Legal / Privacy
Privacy Policy
What we collect from your team, why we need it, who else touches it, and how to get it back or have it deleted. Written to be read, not skimmed past.
Last updated 7 August 2026
01What we collect
Two things come from your employees, and both are given deliberately:
- Daily check-in text. Four short written answers per working day: what they worked on, what took longest, what they had to redo, and what frustrated them. Free text, typed by the employee.
- Uploaded work samples. Optional. An employee may attach or paste a document (.txt, .docx, .pdf). We extract the text server-side and store only that text — the original file is never saved anywhere. Before storing, an automatic pass strips obvious email addresses, phone numbers and SSN-like patterns, and the employee must tick a box confirming they removed client names and confidential information.
We also hold the ordinary account details needed to run the service: names, work email addresses, job titles, firm name, industry, address, time zone, and billing information.
What we do not collect: no screen recording, no keystroke logging, no location tracking, no idle-time or activity monitoring, no reading of email or files we weren't given, and no tracking of your team across other websites.
02Why we collect it
Solely to produce the thing you are paying for: a skill report for the firm and a set of courses for each employee, built from their own work rather than a stock curriculum. The check-in text and work-sample text are the input the AI analysis reads.
We use account and billing details to run your subscription and to email you about your account. We do not use any of it for advertising.
03How long we keep it
- Check-ins, work samples, reports and courses: For as long as the firm's account is open. Deleted with the account.
- Access logs: 12 months.
- Support access records: Kept as a permanent record that support accessed an account, and why.
- Deletion receipts: Kept after deletion — they are the proof the deletion happened.
04We never sell it
We do not sell, rent, or trade your data to anyone, for any purpose. We do not use it to train public AI models, and we do not pool one firm's data with another's.
05Who else processes it
Running the service means a small number of companies handle some of your data on our behalf. This is the complete list:
| Company | What they do | What they see |
|---|---|---|
| Neon | Database hosting (United States) | All application data, including check-in text and uploaded work-sample text — both encrypted by us before they are stored. |
| Vercel | Application hosting (United States) | Serves the application; processes requests in transit. No separate copy of firm data is stored. |
| Clerk | Authentication | Names, email addresses and passwords. Passwords are held by Clerk and are never visible to us. |
| Stripe | Payments | Billing contact and payment details. Card numbers go directly to Stripe and never reach our servers. |
| Resend | Transactional email | Names and email addresses, and the contents of the emails we send you. |
| Anthropic and/or Ollama | AI analysis of check-ins and work samples | Check-in text and work-sample text, sent to generate skill reports and courses. Which provider is in use depends on configuration; both are US-based. |
The AI provider receives check-in and work-sample text in order to generate the analysis. If that matters to your firm, read the Acceptable Use rules on what should never be uploaded.
06How we protect it
- Encrypted in transit. The site is HTTPS-only and the database connection requires TLS.
- Encrypted at rest. Check-in text, uploaded work-sample text and AI skill reports are encrypted with AES-256-GCM before they are written to the database.
- Per-firm isolation. Every request is authorised on the server and scoped to the requesting firm. We test this by trying to reach one firm's data while signed in as another.
- Access logging, kept 12 months, recording who reached what and when.
- Deletion on request, with a dated receipt listing exactly what was removed.
Occasionally we may need to open your workspace to diagnose a problem you have reported. When that happens it is read-only, a reason must be given first, every page opened is recorded permanently, and we can email you to say it happened. We can never see or change anyone's password — those are held by our login provider and are not visible to us.
What we don't claim: we are not SOC 2, ISO 27001, or HIPAA certified, and we have not been independently audited. We would rather tell you that plainly than display a badge we haven't earned.
07Export and deletion
A firm owner can download everything we hold for their firm at any time from Settings — as JSON, or as a CSV of the check-ins. That export includes the record of every time our support has accessed the workspace.
To have data permanently deleted, email aqeek@mehaklearning.com. We remove the firm's records and send back a dated receipt listing exactly what was deleted and how much of it. Individual employees should ask their firm owner, who controls the firm's data — see the Data Processing terms for why.
08Changes and contact
If we change this policy in a way that materially affects you — including adding a processor to the list above — we will email the firm owner before it takes effect.
Mehak Learning, Albany, New York. aqeek@mehaklearning.com
The other policies
Questions about any of this? Email aqeek@mehaklearning.com and a person will answer.