Privacy policy.
The full thing. The TL;DR: we collect what we need to teach, nothing more.
Summary
This policy describes how Coursim, Inc. ("we", "us", "Coursim") collects, uses, discloses, and protects personal information. It applies to students, teachers, administrators, and parents using Coursim (the "Service").
Plain-English promise:: we do not sell your data. We do not use student data for advertising. We do not share student data with third parties except the subprocessors listed below, and only as necessary to deliver the Service.
Information we collect
We collect: account information (name, email, role, school affiliation); learning activity (answers, time on task, XP, streaks); device and usage metadata (browser, OS, coarse IP-derived region); and teacher-generated content (courses, lessons, comments).
We do not collect: precise geolocation, biometric identifiers, contact lists, advertising identifiers, or social-media profiles.
How we use information
We use information to: provide and personalize the Service, communicate with you about the Service, maintain security and prevent abuse, comply with legal obligations, and conduct aggregate research – strictly on de-identified data – to improve learning outcomes.
Subprocessors
We use the following subprocessors: AWS (hosting, US), Stripe (payments, US), Postmark (transactional email, US), Zendesk (support, US), and our AI model provider (LLM inference, US). A full subprocessor list naming every provider, with data categories, is available in our DPA.
Your rights
You may request access to, correction of, or deletion of personal information by emailing privacy@coursim.co. For student data, requests are routed through your school or district, which is the data controller under FERPA.
Children
Coursim is offered to schools for classroom use. School-authorized use of Coursim by students under 13 is governed by our COPPA-compliant practices; see our children's privacy notice.
International transfers
If you access Coursim from outside the United States, your information will be transferred to and processed in the United States. For EU/UK data subjects, transfers rely on Standard Contractual Clauses and supplementary safeguards; see our GDPR notice.
Changes
Material changes to this policy will be notified via email to account-holders at least 30 days before taking effect. Continued use of the Service after the effective date constitutes acceptance.
Questions about your data?
Every right granted by GDPR and CPRA is available to every Coursim user, everywhere. Access, export, delete – all self-serve.