Privacy Policy
Draft template — not yet reviewed by a lawyer. Replace every [BRACKETED] placeholder and validate against GDPR/UK GDPR, CCPA/CPRA, Nigeria's NDPA, Kenya's DPA, and South Africa's POPIA with counsel before relying on it. See LEGAL-REVIEW.md.Last updated: 2026.
1. Who we are (data controller)
[LEGAL ENTITY NAME] ("LogikStack", "we") of [REGISTERED ADDRESS] is the controller of your personal data. For privacy questions contact [PRIVACY / DPO EMAIL].
2. What we collect
- Account: name, email address, hashed password, and — for social sign-in — your provider identity and (optionally) profile image.
- Authentication security: TOTP secret (encrypted at rest) and recovery-code hashes, failed-login counters.
- Learning activity: course progress, quizzes/problems completed, streaks, and activity timestamps.
- Billing: subscription tier/status and transaction records (amount, currency, reference). Card details are handled by our payment provider, not stored by us.
- User content: community posts, feedback, and text you paste or upload (e.g. a résumé or job description).
- Technical: IP address and basic request metadata used for security and rate-limiting.
- Consent records: your cookie/AI-processing choices, with timestamp and version.
3. How and why we use it (legal bases under GDPR Art. 6)
- To provide the Service and save your progress — performance of a contract.
- To process payments and send receipts — contract / legal obligation.
- To secure accounts (hashing, MFA, lockout, rate-limiting, fraud prevention) — legitimate interests.
- To process AI features (lessons, résumé/JD analysis) — contract and, for uploaded résumé/JD text, your consent.
- To send service and, if you opt in, product messages — contract / consent.
- To improve the product — legitimate interests.
4. AI processing of your uploads
When you use the Job Description Lab or AI features, text you provide (including résumé/JD content) is sent to our AI provider (Anthropic) to generate a response. This text is processed transiently to produce your result and is not stored by us as a profile. We ask for your consent before this processing and log that choice.
5. Who we share with (sub-processors)
We share the minimum necessary with:
- Anthropic (Claude) — AI lessons and résumé/JD analysis. Receives the prompt text, including anything you paste or upload.
- Flutterwave — payment processing. Receives billing identifiers.
- [HOSTING PROVIDER, e.g. Render] and [DATABASE, e.g. Neon] — hosting and database. Hold all stored data (encrypted in transit; sensitive fields encrypted at rest).
- [EMAIL PROVIDER, e.g. Resend] — receipts and account emails. Receives your email address and receipt PDF.
- Google / Apple / Facebook — optional social sign-in. Receive/return the identity tokens you choose to share.
We do not sell your personal data. A Data Processing Agreement should be in place with each processor (see COMPLIANCE.md).
6. International transfers
Some providers process data outside your country (e.g. in the United States). Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision. [Confirm the mechanism for each provider.]
7. Retention
We keep account data while your account is active. When you delete your account we erase your data (see §8), except records we must keep by law — for example transaction/tax records for [RETENTION PERIOD, e.g. 6–7 years]. Backups are rotated and expire on a rolling basis.
8. Your rights
Depending on where you live (GDPR/UK GDPR, CCPA/CPRA, NDPA, Kenya DPA, POPIA), you may have the right to: access, export/port, correct, delete, restrict or object to processing, and withdraw consent. You can:
- Export your data — Settings → Account → Export.
- Delete your account and data — Settings → Account → Delete account.
- Correct your details — Settings → Edit Profile.
- For anything else, contact [PRIVACY / DPO EMAIL]. We respond within the time your law requires (usually 30 days).
You also have the right to complain to your data-protection authority (e.g. an EU supervisory authority, the UK ICO, Nigeria's NDPC, or South Africa's Information Regulator).
9. Children
The Service is not directed to children under [MINIMUM AGE], and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
10. Cookies
We use a single essential session cookie and store your theme/language/appearance preferences locally in your browser (not sent to us). See the Cookie Policy.
11. Security
Passwords are hashed (bcrypt), sensitive fields (e.g. TOTP secrets) are encrypted at rest, sessions are signed and httpOnly, and we apply MFA, rate-limiting, CSRF protection, and security headers. No system is perfectly secure, but we work to protect your data.
12. Changes
We may update this policy; material changes are posted here with a new "last updated" date and, where required, notified to you.
13. Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS] — [PRIVACY / DPO EMAIL].