Privacy Policy

Last Updated: August 2026

Welcome to Learniverse! This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our platform. By using our services, you consent to the practices described in this policy.

Learniverse is used by regulated workplaces — including dental and other healthcare practices — to train and document their staff. Sections 1, 3, and 4.4 explain who is responsible for what in that arrangement, what staff information we hold, and why patient information must never be placed on the platform.

1. Our Role and Your Role

Two different relationships are covered by this policy:

  • Your own account information. When you sign up, browse our site, or contact us, we handle your personal information for our own purposes as described below. For that information we are the business responsible for it (the "controller", or under Québec law the enterprise responsible for protecting it).
  • Staff and learner records inside a practice or team account. When a clinic, practice, school, or company adds its people to Learniverse and records their training, that organization decides who is enrolled, what is recorded, how long it is kept, and what it is used for. It is responsible for that information; we process it on its behalf and on its instructions (as a "processor" or service provider).

If you are a learner in an organization's academy and want your training records corrected or deleted, contact that organization first — they control those records. We will support them in responding, and we will not use their staff data for our own purposes beyond operating, securing, and improving the service.

A data processing agreement is available to organizations on request at support@learniverse.app.

2. Data Collection

We collect information to provide and improve our services. The types of data we collect include:

2.1 Account Information

  • Email address: Used for account identification, authentication, and communication
  • Name: Used to personalize your experience on our platform
  • Profile picture: Displayed on your profile and within courses you participate in
  • Password: Stored in encrypted format for email/password authentication

2.2 Google Authentication Data

When you sign in using Google, we access the following information from your Google account:

  • Email address: To create and identify your Learniverse account
  • Display name: To personalize your profile
  • Profile photo URL: To display your avatar on the platform

We only request the minimum necessary scopes (email and profile) to authenticate you and create your account. We do not request access to your Google Drive, Gmail, Calendar, or any other Google services beyond basic profile information.

2.3 Staff and Learner Records in Practice Accounts

When an organization enrolls its people, we hold the information it provides and the activity the platform records, which typically includes:

  • Name, work email address, and mobile phone number, as supplied by the organization or through a bulk import
  • Role or job title, location or clinic, and group assignments (for example a hygienists group or a specific practice site)
  • Any professional or internal identifier the organization chooses to enter, such as a licence or order membership number or an employee number
  • Assigned training, due dates, completion status and dates, time spent, exercise responses and scores, and certificates or transcripts generated from that activity
  • Messages the person posts in their academy

Administrators of the organization can see this information for the people in their account, including individual completion and compliance status. We do not sell it and we do not use it for advertising.

2.4 Phone Numbers and SMS

Where an organization enables it, mobile phone numbers are used to sign learners in and to send training and deadline reminders by SMS:

  • Numbers are stored in a normalized international format so that duplicate records for the same person can be detected and duplicate messages suppressed
  • Messages are sent through a third-party messaging provider (Twilio) and delivered by mobile carriers, which process the number and message content to deliver it
  • We keep delivery records (which message was sent to which learner, when, and its delivery status) for troubleshooting and for the organization's audit trail
  • Replying STOP (or ARRÊT) stops platform SMS to that number

The organization that supplies a phone number is responsible for having obtained the person's consent to be contacted at it.

2.5 User-Generated Content

  • Courses and educational content you create
  • Documents you upload for course creation
  • Messages and communications within academies
  • Exercise responses and progress data

2.6 Usage Information

  • Course completion and progress tracking
  • Feature usage and interaction patterns
  • Device and browser information for optimization

2.7 Enquiries and Requested Assessments

If you contact us through a form on our site — for example to request a training or compliance assessment for your practice — we collect the details you submit, such as your name, phone number, email address, practice name, team size, and your message, together with the language of the page you used. We use this to contact you about your enquiry and to prepare for that conversation. We do not sell it or share it for marketing by anyone else.

