Privacy Policy

Last updated September 23, 2026

A clear explanation of what Tiny Courses collects, why it is used, where it is processed, who can see it, and the choices available to you.

What matters most

A plain-English overview. The numbered sections below are the full policy.

  • Your content remains yours.

    We do not sell it, advertise with it, or use Customer Content or learner data to train AI models.

  • Learner visibility is explained up front.

    The relevant creator account can see a learner’s email address and learning activity.

  • Optional means optional.

    Tiny Courses marketing and non-essential analytics require a separate choice and do not control access.

  • Providers have defined purposes.

    We explain the key services used for hosting, storage, email, analytics, security, AI, and payments.

  • You have choices and export rights.

    Account owners can request all or selected account content, and people can manage consent preferences.

1. Who We Are

Tiny Courses is operated by Super Work Studio, a trading name of Super Work Studio Ltd, company number 17102192, whose registered office is Sheffield Technology Parks Cooper Buildings, Arundel Street, Sheffield, South Yorkshire, United Kingdom, S1 2NS. For privacy questions or requests, contact support@tinycourses.com.

2. Who Decides How Information Is Used

Tiny Courses decides how account registration, service usage, security, support, billing references, Tiny Courses communications, and optional product analytics are handled. In privacy terminology, this means Super Work Studio Ltd, trading as Super Work Studio, is the controller of that information.

An account owner or creator usually decides why learner information is collected through their courses and how they will use it. This normally makes the creator the controller of that learner information, while Tiny Courses handles it for them as a processor. Put simply: the creator makes the decisions and Tiny Courses provides the tools.

The account owner and authorised account members can see a learner’s email address and relevant enrolment, progress, activity, completion, and response information. This supports access management, learner support, course insights, and creator communications.

We may also use a limited amount of learner information to keep accounts secure, prevent fraud, meet requirements that apply to us, and operate the service. Creators must explain their own use of learner information and obtain any permission they need. Tiny Courses marketing is handled separately by Super Work Studio and is never a condition of opening an account or accessing creator content.

Business customers can contact us at any time to discuss written data-processing terms, security information, or how these responsibilities apply to their account.

3. Information We Collect

Depending on how you use Tiny Courses, we collect:

  • Account and profile information: name, email address, authentication identifiers, account memberships, roles, profile and space details, preferences, and support communications.
  • Customer Content: courses, lessons, flows, text, links, branding, images, audio, video, downloads, and other material created, imported, or uploaded through an account.
  • Learner information: email address, enrolments, invitations, progress, lesson and course activity, answers, responses, completion information, and the creator content through which access was requested. The relevant creator account can see this information as described above.
  • Billing information: plan, subscription status, Stripe customer and subscription references, invoice status, and limited transaction-support information. Tiny Courses does not store full card numbers or card security codes.
  • Technical and security information: IP address, device and browser details, session identifiers, request metadata, authentication activity, security events, and logs needed to diagnose errors or prevent abuse.
  • Optional analytics and communications data: consent choice, pages and features used, broad campaign or referrer information, selected product events, privacy-masked session replay, and email subscription or delivery status.
  • AI request data: only the prompt, selected material, and limited context submitted when a user chooses an AI-assisted feature, together with the generated response and operational request identifiers.

4. Where Information Comes From

We receive information directly from you; from an account owner or team member who invites or manages you; from a creator whose course you access; automatically from your device and use of the service; and from service providers such as authentication, payment, email, analytics, and security providers. If you choose social sign-in, stock imagery, or another integration, we receive the limited information needed from that provider to complete your request.

