Privacy policy
What we collect, why we collect it, and how to get rid of it. Written to be read, not to be survived.
Last updated: 30 July 2026
Draft — not yet in force
This document is missing its legal entity details (see config/legal.ts). Fill those in and have it reviewed before relying on it.
Who we are
Learn in Five.ai is operated by TODO_LEGAL_ENTITY_NAME, TODO_COMPANY_REGISTRATION, at TODO_REGISTERED_ADDRESS. We are the data controller for the information described here. For anything privacy-related, email hello@learninfive.ai.
Learn in Five.ai is a sister product of Collabr.ai. The two share no login and no database — the only thing that crosses between them is your email address, and only if you buy a Collabr course (see Collabr.ai course grants below).
What we collect
| What | Why | Legal basis |
|---|---|---|
| Your email address | It is your account. We use it to send sign-in links, and to match a Collabr course purchase to your account. | Performance of a contract |
| Your name and profile picture | Only if you sign in with Google, which supplies them. Used to show who is signed in. | Performance of a contract |
| Your answers to challenges | So we can grade them, show you your history, and let you compare against past attempts. | Performance of a contract |
| Your streak and completion dates | The product is a habit tracker; this is the thing being tracked. | Performance of a contract |
| Subscription status | To know whether you can open premium content. | Performance of a contract |
| Request metadata (IP address, user agent) | Rate limiting and abuse prevention. Not used to build a profile of you. | Legitimate interests — keeping the service available |
| Aggregate page views | To see which pages are worth keeping. Only collected if you accept analytics cookies. | Consent |
We do not collect anything we don't use. There is no advertising ID, no cross-site tracking, no data broker, and no sale of personal data — under any definition, including the broad Californian one.
Your submitted answers, and AI grading
Most exercises are graded by a rule-based checker that runs on our own servers. Your answer never leaves our infrastructure for those.
Some exercises are graded by a large language model instead. When that happens, the exercise scenario and the text you wrote are sent to Anthropic's API to produce the feedback. Anthropic processes it to return a result and does not use API inputs to train its models. Nothing else about you — not your name, email, or streak — is included in that request.
If you would rather not have your writing processed that way, don't include personal or confidential information in your answers. They are practice exercises; there is never a reason to put real customer data in one.
Who else processes your data
We use the following sub-processors. Each is here because the product genuinely sends them data — this is not a boilerplate list.
| Provider | What it does | What it receives |
|---|---|---|
| Neon | Managed Postgres — stores your account, submissions and streak | Account details, submissions, streak, subscription state |
| Vercel | Hosting, and privacy-friendly page analytics | Request metadata (IP, user agent), aggregate page views |
| Resend | Transactional email — sign-in links, reminders, receipts | Email address, message content |
| Upstash | Rate limiting, to stop abuse of public endpoints | Hashed request identifiers (IP or user id) and counters |
| Stripe | Payment processing for the premium subscription | Billing details — we never see or store your card number |
| Anthropic | Optional AI grading of prompt exercises, when a challenge is set to AI judging | The exercise scenario and your submitted answer |
| Optional sign-in with Google | Email address, name and profile picture, if you choose that method | |
| Collabr.ai | Grants a year of premium to course buyers | Your email address, to match a purchase to an account |
Some of these are outside the UK/EEA. Where that is the case, transfers rely on the provider's Standard Contractual Clauses or an equivalent approved mechanism.
Collabr.ai course grants
If you buy a course from Collabr.ai, Collabr sends us your email address, the course identifier and the purchase time, so we can give you a year of premium here. That request is cryptographically signed; we reject anything unsigned.
If you have no Learn in Five.ai account yet, we hold that email address until you sign up (or for two years, whichever comes first) purely so the premium is waiting for you. We do not email you marketing on the strength of a Collabr purchase.
How long we keep it
- Your account and submissions — until you ask us to delete them.
- Sign-in tokens — 24 hours, then they expire and are removed.
- Rate-limiting counters — minutes. They exist to count requests in a short window and are not archived.
- Unclaimed course grants — two years, then deleted.
- Payment records — kept by Stripe for as long as tax law requires, independently of us.
Your rights
If you are in the UK or EEA you have the right to access your data, correct it, delete it, take it elsewhere in a portable format, object to processing based on legitimate interests, and withdraw consent you have given. Those rights are not conditional on quoting the right article number at us — just email and ask.
- Get a copy — email us and we'll send everything we hold about you.
- Delete it — email us and your account, submissions and streak are removed. This is not recoverable.
- Stop the reminders — the toggle on your account page, or the one-click link at the bottom of any reminder email.
- Change your cookie choice — see the cookie policy.
We aim to respond within a few days and are required to within one month. If you think we've handled your data badly, please tell us first — but you also have the right to complain to your data protection authority (in the UK, the ICO).
Security
Sign-in is by emailed link; we never store a password because we never ask for one. Sessions live in our database and can be revoked. Access to premium content is checked on the server on every request, never trusted from the browser. Payment card details go directly to Stripe and never touch our servers.
No system is perfect. If you find a vulnerability, please report it to hello@learninfive.ai rather than disclosing it publicly, and we will fix it and credit you if you'd like.
Children
Learn in Five.ai is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will remove it.
Changes to this policy
If we change how we handle your data in a way that affects you, we will update the date at the top and — for anything material — email you about it rather than hoping you re-read this page.