Effective: September 13, 2026. Controller: Jamnaytac LLC (doing business as eCollective), 24A Trolley Square #1752, Wilmington, DE 19806-3334. Privacy contact: privacy@diydegree.org.

This policy covers the DIY Degree app at https://app.diydegree.org and in the iOS and Android stores, and this website. It applies to everyone who uses them, and it is written for a reader who wants the facts rather than the boilerplate.

What we collect, and why

The app is built around one loop: pick a topic, learn it from an existing resource with an AI guide, prove it with a short check, get the next topic. Everything below serves that loop.

  • Account. Your email address, a password hash or a Google/Apple identifier, your birth year (only the year, to keep the app to people old enough to use it), your time zone and locale, and an optional display name and avatar. Lawful basis: performing our contract with you.
  • Learning progress. Which topics you have studied, your check attempts and scores, mastery, XP, streaks and the time the app has given back to you. Lawful basis: performing our contract with you.
  • Guide conversations and free-response answers. What you and the AI guide say to each other, and answers you type into checks. These are the most sensitive data the app holds and are treated that way: see How the AI is used and How long we keep things. Lawful basis: performing our contract with you.
  • Sessions and devices. The device and platform of each sign-in, a coarse location derived from the sign-in IP address (never a precise location), and the last time it was active, so you can see and revoke sessions. Lawful basis: our legitimate interest in keeping your account secure.
  • Analytics. Which screens and features are used and how long a study session lasts, so we can see what works. You can turn this off in Settings and the app then stops sending events from your device. Lawful basis: your consent.
  • Crash reports. Stack traces and device details when something breaks, with personal data scrubbed before they leave the device. Lawful basis: our legitimate interest in keeping the app working.

We never collect a phone number, a postal address, a precise location, or a government identifier. There are no advertising SDKs, no data brokers, and we do not sell or share personal information in the sense of the CCPA.

How the AI is used

The guide and the check grader run on Anthropic's Claude models, which means the words you type are sent to Anthropic to be answered.

Nothing you write is used to train an AI model. Anthropic's commercial terms prohibit training on the content we send them, and we do not train on it either, sell it, or give it to anyone else.

Anthropic does hold that content for a limited period under its own commercial terms and data processing agreement, so that it can run the service and investigate abuse. A zero-retention arrangement, which would remove that window entirely, is something we have chosen not to pursue yet; if we arrange one, this page will say so.

If a learner volunteers contact details in a guide conversation (a phone number, an address, a social handle), they are removed from the stored transcript at the moment it is written.

Aggregate learning evidence per topic (how many learners attempted it, how many passed, median time to mastery) is published openly, but only when at least 50 learners are in the count, rounded to whole percentages, with no free text and no per-learner rows. Your own answers are never published, licensed, or contributed anywhere.

Who processes data for us, and where

These are the only companies that process personal data on our behalf.

ProcessorPurposeRegion
Amazon Web Services (AWS)Hosting and storage: sign-in (Cognito), the application database and API (DynamoDB, AppSync, Lambda), file storage (S3), transactional email (SES), text embeddings for search (Bedrock, Titan), and the web app itself (Amplify Hosting with a global CloudFront edge cache).US East (N. Virginia), us-east-1; CloudFront edge locations worldwide for the web app
AnthropicThe AI guide and check grading (the Claude API).United States. Contractually barred from training on what we send. Content is held for a limited period under Anthropic’s commercial terms and data processing agreement.
Expo (EAS)Building and submitting the iOS and Android apps. Receives no learner data at run time.United States
SentryCrash and error reports from the app, with personal data scrubbed before sending.United States
PostHogProduct analytics: which screens and features are used. Off entirely when you opt out.United States
Google and AppleOnly if you choose "Sign in with Google" or "Sign in with Apple": your identity provider shares your email address and a stable identifier with us.Per the provider

Learning resources themselves (a YouTube video, a course page) are played through the provider's own embedded player or opened in your browser; the provider's own privacy policy applies to what you do there, and the app tells you when you are leaving it.

How long we keep things

DataKept for
Account and profileFor as long as the account exists; purged within 30 days of deletion
Guide conversations12 months by default, or deleted after each session if you choose that in Settings
Free-response check answers24 months
Text extracted from learning resources for the guide90 days; never the media itself
Analytics events25 months, or none if you opt out
Session records (device, coarse location from sign-in IP)Until you revoke the session or delete the account

Your choices and rights

  • Export. From Settings, request a ZIP of your profile, mastery, attempts, XP, sessions and guide transcripts as JSON, plus a readable mastery record. Delivered within 30 days, usually within a day.
  • Delete. From Settings, delete your account. There is a 7-day window to change your mind; after that every personal record is hard-deleted within 30 days. Aggregate statistics that already met the 50-learner threshold survive because they contain nothing about you.
  • Opt out of analytics. One switch in Settings. It disables event collection on the device rather than merely hiding it.
  • Control guide transcripts. Keep them for 12 months, or have them deleted after every session.
  • Sessions. See every active session and sign out any of them, or all of them at once.
  • Public profile. Off by default. Nothing about you is public until you choose it.

If you are in the EEA, the UK, California or another place with a privacy law that gives you rights of access, correction, portability, erasure, restriction or objection, write to privacy@diydegree.org and we will act within the time the law gives us. You may also complain to your local supervisory authority.

Children

The app is for people aged 13 and over in the United States and 16 and over in the EEA and the UK (or the age of digital consent where your country sets it lower). We ask for a birth year at sign-up and do not create accounts below the minimum; if we learn that one exists, we delete it. We do not knowingly collect anything from a child.

Security

Data is encrypted in transit and at rest, sign-in is handled by Amazon Cognito, every server record that describes your progress can be written only by our own back-end code, and curators who review content pass identity vetting and use multi-factor authentication.

Copyright and takedown requests

The app links to and embeds other people's learning material; it does not copy or re-host it. If you believe content reachable through the app or this site infringes your copyright, or should otherwise be removed, contact our designated agent, Copyright Agent, at copyright@ecollective.org (by post: Jamnaytac LLC (doing business as eCollective), 24A Trolley Square #1752, Wilmington, DE 19806-3334; by phone: 929-262-1869) with the location of the material, a description of the work, your contact details, and a statement of good-faith belief. We act on every valid notice and route it to a human reviewer.

Changes

When this policy changes in a way that matters, we say so in the app and update the effective date above. Older versions are available on request.