, login, communications Contract (Art. 6(1)(b)) Account lifetime + 30 days after deletion
Randomized anon_id (user_xxxxxx) Link quiz results and progress to a non-identifiable ID instead of your name or email Contract (Art. 6(1)(b)) Deleted with your account
Name, date of birth Password accounts only — display name and 16+ age check Contract (Art. 6(1)(b)) Account lifetime + 30 days after deletion
Quiz results, course progress Delivering the learning service, personalisation Contract (Art. 6(1)(b)) Account lifetime + 30 days
Code, Playground projects, per-run snapshots Coding exercises, saving your work, instructor evaluation (typed vs pasted) Contract (Art. 6(1)(b)) Account lifetime + 30 days
Payment details (card, billing address) Subscription processing Contract (Art. 6(1)(b)) Held by Paddle — see their policy
IP address, browser, device info Security, fraud prevention, error monitoring Legitimate interest (Art. 6(1)(f)) 90 days
Transaction records Legal and tax compliance Legal obligation (Art. 6(1)(c)) 7 years

6. In-browser code execution

Python in the Playground runs in your browser (Pyodide / WebAssembly). Code is not sent to our servers to execute. Saving a project or running a course exercise stores files and run snapshots on our servers so you and your instructor can review them.

7. Third-Party Processors

We share your data with the following trusted third parties only to the extent necessary to provide our service. All processors are bound by appropriate data processing agreements (DPAs).

Processor Purpose Location Privacy Policy
Paddle.com Payment processing and subscription management (Merchant of Record) UK / USA View
Sentry Application error monitoring USA (EU hosting available) View
Cloudflare CDN, DDoS protection, TLS termination Global View

8. International Data Transfers

Some of our third-party processors are based outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable (e.g., UK–EU adequacy decision)
  • Data Processing Agreements with each processor

9. Your Rights

Under GDPR and similar laws, you have the following rights regarding your personal data:

Right to access Request a copy of the personal data we hold about you.
Right to rectify Ask us to correct inaccurate or incomplete data.
Right to erasure Request deletion of your personal data where there is no overriding legal reason to keep it. You can delete your account from your Profile page.
Right to portability Receive your data in a structured, machine-readable format. Use the 'Export my data' option in your Profile settings.
Right to restrict Ask us to pause processing your data in certain circumstances.
Right to object Object to processing based on legitimate interests. For marketing, you can unsubscribe at any time.
Withdraw consent Where processing is based on consent (e.g. analytics cookies), you can withdraw it at any time via our Cookie Policy.

To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK, or your national DPA in the EU).

10. CCPA Rights (California Residents)

If you are a California resident, the CCPA/CPRA grants you additional rights:

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising your rights

We do not sell or share your personal information with third parties for their own marketing purposes.

To submit a verifiable consumer request, email [email protected].

11. Cookies and Tracking

We use cookies and similar technologies. Please see our full Cookie Policy for details on what cookies we use, why, and how to manage your preferences.

12. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption in transit (TLS/HTTPS) for all data
  • Encrypted database connections
  • CSRF protection on all forms
  • Hashed passwords for password accounts (login-link accounts have no password)
  • Role-based access controls
  • Regular security monitoring via Cloudflare and Sentry

No system is 100% secure. In the event of a data breach that poses a risk to your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Art. 33–34.

13. Why we require you to be 16 or older

CourseCamp is built for adult learners and professionals. Password accounts must confirm they are at least 16 (we collect date of birth at signup). Login-link accounts are created by an instructor invitation and store email only. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has an account, contact us and we will delete it.

In jurisdictions where the minimum age for using an online service is set higher than 16 (for example under certain local data-protection laws), the higher age applies.

14. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email or via an in-app notice at least 30 days before the change takes effect. The 'Last updated' date at the top reflects the most recent revision.

15. Contact

For any privacy-related questions or requests: