Privacy Policy
Last updated: July 27, 2026
The short version
- We collect what we need to build your plan and run your account. Nothing more.
- We don't sell your data. We don't train third-party AI on it.
- You can export or delete your account and data any time.
- We use standard security: TLS in transit, encryption at rest, row-level access.
1. Who we are
Freecoursera is operated by Educivitas Limited ("Educivitas", "we", "us"), providing an online career planning service that turns your background and goal role into a skills-mapped learning plan. For EU GDPR and UK GDPR purposes we are the data controller of personal data you provide. You can reach us at sg@educivitas.com or via our contact page.
2. What data we collect
- Account data — email, password hash (never the password itself), and Google account identifier if you sign in with Google.
- Profile & career data — current role, target role, years of experience, skills you record in your Skill Wallet, evidence you upload, learning progress, and job applications.
- Usage data — pages visited, features used, and error logs — for reliability and product improvement.
- Technical data — IP address, browser type, device information, timestamps.
3. Why we can use your data (legal bases)
Under EU / UK GDPR we rely on:
- Contract — to run the account, plan, wallet, and job matching you asked for.
- Legitimate interests — to keep the service secure, prevent abuse, and improve product quality.
- Consent — for optional marketing emails and non-essential cookies. You can withdraw at any time.
- Legal obligation — to comply with tax, accounting, and lawful requests.
4. How we use your data
- Create and secure your account.
- Generate your personalised learning plan.
- Match your Skill Wallet against available jobs.
- Send service emails (sign-in, password reset, weekly digest, receipts).
- Respond to support requests.
- Detect and prevent fraud, spam, and abuse.
We do not sell your personal data. We do not use your data to train third-party AI models.
5. Sub-processors
We use a small number of processors under written data-processing agreements. Each is bound by confidentiality and security terms consistent with GDPR Article 28:
- Cloud hosting and database (Lovable Cloud, powered by Supabase).
- Email delivery (Lovable Emails).
- AI inference for plan generation (Lovable AI Gateway).
- Public job feeds (e.g. Remotive).
See our attribution page for the current list of data sources.
6. International data transfers
Some processors are located outside your country. Where they are, we rely on the EU Standard Contractual Clauses, the UK International Data Transfer Agreement (or the UK Addendum), or an approved adequacy decision to safeguard your data.
7. Retention
- Account data — while your account is active.
- Plans, wallet entries, applications — while your account is active or until you delete them.
- Server logs — up to 30 days.
- Backups — up to 30 days after deletion.
You can delete your account and all associated data at any time from your account settings.
8. Your rights (EU / UK)
Under GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Erase your data ("right to be forgotten").
- Restrict or object to certain processing.
- Data portability — receive your data in a machine-readable format.
- Withdraw consent for marketing and non-essential cookies.
- Lodge a complaint with your local Data Protection Authority — for example the UK ICO (ico.org.uk) or the lead supervisory authority in your EU member state.
9. Your rights (California, USA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to:
- Know what personal information we collect and how we use it.
- Access a copy of your personal information.
- Correct inaccurate personal information.
- Delete your personal information (with limited exceptions).
- Opt out of sale or sharing of personal information — we do not sell or share your personal information, so there is nothing to opt out of.
- Non-discrimination for exercising these rights.
You can exercise these rights through our contact page. We do not use "financial incentives" tied to your data.
10. Cookies
We use strictly necessary cookies for sign-in and session state. Non-essential cookies (analytics, if any) are only set with your consent via the cookie banner. You can change your choice any time by clearing site data in your browser.
11. Security
We take appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), encryption at rest, row-level access controls, and least-privilege access for staff. No system is perfectly secure — please keep your password confidential.
12. Children
The service is not intended for children under 16 (or the minimum digital-consent age in your country if higher). We do not knowingly collect data from children.
13. Changes to this policy
We may update this policy from time to time. Material changes will be highlighted in-app or by email. The "last updated" date at the top always reflects the current version.
14. Contact
Privacy queries: please use our contact page.
Freecoursera