Effective Date: September 13, 2026 Legal Entity: AvaCode Solutions LLC-FZ Registered in: Meydan Free Zone, Dubai, UAE Data Hosting: Google Cloud Platform — EU Region Contact: [email protected]
This Privacy Policy explains how we collect, use, and protect your personal data when you use InboxAcademy.
InboxAcademy is operated by AvaCode Solutions LLC-FZ, registered in Meydan Free Zone, Dubai, UAE. We are the data controller for personal data collected through the Platform. For all privacy-related inquiries, contact us at [email protected].
This Privacy Policy applies to:
When you register and use the Platform, we collect:
Unlike Learner profile pictures imported via Google Workspace (see Section 3.2), any profile photo associated with an Organization User — whether added manually or sourced automatically from Google or LinkedIn at registration — is publicly accessible on the internet, since it may be used in course or assignment-related emails sent to Learners. Similarly, any image you embed in a Course lesson, quiz, assignment, or newsletter is hosted at a publicly accessible URL because this content is delivered via email, even where the Course itself is not marked as public. Please do not upload or embed any image that must not be publicly accessible.
If you register or sign in using Google or LinkedIn social sign-in, we collect your name, email address, and profile photo (where available) from that account at the time you register or sign in; we do not access your account again afterward. You may revoke InboxAcademy's access to your Google or LinkedIn account at any time through that provider's own account settings, and you may request deletion of the data we collected from it by contacting us at [email protected].
By default, a Course Provider's Organization and each Course it creates are publicly visible, unless the Course Provider makes either private instead. The resulting public profile page (Organization name, logo, description, website, and social links, where provided) and/or public Course page is accessible to anyone, including individuals who are not enrolled Learners. While an Organization or Course is public, we may also feature this information elsewhere on the Platform or our website, such as in directories, search results, or promotional placements.
If you choose to connect your Google Workspace account to use our optional learner import feature, we access the data needed to import users in your workspace as Learners for your courses, including their email address and profile picture (where available). Imported Learner profile pictures are accessible only to your Organization and to InboxAcademy administrators, and are not publicly accessible. We do not collect Google Workspace details as part of standard account registration.
InboxAcademy's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Learners do not create accounts on InboxAcademy. We collect the following data either as provided by the Course Provider, submitted by you during self-enrollment, or collected through your participation in a course:
Personalized content is delivered via secure, time-limited JWT token links. No password or account login is required for Learners.
Quiz responses and assignment submissions are shared with the relevant Course Provider through the Platform so they can deliver, assess, and manage the course.
If you subscribe to a Course Provider's newsletter, either through a subscription form on the Course Provider's public page or website, or by opting in when you enroll in a course, we collect your email address and whether you have confirmed your subscription. A subscription made through a subscription form is confirmed only once you click the link in the confirmation email we send you; a subscription made when you enroll in a course is confirmed when your enrollment is verified. Newsletter sendouts are delivered to you only once your subscription is confirmed. The Course Provider can view and export its list of subscribers, including each subscriber's email address and confirmation status.
If you claim a certificate of completion, it displays your name, the course name, the Course Provider's organization name and logo (where provided), and the date of issue. Each certificate has its own public verification page, accessible via a unique link and QR code, that anyone with the link can use to confirm the certificate's authenticity. This verification page is public and is not subject to the same access restrictions as your other course data.
When you visit our website, we collect usage and behavioral data including pages visited, session duration, device type, approximate location, IP address, browser type, and referring URL. This data is collected via Google Analytics 4 (GA4).
We also use the Meta Pixel on our public website to measure the effectiveness of our advertising on Meta's platforms (Facebook and Instagram). Where you have consented, the pixel records page views on our public pages and sends Meta your IP address, browser and device information, the page you are viewing, and identifiers held in Meta cookies, which Meta may use to link that visit to a Meta account. Besides page views, the pixel records two events during registration, where you have consented: one when you submit the registration form and we send your verification email, and one when you click that link and your account becomes active. Both record that a registration reached that stage; neither sends Meta the contents of the form.
The pixel runs on our public website pages, and it is not active anywhere inside the Platform. It runs only while you are not signed in to a Platform account, with one exception: the short confirmation page shown immediately after you verify your email address, which you reach already signed in and which is where the completed registration is recorded. Once you leave that page for the Platform itself, the pixel does not follow you.
Your IP address is also used to determine your approximate country of residence via IP geolocation. This is used solely to decide whether to display a cookie consent banner, in accordance with applicable privacy regulations. No additional personal data is collected or stored as part of this process.
