Privacy Policy

Last updated: 20 September 2026

1. Data Controller

The data controller for this Service is Digital Creative Academy LLC, registered in Switzerland ("we", "us", "our"), operating the Kora platform. For any privacy-related inquiries, contact us at learning-support@digital-creative-academy.com.

This policy explains how we handle personal information. Where separate consent is required, we will request it specifically.

2. Information We Collect

We collect the following information:

  • Account data: Name, email address, and authentication information when you create an account.
  • Payment data: Processed securely by Stripe. We do not receive your full card details. We store your Stripe purchase references, plan, subscription status, access dates, and records needed to manage billing and prevent duplicate processing.
  • Learning progress: Module completion status and session duration, a short AI-generated session summary, concept mastery indicators, Practice activity, and assessment results are stored on our servers to track and personalise your progress. Raw session transcripts and personal notes are not stored on our servers.
  • Content submitted for AI processing: Live speech and transcript fragments, recent transcript excerpts used to create a session summary, Practice answers or code, chat messages, and prompts used to create custom programmes may be sent to Google Vertex AI or the Gemini API. AI code review processes code as text. Separately, choosing Run for supported Practice languages executes code locally in your browser, not on Kora's servers.
  • Custom programmes: The topic, learning challenge, and generated programme are stored. Programmes are automatically considered for the shared catalogue and may become available to other Kora users after review. Do not include confidential information or unnecessary personal details in a programme request; automated review does not guarantee removal of identifying content.
  • Voice audio: During live sessions, your microphone audio passes through our relay to Google Vertex AI for AI facilitation. Our deployment configuration specifies European hosting and a supported European Vertex endpoint. Kora processes audio transiently and does not keep audio recordings. Provider handling is described below.
  • Service and security data: IP addresses, request information, usage counters, and diagnostic information help protect accounts, apply service limits, prevent abuse, and investigate errors. These records are not necessarily anonymous.
  • Contact messages: Information you provide when contacting us through our form.

3. Data Stored Only in Your Browser

Raw session transcripts and personal notes are personal data stored persistently only in your browser's local storage. Voice and transcript fragments pass transiently through the relay during a live session but are not stored there. A short AI-generated summary and learning indicators derived during the session are stored on our servers. Recent excerpts are sent to Gemini to create the short summary, but the raw transcript is not retained in our server database. You can delete local transcripts or notes with their in-app clear controls or by clearing your browser data. Successful account deletion also clears Kora transcripts and notes in the browser used for that request, but cannot clear other devices or downloaded copies. Clear local data on shared devices. Provider processing of submitted excerpts is separate from storage in Kora's database.

4. Legal Basis for Processing

We handle personal data under applicable Swiss law and, where applicable, EU or UK GDPR. The legal basis depends on the processing purpose:

  • Contract performance: Processing your account data, payment data, learning content, AI submissions, and learning progress as necessary to provide requested features and manage your purchases.
  • Legitimate interests: Protecting accounts, preventing abuse, providing support, and improving service reliability, subject to your rights and interests.
  • Legal obligations: Keeping required financial records and responding to valid legal and privacy requests.
  • Consent: Where applicable law requires consent for optional processing, it must be informed and specific. Starting a session or granting microphone permission enables the voice feature; it is not consent to unrelated uses of your information.

Avoid unnecessary sensitive information and personal details about others. Where GDPR Article 9 applies to special-category information, such as health data, an additional permitted condition is required; contractual necessity alone is not sufficient. You can stop further microphone input by muting or ending a session and contact us to withdraw consent where we rely on it, without affecting prior lawful processing.

5. How We Use Your Data

  • To provide and improve the Kora learning experience
  • To process payments and manage subscriptions
  • To send verification and transactional emails
  • To respond to your support inquiries
  • To generate and review learning content and personalise facilitation

We do not sell, rent, or share your personal data with third parties for marketing purposes.

6. Data Security

Safeguards include protected authentication credentials, encrypted account identifiers, access controls, and encrypted network connections. These measures do not mean every learning record or browser copy is individually encrypted, or that the service is end-to-end encrypted against Kora or its providers.

No system guarantees absolute security. Protect your account and devices, and contact us about suspected unauthorized access. Payment card processing is handled by Stripe.

7. Cookies & Local Storage

We use HTTP-only session cookies for authentication. These are used to provide the requested service. We do not use advertising or third-party analytics cookies. Security providers may process technical information to protect the service; any non-essential storage remains subject to applicable consent requirements.

We use your browser's local storage to save session transcripts and personal notes for your convenience. This data remains on your device unless you choose to submit related content through another feature.

