Privacy Policy

What we collect, why, and what we deliberately avoid

Last updated: July 29, 2026

1. What we collect

We collect the minimum needed to run the service:

  • Name, email, and photo — verified by Google or Apple
  • Learning data: enrolled courses and your progress in them
  • Purchase data: orders and invoices (we never store card details)
  • Device data: device type, operating system, and a random local identifier

2. What we do not collect

Some things we deliberately avoid:

  • We do not store raw IP addresses — only an irreversible hashed fingerprint
  • We use no advertising trackers and never sell your data to anyone
  • We never request camera, microphone, or location permissions
  • We never keep your card details — they stay with the licensed payment provider

3. Why we collect it

To run the service: showing your courses, saving your progress, issuing your certificates.

To protect instructor rights: device and concurrent-stream limits require knowing active devices.

For legal compliance: keeping invoices is required by tax law.

4. Retention

We delete what we no longer need:

  • Watch sessions: deleted automatically after 90 days
  • Invoices: kept for the statutory tax-retention period
  • On account deletion: personal data is erased and invoices anonymized while keeping accounting numbers

5. Sharing with third parties

We share the minimum with essential service providers only:

  • Authentication provider (Google / Apple) — for sign-in
  • Cloud infrastructure (Google Cloud / Firebase) — for hosting data
  • Payment provider — for processing transactions
  • Video streaming provider — for delivering encrypted content
  • Email provider — for transactional messages

6. Your rights

Under the Saudi Personal Data Protection Law you have the right to access, correct, and delete your data, and to object to its processing.

To exercise any of these rights, email support@learova.com and we will respond within 30 days.

7. Data security

Data is encrypted in transit and at rest, and access is governed by strict database-level rules — not just at the interface.

Video content is protected by DRM and short-lived access tokens.