Privacy Policy
Last updated: August 16, 2026
1. Who We Are
Tensorcraft is a browser-based machine learning course for JavaScript engineers. Tensorcraft is the data controller for everything this policy describes. For any question about this policy, or to exercise any right in section 8, email privacy@tensorcraft.app.
2. Information We Collect
Account data: your email address, display name, and avatar, from GitHub, Google, or the email address you sign up with. Onboarding also records your JavaScript background, experience level, and learning goal. An account is required to buy.
Learning data: lessons completed, exercise attempts and scores, hints used, your run of consecutive active days, the code you write in exercises and in arena challenges (timed coding challenges inside the course), and certificates you earn. A certificate page shows your display name and avatar to anyone who has its link, so share that link deliberately.
Purchase data: payment happens on Stripe, and card numbers never reach our servers. We keep the plan, amount, payment status, your billing country, a VAT or tax ID if you entered one, and the customer reference Stripe assigns you, which lets us match a payment to your account without holding card details.
Bug reports: the description you write, your email address, the page URL, your browser version, and a screenshot if you attach one.
Waitlist and newsletter: your email address and whether you asked for the weekly digest.
Technical data: your IP address, held for up to two minutes to rate-limit abusive traffic, and error reports with personal fields stripped (section 4).
3. How We Use It
Each purpose below names its legal basis under the GDPR:
- Running the course: accounts, progress, certificates (contract)
- Processing payments and keeping tax records (contract; legal obligation)
- Sending sign-in links, receipts, and the emails you opted into (contract; consent)
- Rate limiting and abuse prevention (legitimate interest)
- Error monitoring (legitimate interest)
- Product analytics, only after you accept the cookie banner (consent)
We do not sell your data.
4. Analytics & Error Monitoring
No analytics run until you choose "Accept all" on the cookie banner. With your consent: PostHog (EU servers) records pageviews and product events keyed to a random account ID, never your name or email; Plausible and Vercel Analytics count pageviews without cookies; Vercel Speed Insights measures page load times, also without cookies. Declining the banner, or ignoring it, keeps all four off. You can change your answer any time via "Cookie settings" in the footer.
Sentry, our error monitor, runs without consent so we can see crashes: our legitimate interest in a working product. Before an error report leaves your browser, Sentry strips emails, user IDs, IP addresses, and auth headers. Session recording is off.
5. Third-Party Services
Your data passes through these processors:
- Supabase: authentication, database, and file storage
- Stripe: payment processing
- Resend: sends the weekly digest and support notifications
- Kit (ConvertKit): lifecycle emails, like the welcome sequence
- Sentry: error monitoring (section 4)
- PostHog: product analytics on EU servers, consent-gated
- Plausible: cookie-free pageview analytics, consent-gated
- Vercel: web hosting, plus consent-gated pageview analytics and page speed metrics
- Fly.io: API hosting
- Upstash: rate limiting; sees your IP address for up to two minutes
- jsDelivr: backup CDN. If our bundled copy of TensorFlow.js fails to load, your browser fetches it from jsDelivr, which sees your IP address like any web request.
- GitHub: optional, only if you connect your account to push exercise code
6. Cookies & Local Storage
Cookies we set: a session cookie that keeps you signed in (essential); tc_world, which remembers the world you picked, for one year; a ten-minute security cookie during GitHub sign-in; and, only after consent, a PostHog analytics cookie.
Local storage on your device holds your cookie choice, color scheme, lesson progress, and drafts of your exercise code. That data stays in your browser until a feature you use sends it to us, like finishing a lesson while signed in.
7. International Transfers
Some of our providers, including Stripe, Vercel, Fly.io, Sentry, Resend, and Kit, process data in the United States. PostHog and Plausible stay on EU servers. Where your data leaves the EU, it moves under each provider's EU-approved safeguards: Data Privacy Framework certification or standard contractual clauses.
8. Your Rights (GDPR / CCPA)
You can:
- download everything we hold about you as JSON, from Settings
- correct your display name and avatar in Settings, or email us for anything else
- delete your account and data from Settings (section 9 lists the exceptions)
- opt out of analytics: decline the cookie banner, or change your answer under "Cookie settings" in the footer
- unsubscribe from any email via its unsubscribe link or in Settings
- withdraw consent at any time
If you are in the EU or UK, you can also lodge a complaint with your data protection authority. For anything not covered by a Settings control, email privacy@tensorcraft.app.
9. Data Retention
Your account and learning data stay while your account is active. Deleting your account removes them within 30 days, with three exceptions:
- Purchase and tax records are kept up to ten years, as tax law requires. They are unlinked from your identity: the record keeps the sale, not the person.
- Bug reports are kept as operational records, with your email, account link, and screenshot removed.
- Analytics events are keyed to a random ID and are kept in that pseudonymous form.
Waitlist and newsletter emails are separate from your account. We keep them until you unsubscribe, or for 24 months without engagement, whichever comes first.
10. Children's Privacy
Tensorcraft is not intended for users under the age of 16, and our Terms of Service require account holders to be 16 or older. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes via email. The "Last updated" date at the top reflects the most recent revision.
12. Contact
Questions about privacy? Email privacy@tensorcraft.app.