Privacy Policy
Last updated: 25 September 2026 · Effective: 25 September 2026
This Privacy Policy explains how Velquix Learn (“we”, “us”), a product of Velquix (based in Mumbai, India) [CONFIRM: registered legal entity name, full registered address, and governing jurisdiction], handles information when you use learn.velquix.dev. It describes what we collect, why, and the choices you have.
Information we collect
- Account information. Your email address, and a display name and profile handle. Passwords for email/password accounts are stored only as salted hashes by our authentication system — we never store your password in plain text.
- Google sign-in data. If you sign in with Google, we receive your Google account's basic identity (a Google subject identifier), email address, verified-email status, and — where provided — your display name and profile image URL. We request only the identity and email scopes needed to sign you in. We do not access Gmail, Drive, contacts, or other Google services, and we do not store Google passwords or long-lived Google access/refresh tokens.
- Email verification. For email/password accounts we store a one-time, hashed verification token and whether your email is verified.
- Learning data. Your progress through resources, roadmaps, practice tasks and projects; bookmarks; experience points, streaks and achievements; learning goals; and community content you create (such as group membership and contributions).
- Authentication metadata. Your last successful login method and time, kept private to your account for your own security awareness.
How we use your information
- To create and secure your account and sign you in.
- To provide learning features and track your progress and achievements.
- To send transactional emails (email verification and password reset).
- To operate community features you choose to use.
- To protect the service (rate limiting and abuse prevention).
We do not sell your personal information. We do not send marketing email as a condition of creating an account.
Cookies and analytics
To keep you signed in, our API sets a single essential, httpOnly session cookie (your refresh token), scoped to the authentication endpoints and marked Secure in production. A short-lived access token is held only in browser memory. We do not use third-party advertising cookies. See our Cookie Policy for details. [CONFIRM: list any analytics or measurement cookies actually deployed in production; if none, state “we do not use analytics cookies”.]
Service providers
We host our data with a managed PostgreSQL database provider (Supabase) and use Google for “Continue with Google” sign-in. These providers process data on our behalf to operate the service. [CONFIRM: any additional processors (e.g. email/SMTP provider once configured) and their hosting regions.]
Data retention
We keep your account and learning data while your account is active. One-time security tokens (email verification and password reset) expire and are single-use. [CONFIRM: specific retention periods and deletion timelines.]
Your rights
You may request access to, correction of, or deletion of your personal data. [CONFIRM: applicable legal rights (e.g. GDPR/DPDP) and how to exercise them, based on your operating jurisdiction.]
Contact
Questions about this policy? Email us at hello@velquix.dev, or see our Contact page.