For details on how analytics and advertising cookies are managed and how to opt out, see Section 4.
If your Subscription plan allows it, any Organization User may connect a third-party AI assistant or agent of your choice to your Organization's Course content using our Model Context Protocol (MCP) service. This is an author-side feature. A connected client, and the AI model behind it, acts within that user's existing role: Admin and Editor users can read and draft Course, lesson, and quiz content, while Instructor and Viewer users can read that content only. Regardless of role, a connected client cannot access Learner identities, Learner email addresses, enrollment or progress data, or newsletter subscriber lists, and it cannot delete content, change settings, manage Organization Users, or send email.
When you authorize such a connection, we process:
Access tokens expire within 10 minutes. Refresh tokens expire after 30 days and are revoked automatically when the authorizing user leaves the Organization, has their role changed, or has their account deactivated; the user may also disconnect the client at any time. Content that a connected client reads or drafts is processed by that third-party client and its AI provider under their own terms and privacy policy. You choose and control the client you connect, and you are responsible for its security and for the credentials and tokens it holds.
The Platform uses strictly necessary cookies essential for the operation of the service, such as maintaining your authenticated session and ensuring secure access. These cookies do not require your consent and cannot be opted out of while using the Platform.
We also use Google reCAPTCHA Enterprise on our registration form to detect and prevent fraudulent or automated sign-ups. reCAPTCHA may set cookies and collect device and interaction data as part of this process. This data is processed by Google in accordance with the Google Privacy & Terms.
Our public website uses two non-essential tools: Google Analytics, to understand how visitors interact with our site, and the Meta Pixel, to measure the effectiveness of our advertising on Meta's platforms. Neither is used anywhere inside the Platform itself. Neither runs while you are signed in to a Platform account, apart from the confirmation page shown immediately after email verification, described in Section 3.4.
Both are governed by a single consent choice, and both load in an inactive state on every visit: Google Analytics loads with consent denied, and the Meta Pixel loads with consent revoked. Neither sets its cookies or records your visit until you actively accept.
Your choice is stored in a cookie on your browser and applies to both tools together; you cannot accept one and decline the other.
When the tools covered by this choice change, any consent previously given no longer covers the new set, so it is discarded and the banner asks again. This happened with the introduction of the Meta Pixel in v1.7 of this Policy: consent given before that date covered Google Analytics alone and was not carried over. A previous refusal is carried forward rather than re-asked.
Regardless of where you live, you have full control over your data:
On this site: You can instantly change your preferences or withdraw consent by clicking Cookie Settings. Withdrawing consent revokes it with both Google Analytics and the Meta Pixel immediately.
Globally: You can permanently prevent Google Analytics from using your data on any website by installing the Google Analytics Opt-out Browser Add-on. You can control how Meta uses data collected about your activity on other websites through the ad settings of your Meta account, and through Meta's Off-Facebook Activity tools.
More Info: For details on how Google handles your data, please see the Google Privacy & Terms. For details on how Meta handles data collected by the pixel, please see the Meta Privacy Policy and Meta's Cookies Policy.
Where you have consented, the Meta Pixel described above sets advertising cookies. Meta acts as an independent controller for the data it receives through the pixel and may use it to measure and improve the performance of our advertising, and to build audiences for advertising on its platforms, in accordance with its own policies.
The pixel records page views on our public website, and the two registration events described in Section 3.4. We do not use it to collect Learner course data, quiz responses, assignment submissions, or any Platform account activity, and beyond the confirmation page named in Section 3.4 we do not run it on pages seen by signed-in users. We do not sell your data to third parties for marketing purposes.
We use the data we collect to:
Product tips, onboarding guidance, and other engagement communications are optional. Every such email includes an unsubscribe link, and you may opt out at any time without affecting delivery of account, billing, or service-related emails.
AI-assisted authoring features (including AI quiz generation and AI content editing) send the specific Course, lesson, or quiz content you submit for processing to our AI sub-processor. This content is free-form and may contain personal data you choose to include. You should not submit personal data through these features, or expose it to a connected AI client, that you do not want processed by our AI sub-processor or by the client you have connected. AI-assisted authoring features and MCP connections do not read Learner identities, Learner email addresses, enrollment or progress data, or newsletter subscriber lists.
For users located in the European Economic Area (EEA) or the United Kingdom, we process personal data under the following legal bases:
Regardless of your location, InboxAcademy is committed to handling all personal data with care and transparency in accordance with this Privacy Policy.
