Skip to content

Privacy Policy

This document is not final.

What follows is scaffolding, not reviewed legal text, and nothing on this page should be relied on. It must be replaced before Library & Co. accepts a real student.

To be written: The data-controller identity, the legal bases for processing, retention periods, how to exercise access/erasure rights, international-transfer terms, and the cookie disclosure. Blocked on the Jordan business registration and a review of which regimes apply to a worldwide student base.

What we collect

  • Account details: email, username, password (stored hashed, never in readable form).
  • Your IB subjects and levels, and your graduation session — used for recommendations.
  • Who referred you, if you signed up with a referral code.
  • Purchases, wallet credits and refunds.
  • Learning activity, in more detail than you might expect: while a lesson video is playing, your browser tells us roughly every 15 seconds how far you have got. For each lesson we keep the total time you have watched, the furthest point you reached, and when you were last watching. For a note we keep less — only that you opened it, and when you first did. This drives your progress bar and the refund and review eligibility rules. It is kept for as long as your account exists, and there is no setting to turn it off.
  • Anything you write: reviews, discussion posts, reports, refund reasons.

“Post anonymously” hides you from other users, not from us

When you post anonymously, other students and the teacher see “Anonymous student” — your username is not shown to them. Platform admins can always see who wrote a post, including anonymous ones, and they need to in order to act on reports and abuse. The same applies to anonymous reviews.

Watermarking

Course videos and notes are displayed with your username and a short code overlaid on them. The code identifies your account to us and means nothing to anyone else — it is there so that leaked material can be traced back to the account it came from. It is deliberately not your email address.

Who else sees your data

  • Teachers see aggregate figures for their own courses — enrolment counts, watch time, ratings — and the username on any non-anonymous post or review. They are not given your email.
  • The companies that run this service for us, each handling only what their part needs: Supabase (the database, your account, and the emails that confirm your address or reset your password), Bunny (delivering course video), Railway (running the website), and Cloudflare (the domain and our email routing). When card payment is switched on, PayTabs will handle the payment itself. These companies are outside Jordan; the specific countries are [BUSINESS INPUT REQUIRED: PROCESSOR LOCATIONS].
  • Some actions — approving or rejecting a teacher application, or sending a moderation warning — write a line to our server log that includes the email address the message was addressed to. Those logs are held by our hosting provider.
  • When card payments are enabled, our payment provider handles the card details. We never receive or store your card number.

Two things we keep that you might not expect

Masked contact details are kept unmasked. When you write a phone number, email address or social handle in a discussion, we hide it from other users — but we keep what you originally typed, so a moderator can see what was actually written if the post is reported.

Teacher applications are kept even if we say no. If you apply to teach, the name, schools and any documents you upload stay with us after a rejection, so we have a record of the decision and can recognise a re-application.

To be written: How long those two are kept. A 90-day rule for the unmasked discussion text is written down in the design notes and is not implemented — there is no purge function and no scheduled job — so stating a period here would publish a promise the code does not keep. Both need [BUSINESS INPUT REQUIRED: DATA RETENTION PERIOD] and then the mechanism to enforce it.

Your rights, and how to use them

Jordan's Personal Data Protection Law gives you rights over the data we hold about you — to see it, to have it corrected, to object to how we use it, and to withdraw consent you have given. To use any of them, email support@libraryandco.com, telling us what you want and which account it concerns.

We are not quoting a response time here, because we would rather not promise one we have not committed to. We will acknowledge your message and tell you what we are doing.

What we do not do

We do not sell your data, and we do not run third-party advertising or analytics trackers on the site.

Asking us to close your account

Your settings page has a control that asks us to close your account. It files a request for a person to review; nothing is erased automatically, and your account keeps working until someone acts on it. You can cancel a pending request yourself.

Not everything can be removed. Orders are accounting records. A discussion post others have replied to belongs to a conversation that is not only yours. Moderation and audit records exist precisely so that actions taken against an account can be reviewed afterwards.

To be written: What closing an account actually erases, what is kept, and for how long. This is the most important gap on this page, and it is a gap in the PRODUCT rather than only in the wording: as of 2026-08-18, approving a deletion request records the decision and erases nothing, because no erasure mechanism has been built. This section cannot be written honestly until the founder decides what deletion means here — full erasure, anonymising the profile while retaining orders, or something else — and that decision is implemented.

Age

You must be at least 16 to have an account, and you confirm that when you sign up. We store the fact that you confirmed it, when you did, and which minimum applied at the time.

We deliberately do not ask for your date of birth and do not store one. Confirming an age keeps less data about you than proving one would, and for a platform whose users are mostly under 18 that is the safer thing for us to be holding.

To be written: Children's data: which regime applies, and what this policy must therefore say. The minimum above is 16, so this platform still knowingly processes minors' data — a floor is not an answer to that. Which rules bind a Jordan-based platform with a worldwide student base, what lawful basis covers a 16- or 17-year-old's data, and whether a parent or guardian has rights over it here, all need a lawyer. Flagged rather than left silent, because silence would read as a claim that the question was considered and found not to apply.