Legal / Privacy

Privacy Policy

What we collect from your team, why we need it, who else touches it, and how to get it back or have it deleted. Written to be read, not skimmed past.

Last updated 7 August 2026

01What we collect

Two things come from your employees, and both are given deliberately:

  • Daily check-in text. Four short written answers per working day: what they worked on, what took longest, what they had to redo, and what frustrated them. Free text, typed by the employee.
  • Uploaded work samples. Optional. An employee may attach or paste a document (.txt, .docx, .pdf). We extract the text server-side and store only that text — the original file is never saved anywhere. Before storing, an automatic pass strips obvious email addresses, phone numbers and SSN-like patterns, and the employee must tick a box confirming they removed client names and confidential information.

We also hold the ordinary account details needed to run the service: names, work email addresses, job titles, firm name, industry, address, time zone, and billing information.

What we do not collect: no screen recording, no keystroke logging, no location tracking, no idle-time or activity monitoring, no reading of email or files we weren't given, and no tracking of your team across other websites.

02Why we collect it

Solely to produce the thing you are paying for: a skill report for the firm and a set of courses for each employee, built from their own work rather than a stock curriculum. The check-in text and work-sample text are the input the AI analysis reads.

We use account and billing details to run your subscription and to email you about your account. We do not use any of it for advertising.

03How long we keep it

  • Check-ins, work samples, reports and courses: For as long as the firm's account is open. Deleted with the account.
  • Access logs: 12 months.
  • Support access records: Kept as a permanent record that support accessed an account, and why.
  • Deletion receipts: Kept after deletion — they are the proof the deletion happened.

04We never sell it

We do not sell, rent, or trade your data to anyone, for any purpose. We do not use it to train public AI models, and we do not pool one firm's data with another's.

05Who else processes it

Running the service means a small number of companies handle some of your data on our behalf. This is the complete list:

CompanyWhat they doWhat they see
NeonDatabase hosting (United States)All application data, including check-in text and uploaded work-sample text — both encrypted by us before they are stored.
VercelApplication hosting (United States)Serves the application; processes requests in transit. No separate copy of firm data is stored.
ClerkAuthenticationNames, email addresses and passwords. Passwords are held by Clerk and are never visible to us.
StripePaymentsBilling contact and payment details. Card numbers go directly to Stripe and never reach our servers.
ResendTransactional emailNames and email addresses, and the contents of the emails we send you.
Anthropic and/or OllamaAI analysis of check-ins and work samplesCheck-in text and work-sample text, sent to generate skill reports and courses. Which provider is in use depends on configuration; both are US-based.

The AI provider receives check-in and work-sample text in order to generate the analysis. If that matters to your firm, read the Acceptable Use rules on what should never be uploaded.

06How we protect it

  • Encrypted in transit. The site is HTTPS-only and the database connection requires TLS.
  • Encrypted at rest. Check-in text, uploaded work-sample text and AI skill reports are encrypted with AES-256-GCM before they are written to the database.
  • Per-firm isolation. Every request is authorised on the server and scoped to the requesting firm. We test this by trying to reach one firm's data while signed in as another.
  • Access logging, kept 12 months, recording who reached what and when.
  • Deletion on request, with a dated receipt listing exactly what was removed.

Occasionally we may need to open your workspace to diagnose a problem you have reported. When that happens it is read-only, a reason must be given first, every page opened is recorded permanently, and we can email you to say it happened. We can never see or change anyone's password — those are held by our login provider and are not visible to us.

What we don't claim: we are not SOC 2, ISO 27001, or HIPAA certified, and we have not been independently audited. We would rather tell you that plainly than display a badge we haven't earned.

07Export and deletion

A firm owner can download everything we hold for their firm at any time from Settings — as JSON, or as a CSV of the check-ins. That export includes the record of every time our support has accessed the workspace.

To have data permanently deleted, email aqeek@mehaklearning.com. We remove the firm's records and send back a dated receipt listing exactly what was deleted and how much of it. Individual employees should ask their firm owner, who controls the firm's data — see the Data Processing terms for why.

08Changes and contact

If we change this policy in a way that materially affects you — including adding a processor to the list above — we will email the firm owner before it takes effect.

Mehak Learning, Albany, New York. aqeek@mehaklearning.com

The other policies

Questions about any of this? Email aqeek@mehaklearning.com and a person will answer.