Last updated 7 August 2026
Privacy Policy
What we collect when you use Zero to Power User, why we collect it, who else sees it, and how to make us delete it.
1.The short version
We hold your email address, your name if you give us one, what you said you want Claude for, and a record of what you have done in the course. We use it to run the course and nothing else.
There are no analytics, no tracking pixels, no advertising tags and no third-party cookies anywhere on this site. Exactly one cookie exists and it is the one that keeps you signed in. We do not sell data, we do not share it for marketing, and there is no ad network to share it with.
The rest of this page is the detail behind those two paragraphs. It is written from the actual database, not from a template.
2.What we collect, and why
Everything we hold about you falls into one of these groups.
| What | Why we have it |
|---|---|
| Email address | It is how you sign in — we email you a one-time link instead of using passwords. Also how we contact you about your account. Required. |
| Your name | Optional, and only used to greet you and to print on a certificate. You can change or clear it on your account page. |
| What you want Claude for | The goal you pick when you join. It tailors examples to your situation. It is not profiling and it goes nowhere near an advertiser. |
| Your progress | Lessons started and completed, scores, XP, badges, current and longest streak, and the date you were last active. This is the product — it is what draws your trail and computes your Skill Score. |
| Your answers | What you typed or chose in exercises, mastery checks and the exam, whether it was right, and the feedback you were given. We keep them so the course can mark you accurately, show you your own history, and so an exam result can be checked if it is ever questioned. |
| Capstone submissions | The evidence you paste for the two graded builds. A human reads these. See section 3 — it deserves its own warning. |
| Subscription state | Which plan you are on, whether it is active, when the period ends, and an identifier linking you to your Stripe customer record. Not your card number — see section 6. |
| Sign-in sessions | An unguessable token and its expiry date, so you stay signed in for 30 days. Sign-in links themselves are stored only until they are used or expire. |
| Email we have sent you | A log of which lifecycle emails went out and when — so that a re-run of our scheduled job can never send you the same email twice. If you unsubscribe we also record that, and when, so it can't be quietly undone. |
| Bug reports and support messages | What you send through the help button: your message, and for a bug the severity and the area you picked. We also attach the page you were on, your screen size and your browser, because without them a bug report usually costs two more emails. The form tells you this at the point you send it. |
| Survey answers | When you finish a level we ask one question about what we should build next. If you answer, we store which options you clicked and which level prompted it — nothing else. There is no text box, so there is nothing here you could accidentally tell us about yourself. Answering is optional and skipping it changes nothing. |
| Certificates | The certificate ID, the name it was issued to, what it is for, when it was issued, and whether it has been revoked. Part of this is public — see section 9. |
The legal basis, for those who want it
Most of the above we process because it is necessary to provide the course you asked for — the contract between us. Keeping a record of exam attempts and certificates rests on our legitimate interest in being able to stand behind a credential we issued. Records tied to payments are kept because tax and accounting law requires it.
We do not collect anything in a special category — no health data, no biometrics, no politics, nothing of that kind — and we would rather you did not type any into an exercise box either.
3.A specific warning about capstone submissions
Still to be decided · James
Capstones are closed at the moment, so there is nothing here for you to submit today. This section stays because it governs submissions already made, and because it will apply again if the assessment track reopens.
The two capstones ask you to paste evidence from work you actually did — draft emails Claude wrote in your real inbox, a workflow you built, output from a real project. That is the point of them: it is what makes the credential mean something.
It also means you may be about to paste other people's information into our database.
- Redact before you submit. The rubrics ask for anonymised excerpts. Remove names, email addresses, phone numbers, client details and anything confidential. The reviewer is assessing your method, not your contacts.
- A human reads it. Capstone submissions are reviewed by a person at Beginners in AI against the published rubric. They are not published, quoted, or shown to anyone else.
- Do not paste anything you are not allowed to share. If your employer or client would not want it leaving their systems, use a different example. Every rubric can be satisfied with a redacted one.
If you have already submitted something you would rather we did not hold, email us and we will delete that submission.
The same applies, in a smaller way, to bug reports. Describe what broke rather than pasting a screenful of your own work into the box, and if you do need to include real content, redact it first.
4.How your answers are graded
Multiple-choice and structured exercises are marked on our own servers against the correct answer, which never leaves them. Written answers are marked by a keyword and rubric check that also runs on our own servers.
Today, nothing you write is sent to an AI service to be graded. We have built the option to grade written answers against a rubric using Anthropic's API, and it is currently switched off in production.
If we turn it on, we will update this page and say so before it affects anything you write. We are stating this here rather than pre-emptively writing “we may send your answers to a third party” because that is not true right now, and a privacy notice that hedges everything tells you nothing.
6.Who else touches your data
We are a small operation and we use four suppliers to run the service. Each one is contractually a processor: they handle data on our instructions and may not use it for their own purposes.
| Supplier | What it does | What it sees |
|---|---|---|
| Vercel | Hosts and serves the site | Requests to the site, including IP address, in standard short-lived server logs |
| Neon | Runs the database | Everything listed in section 2 — this is where it is stored |
| Stripe | Takes payments and runs the billing portal | Your email, your card details and your payment history. Card details go straight to Stripe and never reach us. We store only an identifier for your Stripe record and which plan you are on |
| Resend | Delivers our email | Your email address and the contents of emails we send you |
That is the complete list. If we add a supplier that handles personal data, this table changes before they are switched on.
7.What we never do
- We do not sell your data. Not to anyone, not in any form.
- We do not share it with advertisers, data brokers or “partners”.
- We do not track you across other websites, because we run nothing that could.
- We do not build a profile of you for anything other than showing you your own progress and choosing which lesson to suggest next.
- We do not make automated decisions with a legal or similarly significant effect on you. Your exam is marked automatically, but you can ask a human to look at it and the capstones are human-reviewed by design.
