This policy explains what English Course collects when you create an account and work through the course, why it is collected, and which other companies process it on our behalf. Each one is named below.
This policy covers the English Course website and the account you create on it. You can look around without an account; everything described below applies from the moment you sign up.
When you sign up we store your name, your email address, whether that address has been verified, and the avatar you pick for your learner card. A password is stored only as a hash — we never hold the password itself and cannot read it. If you sign in with Google instead, we store the link to that Google account and the address Google reports as verified; we never receive your Google password. Each active session is recorded with its expiry, the IP address it was created from and the browser’s user agent, so that you can be signed out safely and abuse can be traced.
As you work through the course we store which lessons you have completed, how far into each video you watched, which lesson you should continue from, and the rewards you have earned and claimed. That is what lets you pick up where you left off on another device. It belongs to your account, and the only company that sees it is Turso, which hosts the database on our behalf.
We send transactional email only: the message that verifies your address, a password reset when you ask for one, a notice when your password changes, a confirmation when you ask to change your address, and a confirmation when you ask to delete your account. These are delivered through Resend, which sends on our behalf and therefore processes your address and the contents of those messages. We send no marketing email, so there is nothing to unsubscribe from.
The sign-in, sign-up and password-reset forms are protected by Cloudflare Turnstile, which judges whether a request looks automated. Cloudflare receives the signals it needs for that judgement, including your IP address. It is there to stop automated sign-up attempts and stolen-password attacks, not to profile you.
When something fails we send an error report to Sentry so that it can be fixed. The reports carry errors only — no performance tracing and no session recording — and the SDK is configured not to attach personal data. Before a handled error leaves the server, message bodies are dropped entirely and any email address in the surrounding context is replaced with the literal text [email].
We set two cookies and no others. One remembers the language you chose, so the site opens in it next time. The other is your session, which is what keeps you signed in. There are no analytics cookies, no advertising cookies and no third-party trackers on this site.
From your profile you can change the name on your learner card, change your email address — which is confirmed first at the address on file and then at the new one — and change your password. You can delete your account from the same place at any time, without giving a reason; deletion is confirmed by an emailed link that works only in your own session.
Write to privacy@english-course.online with any question about this policy or about the data held for your account.
Last updated September 22, 2026