8. International Data Transfers

Digital Creative Academy LLC is based in Switzerland. Live voice traffic is routed through European infrastructure, but some providers may process support, payment, or text-AI data outside Switzerland, the EEA, or the UK:

  • Render — Application and database hosting, configured for Frankfurt, Germany (EU), for the application and primary database. Contact us for current deployment and subprocessor information.
  • Cloudflare — Network delivery and security where enabled, which can involve request and connection data.
  • Stripe — Payment processing. Stripe may use group companies and subprocessors internationally under its applicable contractual and transfer arrangements.
  • Google Vertex AI — Live voice processing is configured for a supported European regional endpoint. Other AI-assisted text operations use the Gemini API and may be processed outside that regional endpoint. Regional routing does not itself establish that every associated record stays in Europe. Retention, training restrictions, and other handling depend on the service, account tier, and contractual terms.
  • Google Workspace / Gmail — Transactional and support email delivery and storage. Google may process data internationally under the applicable service terms.

International transfers must meet applicable legal requirements. Where required, these include an adequacy decision or appropriate safeguards, such as Standard Contractual Clauses with relevant Swiss or UK adaptations and any necessary supplementary measures. Contact us for the locations and safeguards applicable to your data and how to obtain a copy where applicable. Provider involvement does not remove our own responsibilities.

9. Data Retention

Account details, enrollments, summaries, mastery indicators, passed Practice evidence, and assessment results are generally retained while your account is active. Failed Practice attempts become eligible for cleanup after 90 days; assessment question sets expire after two hours and are eligible for cleanup after expiry. Database contact records are eligible after 12 months. Unverified accounts may be removed after 48 hours; qualifying inactive unpaid accounts may be removed after 12 months, subject to recorded activity and access status. Actual deletion depends on scheduling and successful cleanup, not an exact deadline.

Successful account deletion removes account-linked learning history and clears local transcripts and notes in the requesting browser. Billing cancellation must be confirmed first; contact support if self-service deletion cannot be completed. Custom programme records lose their account link. Unpublished programmes then become eligible for cleanup, while published programmes may remain with their original topic, learning challenge, and content. Removing the account link does not guarantee anonymity. Contact us to request review or removal of personal information in that content.

Support email is separate from database contact records and is kept according to support needs and applicable obligations; database cleanup does not delete mailbox copies. Backups, provider records, and downloaded or other-device copies may also have separate retention. Payment, security, support, or legal records may be retained for required periods or legitimate claims. Contact us for the scope, timing, and any lawful exception applicable to your deletion request.

10. Your Rights

Subject to applicable Swiss, EU, or UK law, your rights include:

  • Access: Request a copy of personal data we hold about you.
  • Rectification: Update incorrect data from your Settings page.
  • Deletion: Request deletion through Settings or support, subject to the retention and legal exceptions described above.
  • Restrict processing: Request that we limit how we use your data.
  • Object: Object to processing based on legitimate interest.
  • Data portability: Request covered data in a structured, commonly used, machine-readable format.
  • Withdraw consent: Contact us where processing relies on consent. Muting or ending a session stops further microphone input, but does not erase earlier processing.

To exercise any of these rights, contact us at learning-support@digital-creative-academy.com. We may request proportionate identity verification; do not send passwords or payment card details. Under EU or UK GDPR, requests are normally addressed without undue delay and within one month. A permitted extension of up to two further months requires notice and reasons within the first month. Requests are normally free, subject to lawful exceptions. Other applicable deadlines remain unaffected.

11. AI Personalisation and Automated Processing

Kora uses AI-generated summaries, assessment results, and concept indicators to adapt later learning sessions. Assessment answers are scored against server-held answer keys; some configured calculations also receive deterministic checks, while other Practice feedback is AI-generated. These learning indicators do not produce legal or similarly significant decisions about you. You may contact us to question or correct inaccurate learning records.

12. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with:

  • The Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch
  • Your local EU/EEA data protection authority, if you are based in the European Union.
  • The UK Information Commissioner's Office where UK law applies.

13. Third-Party Services

  • Google Workspace / Gmail — Transactional and support email processing (Privacy Policy)
  • Stripe — Payment processing (Privacy Policy)
  • Google Vertex AI and Gemini — Vertex AI is configured for European regional live voice processing; the Gemini API supports other AI-assisted text tasks. Provider retention and training rules depend on the specific service and applicable account terms. This notice does not promise zero provider retention. Contact us for the arrangements applicable to your data. Vertex AI information is available in Google's documentation (Data governance).
  • Render — Application and database hosting (Privacy Policy).

14. Children's Privacy

Kora is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

15. Data Breach Notification

Where required, we will notify the relevant supervisory authority within the legally applicable period, including the GDPR's 72-hour period where feasible. We will notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated as required by applicable law, and any required consent will be requested specifically. Continued use alone is not consent to new processing that requires it. The "Last updated" date at the top of this page reflects the most recent revision.

17. Contact

For privacy-related questions, contact us at learning-support@digital-creative-academy.com.