8.Email you get from us
There are two kinds:
- Sign-in links and account email — sent because you asked to sign in, or because something happened to your subscription. You cannot switch these off while you have an account; without them you cannot get in.
- Course email — a welcome, a nudge if you have not started, a warning that your streak is about to lapse, a note if you left a checkout half-finished. These are there to get you back to the lesson you paid for.
Every course email carries a one-click unsubscribe link at the bottom. Clicking it takes you to a page that stops all of them — no sign-in, no survey, no “are you sure” five times. If your mail app shows its own unsubscribe button next to the sender, that works too; we send the standard headers that put it there.
If you change your mind, the same page has a button to turn them back on. You can also just email support@beginnersinai.com and ask.
Unsubscribing does not stop sign-in links or billing email. Those are part of the service rather than marketing, and without them you could not get into your own account.
9.What is visible to other people
Almost nothing about you is public. Your progress, answers, scores and streak are visible only to you.
The one exception is a certificate. Its verification page is public and unlisted — anyone holding the link can see the name it was issued to, which credential it is, when it was issued, whether it is still valid, and the live mastery figure. That is the entire point of a credential: it has to be checkable by someone who is not you, such as an employer.
The page is only reachable by its unguessable ID. It is not indexed, not listed, and there is no directory of certificate holders. You control who gets the link. If you would rather it did not exist at all, ask us and we will revoke it.
10.How long we keep things
- While your account exists — your profile, progress and answers stay, so that coming back after six months means picking up where you left off rather than starting again.
- Sign-in links — deleted once used or expired, which is a matter of minutes.
- Sessions — expire after 30 days.
- Certificates — kept indefinitely unless you ask us to revoke and remove one. A credential that vanishes cannot be verified, which defeats it.
- Bug reports and support messages — kept while the issue is open and for a reasonable period after, so we can tell whether a fix held. Unlinked from you if you delete your account.
- Survey answers — deleted with your account. Unlike a bug report, a stated preference stops being ours to keep once you leave.
- Payment records — Stripe keeps these for as long as tax and accounting law requires, typically six to seven years. That is a legal obligation and it survives account deletion.
11.Your rights, and how to use them
If you are in the UK or the EU these are statutory rights under the GDPR. We extend the same handling to everyone, because running two standards would be more work than doing it properly once.
- See what we hold. Ask, and we will send you everything, in a readable file.
- Correct it. Your name is editable on your account page. For anything else, ask.
- Delete it. Ask, and we will delete your account and everything attached to it — profile, progress, answers, submissions. Three things behave differently and we would rather say so than surprise you:
- The payment record Stripe must keep for tax purposes stays.
- Any bug report you filed stays but is unlinked from you, because the bug is still real after you have gone. Nothing in an unlinked report identifies you unless you typed something identifying into it.
- Any certificate you earned is closed rather than deleted. Your name is removed from it, and its public page then says the credential was closed at the holder's request. We do it that way because the link may be on your CV or in an email to an employer, and deleting the page outright would turn it into a dead link that looks like you invented the qualification. The page says explicitly that this is a privacy choice and not a mark against you.
- Take it with you. Ask, and you get your data in a machine-readable format.
- Object, or ask us to pause. If you think we should not be processing something, tell us and we will stop while we look into it.
Email support@beginnersinai.com for any of these. We will confirm within a few days and complete it within one month, which is the limit the GDPR sets. There is no charge.
There is no self-service “delete my account” button yet, so email us and a person does it — usually the same day. It is not a stalling tactic and there is no retention script: erasure is one action at our end and we would rather you asked than wondered.
12.Where your data physically lives
In the United States, specifically the US East region. The database runs on Neon in AWS US East 1 (Northern Virginia). The site and its server code run on Vercel in iad1 (Washington, D.C.). Stripe and Resend are US companies and process data on their own global infrastructure.
If you are in the UK or the EEA, that means your data leaves it. Transfers are covered by the standard safeguards these suppliers provide — standard contractual clauses and, where applicable, certification under the EU–US and UK–US Data Privacy Framework. We are naming the actual regions rather than describing the general case, because “may be processed internationally” tells you nothing you can check.
13.Security
- Everything travels over HTTPS. There is no unencrypted path to the site.
- There are no passwords to steal — sign-in is a one-time link, and the session cookie is unreadable by scripts in your browser.
- Correct answers are never sent to your browser. Grading happens on the server, which also means there is nothing client-side to tamper with.
- Card details never touch our servers at all.
- Payment notifications from Stripe are cryptographically signed and we verify them.
No system is perfectly secure, and anyone claiming otherwise is selling something. If personal data is ever breached in a way that puts you at risk, we will tell you and the relevant regulator within 72 hours, as the law requires.
If you find a security problem, email support@beginnersinai.com. We will take it seriously and we will not come after you for reporting it responsibly.
14.Children
The course is written for adults and sold to adults. We do not knowingly collect data from anyone under 18, and we deliberately do not ask your age — collecting a date of birth we have no use for would itself be a privacy problem.
If you believe a child has created an account, email us and we will remove it.
15.Changes to this policy
The date at the top says when this last changed. If we change something that materially affects what we do with your data, we will email you before it takes effect rather than quietly editing the page.
16.Contact and complaints
Email support@beginnersinai.com with anything at all — a question, a request, or a complaint. A person reads it.
If you are in the UK and we have not resolved something to your satisfaction, you can complain to the Information Commissioner's Office at ico.org.uk. If you are in the EU, you can complain to your national data protection authority. We would much rather you gave us the chance to fix it first.
The data controller is Solariot, Inc., at 315 West 36th Street, New York, NY 10018, USA.
This policy was last updated on 7 August 2026. See also our Terms of Service.