1. Introduction
Kurso ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our platform at kurso.in.
By using Kurso, you consent to the practices described in this policy. If you do not agree, please discontinue use of the Service.
2. Information We Collect
Information you provide directly:- Account information: name, email address, password
- Profile data: display name, course name, WhatsApp number
- Payment information: processed by Razorpay — we do not store card details
- Course content: videos, PDFs, and other materials you upload
- Student data: phone numbers and enrollment details you add
Information collected automatically:- Usage data: pages visited, features used, time spent on platform
- Device information: browser type, operating system, IP address
- Cookies and similar tracking technologies
- Log data: server logs including timestamps and error reports
Information from third parties:- Google OAuth data when you sign in with Google (name, email, profile picture)
- Razorpay transaction confirmations (amount, transaction ID, status)
- WhatsApp message metadata via Meta WhatsApp Business API
3. How We Use Your Information
We use your data to:
- Provide, maintain, and improve the Kurso platform
- Process payments and manage your subscription
- Deliver course content to your enrolled students via WhatsApp and web portal
- Send transactional emails (receipts, security alerts, account notifications)
- Operate our anti-piracy scanning and takedown services on your behalf
- Monitor platform security and prevent fraud
- Comply with legal obligations
- Respond to your support requests
We do not sell your personal data to third parties. We do not use your data for advertising purposes.
4. Data Storage and Security
Your data is stored on secure servers provided by Supabase (PostgreSQL database) with encryption at rest. Course files are stored on Cloudflare R2 with access controls. All data transmission is encrypted via HTTPS/TLS.
We implement industry-standard security measures including:
- End-to-end encryption for sensitive data
- Role-based access controls limiting who can access your data
- Regular security audits and vulnerability assessments
- Automatic session expiration and token rotation
Despite our best efforts, no security system is impenetrable. In the event of a data breach, we will notify affected users within 72 hours.
5. Data Sharing
We share your data only with:
- Supabase — database and authentication infrastructure
- Cloudflare — file storage and CDN delivery
- Razorpay — payment processing
- Meta (WhatsApp) — message delivery via WhatsApp Business API
- Resend — transactional email delivery
- Legal authorities — when required by law or court order
All third-party providers are bound by their own privacy policies and data processing agreements.
6. Student Data
Creators who use Kurso to deliver courses to students act as independent data controllers for their students' data. Kurso acts as a data processor on behalf of Creators.
Creators are responsible for:
- Obtaining proper consent from students to collect and process their data
- Informing students about how their data is used
- Complying with applicable data protection laws in their jurisdiction
Student phone numbers and progress data are stored securely and used only to deliver course content.
7. Cookies
Kurso uses the following cookies:
- Essential cookies — required for authentication and session management
- Preference cookies — remember your settings and preferences
- Analytics cookies — help us understand how the platform is used (anonymized)
You can control cookie settings through your browser. Disabling essential cookies may affect platform functionality.
8. Data Retention
We retain your data for as long as your account is active. Upon account deletion:
- A 7-day grace period begins where data is soft-deleted
- After 7 days, all account data is permanently and irreversibly deleted
- Payment records are retained for 7 years as required by financial regulations
- Anonymized usage analytics may be retained indefinitely
9. Your Rights
You have the right to:
- Access — request a copy of all data we hold about you
- Correction — update inaccurate or incomplete data
- Deletion — request deletion of your account and data
- Portability — receive your data in a machine-readable format
- Objection — object to processing of your data for specific purposes
- Withdrawal of consent — withdraw consent at any time where processing is consent-based
To exercise any of these rights, email privacy@kurso.in. We will respond within 30 days.
10. Children's Privacy
Kurso is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
11. International Data Transfers
Kurso is operated from India. If you access the Service from outside India, your data may be transferred to and processed in India and other countries where our service providers operate. By using the Service, you consent to these transfers.
For users in the European Economic Area (EEA), we ensure appropriate safeguards are in place for international data transfers in compliance with GDPR.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email at least 14 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions, data requests, or concerns:
Kurso — Privacy Team
Email: privacy@kurso.in
Support: support@kurso.in
We aim to respond to all privacy requests within 30 days.