Privacy Policy
Last updated: 12 September 2026
Educado builds courses for individual learners. To do that it has to know some things about you, and this page says exactly which things, where they go, and what you can do about it.
We have tried to write this so it can be read rather than merely published. If anything here is unclear, ask us and we will fix the wording.
Who we are
Educado is a service operated by Shivam Rana Digital Solution LLP ("Educado", "we", "our", or "us"), a limited liability partnership registered in India. We operate the learning platform at tryeducado.app and the Educado iOS app, and we are the data controller for the information described below.
For anything in this policy — including requests to see, export or delete your data — contact shivam@tryeducado.app.
What we collect
Your account. Your email address and a username, which is how other people on Educado see you. We do not store passwords, because there are none: you sign in either with a six-digit code sent to your email, or with your Google account. Codes are stored hashed, expire after ten minutes, and are invalidated after three incorrect attempts.
If you sign in with Google, Google confirms your email address to us and sends us the name on your Google account. We use that name only to suggest a username, which you can change before you finish signing up and at any time afterwards. We do not receive your Google password, and we do not ask Google for access to anything else — no contacts, no calendar, no files. Your Google profile picture is discarded rather than stored, because Educado draws its own avatars.
Your learner profile. Educado asks one question when you sign up: tell us about yourself — what you do, what you already know well, what you have always meant to understand, and how much time you have. You answer as much or as little of that as you like. We keep both your answer as you wrote it and a short summary generated from it. The summary is shown back to you on your profile page.
What you ask for and what you read. The goal you type when you build a course, in your own words; your answers to the questions asked before it is built; which chapters you have opened and roughly how far through you were; and your score if you take an optional end-of-module quiz.
Technical information. When you sign in we record the IP address and browser user-agent associated with that session, which is standard practice for detecting suspicious access. Our hosting providers keep short-lived operational logs.
We do not use advertising trackers, we do not build advertising profiles, and we do not sell personal data to anyone.
Why we hold it, and on what basis
- To provide the service you asked for — this covers your account, your profile, your courses and your reading position. Without them there is no product. (Legal basis: performance of a contract.)
- To keep accounts secure — sign-in codes, session records, rate limiting. (Legal basis: legitimate interests.)
- To improve how courses are generated — we look at what fails and what gets abandoned. (Legal basis: legitimate interests.)
- To send you a sign-in code when you ask for one. We do not send marketing email unless you separately opt in.
Who else sees your data
We use a small number of providers to run the service. Each receives only what it needs.
Google (Gemini API) — this one deserves particular attention, because it is the least obvious. Generating a course means sending a model the material it needs to write for you: the goal you typed, your answers to the interview, and your profile summary — which can include your profession and what you have said you already know. Chapter text is generated the same way. Your email address and your name are not sent.
Resend — delivers your sign-in email. Receives your email address and the code.
Google (Sign in with Google) — only if you choose it. This is a separate relationship from the one above: Google is not acting for us here, it is telling us who you are because you asked it to. Google knows you signed in to Educado; see Google's own privacy policy for what it does with that.
Vercel — hosts the website you are reading and our application server, and counts page views for us. The counting is aggregate and cookie-free: it records that a page was opened, from roughly where and from which link, and does not set an identifier or build a profile of you. It cannot tell us that a particular visit was a particular person.
Neon — hosts our database, where everything above is stored.
We do not use a third-party authentication vendor. Your account, your sessions and your sign-in codes all live in our own database — signing in with Google changes who vouches for your email address, not where your account is kept.
Automated content, and what that means
Courses, chapters, quizzes and recommendations are generated by a language model. Nothing here makes an automated decision that produces legal effects for you or similarly significantly affects you — the system decides what to teach you, not anything about your rights, your money or your access.
Generated material can be wrong. See our Terms for what that means in practice.
Cookies and local storage
We use two cookies, both to do with signing in. The first is a session
cookie set after you sign in, which is what keeps you signed in. The second
exists only during a Google sign-in, holds a random value for ten minutes so
that the credential Google issues cannot be reused elsewhere, and is gone as
soon as the attempt finishes. Both are httpOnly, meaning no script on the page
can read them, and both are set on this website's own domain.
They are strictly necessary to provide a service you explicitly requested, so we do not ask for consent to set them and there is no cookie banner. We set no advertising or tracking cookies. Our page-view counting sets no cookie at all, which is why there is still nothing to consent to.
The website also uses your browser's session storage to remember that you dismissed a prompt, for the length of that browsing session. Our iOS app keeps a local copy of your courses and reading position on your device so it works offline; signing out deletes it.
How long we keep things
While your account exists, we keep your profile, courses and reading history, because that is the product — Educado is meant to remember what you have learned so later courses do not repeat it.
Sign-in codes are deleted or expired within ten minutes. Sessions expire on their own and are deleted when you sign out.
If you ask us to delete your account, we will delete it and everything attached to it within 30 days. We should be straightforward about the current state of this: there is no delete button in the product yet, so this is done by emailing us. Building the self-serve version is on our list.
Backups may retain data for a short additional period before rotating out.
How we protect it
We encrypt data in transit with TLS, store it in a managed Postgres database that is not exposed to the public internet, and hash sign-in codes so a database read cannot be replayed as a login. Access to production is limited to people who need it.
Every query for your data is scoped to your account on the server, so one account cannot read another's courses, profile or reading history regardless of what a client sends.
No system is perfectly secure, and we would rather say that than imply otherwise.
Your rights
If you are in the UK, EU, or another region with comparable law, you have the right to ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. You may also complain to your local data protection authority.
If you are in India, the Digital Personal Data Protection Act 2023 gives you the right to access a summary of your data and how it is processed, to have it corrected or completed, to have it erased, to nominate another person to exercise these rights on your behalf, and to have a grievance addressed. Write to shivam@tryeducado.app and we will acknowledge promptly and respond within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.
If you are a California resident, you have the right to know what we collect, to have it deleted, and to opt out of the sale or sharing of personal information. We do not sell or share personal information, and we run no advertising or measurement trackers, so there is nothing to opt out of.
Email shivam@tryeducado.app and we will respond within one month. We will not charge you or make it difficult.
Where your data is held
Educado is operated from India, and our application server and database are hosted in Frankfurt, Germany — so your account, profile, courses and reading history are stored inside the European Economic Area.
Some of our processors operate elsewhere. Course generation sends prompts to Google's Gemini API and Anthropic's Claude API, and sign-in emails go through Resend; all three may process data in the United States. Signing in with Google involves Google in the same way, and only if you choose it. Where personal data is transferred out of the UK or EEA we rely on the safeguards those providers offer, including standard contractual clauses where applicable.
Indian law permits transfers outside India except to countries the government has specifically restricted. We do not transfer data to any such country.
Children
You must be at least 18 to create an account. Educado is not directed at children and we do not knowingly collect their personal data.
Indian law treats anyone under 18 as a child for data protection purposes, and processing a child's data requires verifiable parental consent. Setting our minimum age at 18 is how we avoid holding data we could not lawfully process.
If you believe someone under 18 has created an account, contact us and we will remove it.
Changes
If we change this policy materially we will update the date at the top and, for significant changes, tell account holders by email. We will not quietly broaden what we do with your data.