5. Why We Use Information

Privacy rules ask us to name the recognised reason for each use of personal information. These are standard privacy labels, not extra conditions for using Tiny Courses. Here is what they mean in everyday language:

  • Providing the service you asked for. We use the information needed to create accounts, host and deliver content, record learner progress, provide exports, send service messages, and manage subscriptions. Under data-protection rules, this reason is called “contract”; here, that simply means providing the part of Tiny Courses someone chose to use.
  • Keeping Tiny Courses safe and useful. We use limited information to prevent fraud and abuse, diagnose problems, provide support, understand performance, improve the service, and run our business. This reason is called “legitimate interests”, and we consider people’s privacy before relying on it.
  • When you choose. Tiny Courses product and community marketing, and optional analytics where required, use “consent”. These choices start off, can be refused without losing access, and can be changed at any time. Changing your mind stops future consent-based use; it does not undo anything already completed while the choice was on.
  • When we must keep or share something. We may need limited information for tax, accounting, regulators, courts, law enforcement, or a legal claim. The privacy labels for these reasons are “legal obligation” and “legal claims”.

When a learner uses their email address to join creator content, sharing that address and relevant learning activity with the creator account is part of the access and learner-management service they chose to use. Any later use by the creator is the creator’s responsibility. The creator must explain what they do, have an appropriate privacy reason, and get marketing permission where needed.

Information marked as required is needed to create the relevant account, provide requested course access, keep the service secure, or complete a payment. Without it, we may be unable to provide that part of Tiny Courses. Optional profile details, marketing choices, and non-essential analytics can be refused without losing the core service.

6. Content Ownership, AI, and Model Training

Customer Content is stored and processed to provide the features selected by the account owner. Tiny Courses does not acquire copyright in it, sell it, use it for advertising, or use Customer Content or learner data to train, fine-tune, or improve an artificial-intelligence or machine-learning model.

When a user deliberately asks for AI assistance, Tiny Courses sends the prompt, selected content, and limited necessary context to OpenAI through its business API solely to return the requested result. Requests are sent with application storage disabled, Tiny Courses does not opt in to sharing API inputs or outputs for model training, and OpenAI states that API data is not used for training by default. OpenAI may temporarily retain limited API data in abuse-monitoring logs under its API data controls, or for longer if it is required to do so. We do not automatically send an account’s whole content library to OpenAI.

7. Our Current Key Service Providers

Tiny Courses uses carefully selected providers to operate the service. Each receives only the information needed for the part it provides:

  • Supabase stores account, course, and learner data and supports sign-in.
  • Bunny.net stores and delivers uploaded files, images, and video.
  • Vercel hosts and delivers Tiny Courses and, with permission, measures page speed through Speed Insights.
  • Stripe and Link handle checkout, subscriptions, invoices, and refunds.
  • MailerSend sends account, security, and course emails.
  • MailerLite sends optional Tiny Courses marketing emails and manages unsubscribe choices.
  • Sentry helps us find and fix technical problems.
  • Cloudflare helps protect forms from automated abuse using Turnstile.
  • Mixpanel provides optional product analytics, with its analytics data processed and stored in Europe.
  • Google Analytics provides optional website analytics.
  • OpenAI handles AI requests only when a user chooses an AI feature.
  • Unsplash supports stock-image search and selection.

This lists the key providers that may handle personal information or Customer Content, not every tool used internally. Providers may change as Tiny Courses develops. We review what each provider needs and will update this Policy when a change materially affects users.

8. Cookies and Analytics

Tiny Courses uses essential cookies, session storage, and local storage for authentication, security, active account selection, session continuity, and privacy preferences. These are necessary for the service and cannot be disabled through analytics settings.

With permission, Mixpanel and Google Analytics help us understand visits, feature usage, and where people encounter problems. Vercel Speed Insights measures page load and interaction speed. Optional analytics measurement and storage are not enabled unless you accept. Advertising storage, ad personalisation, and ad-user-data signals remain denied.

Mixpanel may capture privacy-masked session replays. Reviewed interface headings, instructions, labels, and controls may be visible, while form values, sensitive details, and user-authored content are obscured. Console logs and network requests are not recorded. Rejecting analytics does not prevent use of Tiny Courses.

Your analytics choice is stored for up to six months. You can withdraw or change it at any time using . We also respect browser Do Not Track settings.