3. Information We Do Not Want — Patient and Clinical Data

Learniverse is a staff-training system, not a clinical or patient-records system. Patient information must not be uploaded to it. That includes patient charts and treatment notes, prescriptions, billing or insurance claims, health-insurance numbers (including RAMQ numbers), and radiographs, intraoral photographs, or other images from which a patient could be identified.

De-identify clinical examples before adding them to training material. We do not act as a HIPAA business associate and have not entered into a business associate agreement or equivalent health-information processing agreement unless one has been signed with you in writing.

If patient information is uploaded by mistake, notify us at support@learniverse.app and we will work with you to remove it from the platform and from our backups on our normal backup cycle.

4. Data Storage

We take data security seriously and implement appropriate measures to protect your information:

4.1 Where We Store Your Data

  • Database: Your account information and content are stored in secure PostgreSQL databases hosted by Supabase
  • File Storage: Documents and media files are stored in encrypted cloud storage
  • Authentication: Authentication tokens are managed securely through industry-standard protocols

4.2 Location of Your Data and Cross-Border Transfers

Our production database and file storage are hosted in the United States (Supabase, AWS us-east-1). Our application, background job, email, SMS, analytics, and AI providers may also process data in the United States and in other countries where they operate. This means that personal information you or your organization place on the platform — including staff names, contact details, and training records — is stored and processed outside Québec and outside Canada, and may be subject to the laws of those jurisdictions, including lawful access requests.

We rely on contractual protections with our providers, access controls, and encryption in transit and at rest to protect that information. Organizations in Québec should take this transfer into account in their own privacy assessment before enrolling staff; contact us at support@learniverse.app if you need additional detail for that assessment.

4.3 Security Measures

  • All data transmission is encrypted using TLS/SSL
  • Passwords are hashed using industry-standard algorithms
  • Access to data is restricted through role-based permissions, enforced at the database level so that one organization cannot read another organization's records
  • Access by our staff is limited to what is needed to operate and support the service
  • Regular security audits and monitoring are performed

4.4 Data Retention

We retain your data for as long as your account is active or as needed to provide you services. You can request deletion of your account and associated data at any time by contacting support@learniverse.app.

Training and completion records are retained for as long as the organization's account is active, because organizations commonly need them as evidence for audits, inspections, or professional obligations. The organization decides how long to keep them and when to delete a learner's records. After a subscription is cancelled, the academy remains available in read-only mode for 30 days so records can be exported; after that, content may be deleted. Backups are retained on a rolling basis for a limited period, so deleted data can persist in backups briefly before it ages out. We may retain a minimal record of billing and account history where we are required to.

5. Data Usage

We use your data for the following purposes:

5.1 Core Service Functionality

  • Authentication: To verify your identity and secure your account
  • Personalization: To display your name and profile picture throughout the platform
  • Course Delivery: To provide access to courses and track your learning progress
  • Training Administration: To assign training, calculate completion and compliance status for the organization, schedule and send reminders, and produce certificates and transcripts
  • Communication: To send important account and service-related notifications

5.2 Google User Data Usage

Specifically for data obtained through Google Sign-In:

  • Your Google email is used solely to create and identify your Learniverse account
  • Your Google display name is used to set your initial profile name (which you can change)
  • Your Google profile photo is used as your default avatar (which you can change)
  • We do not use your Google data for advertising or sell it to third parties
  • We do not transfer your Google data to third parties except as necessary to provide our service

5.3 AI Processing

To generate and edit course content, the platform sends your inputs to third-party AI providers (currently Anthropic and OpenAI) and may send search queries to a web-search provider (Exa). What is sent:

  • The instructions you type, the course settings you choose, and the text of documents or reference material you attach for generation
  • For learner-facing AI features, the question or answer being processed

Our agreements with these providers do not permit them to use the content we send through their APIs to train their models. Do not paste patient information or other data you would not want processed by a third-party provider into AI features — see section 3. AI output can be inaccurate and must be reviewed by a qualified person before it is published to learners.

