F-flat Books, the parent of F-flat Learn ("we", "us"), takes your privacy seriously. This policy explains what personal information we collect when you use the F-flat Learn platform, why we collect it, who we share it with, and how you can access, export, or delete your data.
What we collect
We collect personal information in three ways:
Information you give us
- Account information: name, email address, password (stored as a hash, never in plaintext), profile photo, time zone, and language preference.
- Billing information: when you make a purchase, our payment processors (Stripe and PayPal) collect your payment-card or PayPal-account details directly. We receive only a tokenized reference plus the last four digits of your card, your billing country, and the amount charged.
- Creator profile (creators only): public bio, photo, and payout details (for instructor revenue distribution).
- Organization details (B2B): for tax-exempt or invoiced billing, we collect organization name, billing address, contact name and email, and any tax-exemption certificate you upload.
- Anything you choose to send us through the contact form, support email, or messaging features inside the platform.
Information we collect automatically
- Engagement events: which lessons you started or completed, quiz attempts and scores. This is used to award certificates, calculate creator profit-share, and improve the catalog.
- Technical data: IP address, browser type, device type, pages visited, and timestamps. We use this for security (rate-limiting, abuse detection) and product analytics.
- Cookies: we use essential cookies for sign-in sessions and a small number of analytics cookies (see Cookies and tracking below).
Information from third parties
- If you sign in with Google or Apple, we receive your name, email, and profile photo from that provider.
- Our payment processors send us the result of each transaction (success/failure, subscription status, refund events) so we can grant or revoke access correctly.
- Vimeo (our video host) sends us video-progress events so we can mark lessons complete.
Why we collect it
- To deliver the courses, certificates, and account features you signed up for.
- To process payments, refunds, and creator payouts.
- To send transactional email (receipts, password resets, course updates).
- To detect and prevent fraud, abuse, and security incidents.
- To comply with our tax, accounting, and legal obligations.
- To improve the platform — what to build, which courses are working, where we lose people.
We do not sell your personal information to anyone, ever. We do not use your data to train third-party AI models.
Who we share it with
We share data only with the service providers we need in order to run the platform. Each is bound by a data-processing agreement and uses your data only for the purpose described:
- Stripe — payment processing, subscription billing, tax calculation, invoicing.
- PayPal — legacy subscription processing and creator payouts.
- Postmark — transactional email delivery.
- Vimeo Pro — video hosting and playback.
- Sentry — server-side and client-side error reporting.
- PostHog — product analytics (anonymized where possible).
- Google / Apple — only if you use them to sign in.
We may also disclose information when required by law, when necessary to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (in which case you will be notified).
How long we keep it
- Account data: kept while your account is active. After you delete your account, personal information is removed within 30 days, except for records we are legally required to retain (typically order/payment records for tax purposes).
- Order and invoice records: retained as long as required by applicable tax law (typically 7 years in the United States).
- Engagement events: retained while your account is active, then deleted on account deletion. Aggregated, non-identifying course-level statistics may be retained indefinitely.
- Server logs: retained for up to 90 days for security and debugging.
Your rights
You have the right to:
- Access the personal data we hold about you. Use My account → Privacy → Export my data to download a JSON export of your account and engagement history.
- Correct inaccurate data — most fields are editable directly in your account settings.
- Delete your account and personal data. Use My account → Privacy → Delete my account. We use a 30-day soft-delete window so you can recover the account by signing back in within that period.
- Object to processing or restrict certain uses — contact us using the address in Contact.
- Lodge a complaint with your local data-protection authority if you believe we have not handled your data correctly.
These rights are available to all users; if you are in the EU, UK, or California they are also explicitly guaranteed by GDPR, UK GDPR, and the CCPA respectively.
Cookies and tracking
We use a small set of cookies and similar technologies:
- Essential cookies for keeping you signed in and remembering your preferences. These cannot be disabled.
- Analytics cookies from PostHog to understand how the platform is used. You can opt out from the cookie banner the first time you visit, or anytime from your account privacy settings.
We do not use third-party advertising or retargeting cookies.
Children
F-flat Learn is intended for adult learners. We do not knowingly collect personal information from children under 13 (or under 16 in the EU/UK). If you believe a child has created an account, contact us and we will delete the account and associated data.
International transfers
Our infrastructure and most service providers are located in the United States. If you are accessing F-flat Learn from outside the US, your data will be transferred to and processed in the US. Where required, we rely on Standard Contractual Clauses or equivalent transfer mechanisms.
Changes to this policy
We will post a new effective date at the top of this page when we make material changes, and notify account holders by email when the change affects how we use your data.
Contact
For privacy questions, data-rights requests, or anything else covered above, reach us through the contact form, or write to:
F-flat Books
P.O. Box 3672
Philadelphia, PA 19125