We do not sell your personal data. We share data with the following trusted third-party service providers solely to operate the Platform:
We may also disclose your data where required by law, court order, or to protect the rights, property, or safety of InboxAcademy, our users, or others.
As a Learner, your email address is collected either when you self-enroll or when a Course Provider enrolls you. If you self-enroll, your email address will be shared with the Course Provider of that course so they can deliver and manage the course you are enrolled in.
If you subscribe to a Course Provider's newsletter, your email address is shared with that Course Provider so they can deliver and manage that newsletter, as described in Section 3.3.
Neither InboxAcademy nor Course Providers may use Learner email addresses for any purpose unrelated to the delivery of the specific course the Learner is enrolled in, or the specific newsletter the Learner has subscribed to. This includes, but is not limited to, marketing communications unrelated to that course or newsletter, third-party data sharing, or any other unrelated use. Subscribing to one newsletter does not permit a Course Provider to use your email address for its other newsletters or courses. Course Providers are contractually bound to this restriction through their agreement with InboxAcademy.
Learner email addresses will not be sold or shared with any third party, except where required by law or where disclosure is requested by a competent legal authority.
We retain personal data for as long as necessary to provide the Platform services and as required by applicable law:
All data is hosted on Google Cloud Platform in the EU region. We implement appropriate technical and organizational security measures to protect your personal data, including encryption in transit (TLS) and access controls.
For AI-assisted authoring features and MCP connections, we additionally enforce: per-Organization isolation on every request, so content belonging to another Organization is indistinguishable from content that does not exist; role-based read and write permissions mirroring those in the web app; authorization using OAuth 2.1 with PKCE and exact redirect-URI matching; short-lived access tokens and hashed refresh tokens that are automatically revoked on Organization membership, role, or account changes; plan-based access gating with usage rate limits; and a human-in-the-loop requirement, meaning any lesson or quiz generated by an AI feature or MCP client is created unpublished and must be published by a person in the web app.
While we take data security seriously, no system can be guaranteed to be 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected parties and relevant authorities in accordance with applicable law.
Depending on your location, you may have rights regarding your personal data. For users in the EEA and the United Kingdom, these include at a minimum:
To exercise any of these rights, simply contact us at [email protected]. We will respond within 30 days.
InboxAcademy does not collect age information from Learners and cannot independently verify the age of individuals using the Platform. Course Providers are solely responsible for ensuring that their courses are appropriate for their intended audience, and for obtaining any required parental or guardian consent where their courses involve minors. InboxAcademy assumes no liability for Course Provider content delivered to minors where the Course Provider has failed to meet these obligations.
All personal data collected through the Platform is primarily hosted on Google Cloud Platform servers located in the European Union, ensuring a high standard of data protection by default.
Where data is processed by third-party providers such as OpenAI, those transfers are governed by the provider's own Data Processing Agreement (DPA) and appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission where applicable. InboxAcademy takes reasonable steps to minimize the transfer of personal data outside the EEA, including where available using EU-region endpoints provided by third-party services.
Data collected by the Meta Pixel, where you have consented to it, is transferred to and processed by Meta Platforms outside the EEA, including in the United States, under Meta's own transfer safeguards. You can prevent this transfer entirely by declining or withdrawing consent in Cookie Settings.
Our MCP service, which supports AI connections for content authoring, is hosted in the European Union (Netherlands). Course, lesson, and quiz content processed by our AI sub-processor for AI-assisted authoring features is processed primarily in the United States, subject to the safeguards described above.
Regardless of where you are located, your personal data, including billing data processed via Stripe, may be transferred to, processed in, and stored in countries other than your own, including the United States and other jurisdictions in which InboxAcademy or its service providers operate. By using the Platform, you acknowledge and agree to this transfer, processing, and storage of your personal data outside of your country of residence.
We may update this Privacy Policy from time to time. Material changes will be communicated to registered Course Providers via email at least 14 days before they take effect. The "Effective Date" at the top of this document reflects the date of the most recent revision. Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
By registering as a Course Provider, you agree to this Privacy Policy as part of your acceptance of the InboxAcademy Terms of Service. By enrolling in a course — whether through self-enrollment or via a Course Provider — or subscribing to a newsletter, Learners acknowledge that their data will be processed in accordance with this Privacy Policy. Where Learners are enrolled by a Course Provider, the Course Provider is responsible for ensuring that their Learners are made aware of this Privacy Policy prior to or at the time of enrollment.
Email is currently our only support channel. For any questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please contact us:
All versions are available in the AvaCode Solutions public-contracts repository on GitHub.