5.4 Service Improvement

  • Analyzing usage patterns to improve features and user experience
  • Troubleshooting technical issues and providing support
  • Developing new features based on user needs

5.5 What We Do NOT Do With Your Data

  • We do not sell your personal data to third parties
  • We do not use your data for targeted advertising outside our platform
  • We do not share your Google user data with third parties except as required to provide our services
  • We do not use an organization's staff or training records for our own marketing, and we do not disclose them to other customers
  • We do not use your data for purposes unrelated to providing our educational services

6. Third-Party Services and Subprocessors

We use trusted third-party services to operate our platform:

  • Supabase: Database, authentication, and file storage
  • Vercel: Application hosting and delivery
  • Stripe: Payment processing (we do not store your payment card details)
  • Anthropic and OpenAI: AI model providers used to generate and edit course content
  • Exa: Web search used to find reference material for courses
  • Twilio: SMS delivery for sign-in codes and training reminders
  • Loops: Transactional and notification email delivery
  • Inngest: Background job processing for content generation and scheduled reminders
  • Analytics providers: To understand how our service is used (anonymized or aggregated data)

These providers are bound by confidentiality agreements and their own privacy policies. They only process data as necessary to provide their specific services to us. An up-to-date list of subprocessors is available on request at support@learniverse.app.

7. YouTube API Services

Our service uses YouTube API Services for embedding educational videos. By using our platform, you agree to be bound by the YouTube Terms of Service. We collect and process data in accordance with the Google Privacy Policy.

Learniverse does not collect any user information regarding YouTube API data. Our platform only facilitates the display of YouTube videos through the API for educational purposes.

Our API Client may place cookies or similar tracking technologies on your devices solely for the purpose of enabling YouTube video playback functionality. We do not use these technologies to collect any personal data or track user behavior.

You can revoke our platform's access to YouTube services at any time through the Google security settings page.

8. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your account and associated data
  • Withdraw Consent: Withdraw consent where we rely on it, including stopping promotional email and SMS
  • Revoke Access: Disconnect Google Sign-In through the Google security settings page
  • Data Portability: Request your data in a portable format

To exercise any of these rights, contact us at support@learniverse.app. If your records sit inside an employer's or school's academy, we will direct your request to that organization, which controls those records — see section 1.

Depending on where you live, additional rights may apply. In Québec, Law 25 gives you rights of access, rectification, de-indexing, and portability, and the right to complain to the Commission d'accès à l'information du Québec. Elsewhere in Canada, you may complain to the Office of the Privacy Commissioner of Canada. We respond to requests within the timeframes set by applicable law (30 days in Québec).

9. Confidentiality Incidents

We maintain a register of confidentiality incidents involving personal information. If we become aware of an incident presenting a risk of serious injury, we will notify the affected organizations and, where required, the individuals concerned and the relevant privacy authority, without unreasonable delay, and we will give the organization the information it needs to meet its own notification obligations. Report a suspected incident to support@learniverse.app.

10. Subscription Plans and Payments

We offer various subscription plans for our services. Payment information is processed securely through Stripe. We do not store your credit card details on our servers. Stripe's privacy policy governs the handling of your payment information.

11. Email and SMS Communications

We may send you emails related to your account, including service updates, security alerts, and promotional content. You can opt out of promotional emails at any time through the unsubscribe link in our emails or by contacting us. Transactional messages — sign-in codes, training assignments, deadline reminders, and billing or security notices — are part of the service. SMS reminders can be stopped by replying STOP (or ARRÊT), or by asking your organization's administrator to remove your number.

12. Children

The platform is intended for use by adults and by learners enrolled by an organization. We do not knowingly collect personal information directly from children. If an organization enrolls minors, it is responsible for obtaining any consent required by the law that applies to it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of our platform after such modifications constitutes your acceptance of the updated policy.

14. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us at:

Email: support@learniverse.app

The same address reaches the person responsible for the protection of personal information at Learniverse. Write "Privacy" in the subject line and we will route it accordingly.

For questions specifically related to Google user data or our use of Google APIs, please include "Google Data Inquiry" in your email subject line.