9. Sharing and Where Data Is Processed

We do not sell personal data or Customer Content. If you enter or use an email address to join creator content, we share that address and relevant learning information with that creator’s account owner and authorised members. They may use it to manage the learner relationship and communicate about their content, while following their own privacy and marketing responsibilities. We also share information with the providers above, when you ask us to, as part of a properly managed business sale or reorganisation, or when a court, regulator, security issue, or other requirement means we need to.

Tiny Courses and its providers may process data in the United Kingdom, European Economic Area, United States, and other places where they operate. When information needs extra protection before being transferred internationally, we use a country approval or transfer agreement recognised by UK data-protection rules. Contact us if you would like more information about the protection relevant to your account.

10. Security

We protect information with encrypted connections, managed sign-in, account-based permissions, protected links for private media, server checks, abuse protection, monitoring, limited administrative access, and secure handling of service keys. Providers may maintain protected backups for continuity and recovery. No internet service can guarantee absolute security, so users must also protect their sign-in details and choose publishing and membership settings carefully.

If we confirm a breach involving personal information, we will investigate it, work to contain and recover from it, and notify the people, creators, or regulators we are required to tell. When Tiny Courses handles learner data for a creator, we will give the creator the information reasonably available to help them meet their own responsibilities.

11. How Long We Keep Information and Deletion

We keep account information and Customer Content while the account is active and as needed to provide requested features. Retention also depends on the type of record: learner activity follows the account’s available analytics period; technical, security, and support records are kept only while reasonably needed to operate, investigate, and protect the service; and tax, accounting, payment, fraud, dispute, or legal records may be kept for the period required by law.

Closing an eligible account starts deletion of its account content and remote media. Deletion from active systems may not immediately remove protected backup copies awaiting their normal overwrite cycle, combined information that no longer identifies anyone, or records that Tiny Courses, Stripe, Link, or another party is required to keep. Information kept for these limited reasons remains protected and is not used for unrelated product development or AI training.

If Tiny Courses were ever discontinued, our priorities would be to protect personal data and Customer Content, communicate clearly, and give account owners a reasonable opportunity to export their information, as described in our Terms of Service. After the service and stated export period ended, we would begin deleting account data under this Policy, subject to the same restricted-backup, legal-retention, and rights-protection exceptions. Exceptional legal, security, or operational circumstances could shorten that period, but we would continue protecting recoverable information and communicating as soon as reasonably possible.

12. Your Rights, Choices, and Exports

Depending on the law and circumstances, you may ask to access, correct, delete, limit, or object to our use of your personal information; receive a portable copy; or change a consent choice. A signed-in person can switch Tiny Courses product and community marketing on or off in Profile & Sign-in; that preference follows their verified email/profile across the accounts they can access. They can also unsubscribe using the link in any Tiny Courses marketing email. To stop or question communications from a creator, use the creator’s opt-out method or contact that creator; you can also contact us if you need help identifying the relevant account. You may complain to the UK Information Commissioner’s Office or your local data-protection authority. Tiny Courses does not use fully automated decisions that have a legal or similarly important effect on people.

The primary account owner can request a portable export of all Customer Content and account records, or a selected part, at any time through Account Settings or support@tinycourses.com. The account can remain active while the export is requested. We may verify identity and authority, and we will protect another person’s rights when preparing an export. Learners should normally direct requests concerning creator-controlled course data to that creator; we will reasonably assist the creator and will handle information controlled by Tiny Courses directly.

13. Children

Tiny Courses is not designed for children to create or administer business accounts independently. If a creator makes learning content available to children, the creator is responsible for obtaining any required consent and providing appropriate notices. Contact us if you believe a child’s information has been provided without the required authority.

14. Policy Updates and Contact

We may update this Privacy Policy to reflect changes to the service, providers, or law. We will update the date above and give reasonable notice of material changes where appropriate.

For privacy questions, rights requests, data-processing terms, security information, or international-transfer safeguards, contact support@tinycourses.com.

Privacy questions? Email support@tinycourses.com.