Skip to content

Privacy Policy

Last updated: August 31, 2026

This Privacy Policy explains how Didactora ("we", "us", or "our") collects, uses, and protects your personal information when you use our website and product. We aim to collect only what we need, and we do not sell your personal data or use it for advertising.

1. Who is responsible

Didactora, an independent sole proprietorship based in Israel, is responsible for your personal information in connection with the service. For any privacy question, contact support@didactora.com.

2. Information we collect

We collect the following categories of information:

  • Account information you provide, such as your name and email address, and a securely hashed password. We never store your password in plain text.
  • Billing information, handled by our payment processor Paddle. We do not receive or store your full card number. We receive limited details such as your plan, transaction status, and country for tax purposes.
  • Content you create, such as your courses, text, images, and media. Projects are stored locally in your browser; if you save a project to the cloud or publish a course for hosting, that content is stored on our infrastructure.
  • Learner interaction records, when an author publishes a course with reporting turned on - described in their own section below.
  • Technical and usage data, such as log data, IP address, browser and device information, and error reports, used to operate, secure, and improve the service. Observability data is sampled in production.

3. How we use your information

We use your information to:

  • Provide, maintain, and improve the service.
  • Authenticate you and keep your account secure.
  • Process payments and manage your subscription through Paddle.
  • Respond to your support requests.
  • Detect, prevent, and address abuse, fraud, and technical issues.
  • Comply with legal obligations.

4. Local-first storage, cloud projects, and hosted courses

Didactora is local-first. Your projects are stored in your browser using standard browser storage, and you can export them at any time in the open .didac format. If you choose to save projects to the cloud or to publish a course for hosting, that content is stored on our infrastructure under your account, and a hosted course is served at an unguessable public link that you control: you can take it down, put it back, or delete it.

5. Course reporting (learner records)

When an author publishes a hosted course and turns reporting on, the course sends us interaction records when it is launched outside a learning management system: which slides were viewed, whether the course was completed, and scores. When a course runs inside a learning management system, its record goes to that system only - we never receive a copy.

By default these records are counted per browser and carry no name or email address - records that arrive carrying personal identifiers are rejected. A course can be set to ask learners to identify themselves; in that case the identifier is masked on the way in and we store a coded value in place of what was typed. We say this plainly: the coded value still counts as personal information and is protected as such - masking is not anonymity.

The person or organization that published the course is responsible for the learner records their course collects; we store and process those records for them. If you took someone's course and have a question about your data in it, ask the course provider - from the outside we cannot tell which records are yours.

The account owner chooses where these records are stored (a storage region) once, when reporting is first activated, and that choice does not change afterwards.

6. When a course is taken down or deleted

Taking a course down makes its public link stop answering and closes it to new reports. Nothing is deleted, and the author can put the course back online at the same link at any time.

Deleting a course destroys its content and its public link permanently - the address is never reused. Learner records already collected are not destroyed with it: they are kept until their retention period runs out and are then destroyed automatically, and the account owner can destroy them earlier from the analytics page.

In both cases the course stops being served from our systems. A copy a learner's device has already downloaded can stay on that device until it next asks us for the page, which happens the next time the learner opens the link. We state this rather than claiming that a take-down or a deletion reaches every device at the same instant.

7. Erasing a person from course records

An account owner can erase an identified person from their courses' records. Erasure destroys the stored coded identifier - the only copy - after which the remaining records can no longer be tied to that person through it, while the course's overall statistics stay intact.

Because deleted data can persist in our infrastructure provider's backups for a limited time, we treat an erasure as fully complete 30 days after it is made, and we say so rather than calling it instant.

If you are a learner, ask the course provider to request erasure - they are responsible for the records, and we act on their instruction.

8. Cookies and tracking

We use only cookies and similar technologies that are strictly necessary to run the site and keep you signed in. We do not use advertising cookies, cross-site tracking, or third-party analytics that profile you across the web. Because we avoid non-essential tracking, the site does not need a tracking-consent banner.

9. Who we share information with

We do not sell your personal information. We share it only with the service providers who help us operate Didactora, and only as needed:

  • Paddle, for payment processing and tax handling, as our Merchant of Record.
  • Cloudflare, for hosting, content delivery, and security infrastructure.

We may also disclose information if required by law, to protect our rights, or in connection with a business transfer, in which case we will take reasonable steps to keep your information protected.

10. International transfers

We operate from Israel and use providers that may process data in other countries. Where information is transferred internationally, we rely on appropriate safeguards and on our providers' compliance frameworks.

11. Data retention

We keep your information for as long as your account is active or as needed to provide the service, and afterwards only as required to comply with legal obligations, resolve disputes, and enforce our agreements. You can ask us to delete your account and associated data at any time.

Learner interaction records have their own retention periods, set by plan: detailed raw records are kept for a fixed period, summarized statistics for a longer one, and both are removed automatically when their period ends. Nothing in this category is kept forever. Deleting a course does not extend anything - the records' clocks keep running from the deletion - and an account whose plan includes no reporting has any remaining records destroyed within 30 days of the course's deletion.

12. Security

We use technical and organizational measures to protect your information, including encryption in transit, hashed passwords, and access controls. No method of storage or transmission is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to notify you of significant incidents where required.

13. Your rights

Depending on your location, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise any of these rights, email support@didactora.com and we will respond within a reasonable time. For learner records collected by a customer's course, we refer your request to that customer, who is responsible for them - see the course reporting section above.

14. Children

Didactora is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.

15. Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we will take reasonable steps to notify you, such as by email or a notice in the product. The date at the top shows when it was last updated.

16. Contact us

Questions about your privacy or this policy? Email support@didactora.com.