Privacy Policy
Last updated: July 7, 2026
This policy describes what data Kantigo (kantigo.dev) collects, how we use it, and the choices you have. Questions: support@kantigo.dev.
1. Data We Collect
- Account data — your email address, name, and a hashed password (never stored in plain text). If you sign in with Google or GitHub, we receive your name, email, and profile image from that provider.
- Content you create — courses, lessons, assignments, quiz answers, project submissions, uploaded files, and AI tutor conversations.
- Usage data — server logs of requests and errors (including IP address and user agent), and audit records of security-relevant account events such as logins and account changes.
We do not run client-side analytics or advertising trackers in your browser.
2. How We Use Your Data
We use your data to operate the platform: authenticate you, store and display your courses and submissions, generate AI content you request, send account-related email (such as password resets), secure the service, and debug problems. We do not sell your personal data or use it for third-party advertising.
3. Third-Party Processors
We share data with service providers only as needed to run Kantigo:
- AI providers — OpenAI, Anthropic, Google (Gemini), Groq, and Cerebras. When you use AI features (course generation, lesson content, the AI tutor), the prompts and relevant course context you provide are sent to the selected provider to generate a response.
- Google (YouTube Data API) — used to search and retrieve video metadata for YouTube-based learning paths.
- Sign-in providers — Google and GitHub, if you choose OAuth sign-in.
- Email delivery — a transactional email provider (SendGrid, Amazon SES, or Resend) to send account emails to your address.
- Axiom — server-side log storage for error and request logs.
- Database and file hosting — our MongoDB database host and S3-compatible object storage hold your account data, content, and uploaded files.
4. Cookies
We use only strictly necessary cookies: httpOnly session cookies that keep you signed in and a CSRF protection cookie. We do not set tracking or advertising cookies, so no cookie consent banner is required.
5. Retention
We keep your data for as long as your account is active. When you delete your account, your personal data is deleted or anonymized, except for copies retained in backups for a limited period and records we must keep for security or legal reasons (such as audit logs). Server logs are retained on a rolling basis and then discarded.
6. Your Rights
From Settings you can export a copy of your data or delete your account at any time. Depending on your jurisdiction (including under the Philippine Data Privacy Act of 2012), you may also have rights to access, correct, or object to processing of your personal data — contact support@kantigo.dev to exercise them.
7. Children
Kantigo is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created an account, contact us and we will delete it.
8. Security
We protect your data with industry-standard measures, including hashed passwords, encrypted connections (HTTPS), and access controls. No system is perfectly secure; if a breach affects your personal data, we will notify you as required by law.
9. Changes
We may update this policy. If we make material changes, we will notify you (for example by email or an in-app notice) before they take effect. The "Last updated" date above reflects the current version.
10. Contact
Privacy questions and requests: support@kantigo.dev.