Your data

What we store, who can see you, and what is yours to take

Browsing jarrettheintz.com sets zero cookies and runs zero third-party scripts, and our student database stores only who you are and what you have access to — never your progress, your watch-time, or any analytics about you.

That sentence is the short version of this whole page, and it is written to be checked, not believed: open your browser’s developer tools on any page here and count the cookies and the third-party scripts yourself. Everything below is held to the same standard — if a sentence on this page stops being true, the practice changes back, not the sentence.

What our student database holds

This is the complete list — who you are and what you have access to, and nothing else. An automated check runs on every change to this site and refuses any addition that would record your progress, watch-time, or behaviour server-side.

Your profile
Your email address and display name. So we know which seat is yours when you sign in. Kept while you have an account.
Your entitlements
Which courses you have access to, and when that access started or ended. This is the thing the site actually checks when you open a course. If access is revoked or refunded, the row is marked revoked rather than deleted, so there is an honest trail of what you were owed and when.
Grant history
A permanent record of every time course access was granted, and by what authority. The receipt trail behind your entitlements — it exists so nobody can quietly take back or rewrite what you were given.
Payment events
When Stripe tells us about a purchase or refund, we keep the Stripe event id and what it granted. So a purchase can never be lost or double-processed. Your card details never reach us — Stripe alone handles those.
Deals and cohorts
If you came in through an employer, a class, or a group purchase, the record connecting your seat to it. So group access works and so we know who to talk to about renewing it.
Invite records
The invitation links we create so a person on a deal can claim their seat. So an invite can be honored once, to the person it was meant for.

Smaller things, only if you use them

Calendar connection
If you connect Google Calendar for scheduling, we hold the connection token encrypted, and it self-expires after 180 days.
Rate-limit counters
To keep bots from hammering sign-in, we count requests per network address for about a minute — as keyed codes, not raw addresses, and they evaporate on their own.
Your notebook
If you sync notes, what reaches our server is ciphertext we cannot read. The key never leaves you. Zero-knowledge is the design, not a setting.
One cookie, only if you use the tomato
Starting the pomodoro timer sets one cookie so the timer can follow you between this site and the academy. It holds timer state, nothing else, and expires in 30 days. Browsing alone sets none — that is the sentence at the top of this page.

The one thing we watch for: seat sharing

When a course streams to your browser, we count how many different places your seat is being used from inside a half-hour window. That is the entire observation.

“Place” does not mean your address. The network address is turned into a keyed code the moment it arrives and discarded in the same breath; the code cannot be reversed, and it stops being comparable to anything after six hours, because the key it was made with rotates. The counts live in server memory for those six hours and are never written to any database.

Nothing automatic ever acts on it. The signal cannot block, throttle, log you out, or touch your access — it has no way to, by construction. If one seat shows up in four or more places at once, the only thing that happens is that a person looks. We built it that way because home networks, phones hopping from wifi to cellular, VPNs, and office networks all look like “different places,” and we know it.

This exists to notice one seat being resold to a whole classroom — not to watch you study.

Your record is yours

Your actual learning record — completion, scores, answers, where you left off — lives in your browser, not on our servers. That is the design, not a gap: the scanner that guards our database refuses any table that would hold it. If your access ends, you lose the course, never the record, and you can download it as a file, free, now or any time — the export button sits on every course page, including the page you see after access ends.

Your courses — and with them the export — start from your library. The download is built entirely inside your browser; no server is asked, so no server can say no.

Who else can see you, honestly

We use a small number of companies to run this. Where one of them observes you in ways we do not control, that belongs on this page too:

LearnWorlds
Runs the academy at learn.jarrettheintz.com. When you study there, LearnWorlds sees every visit and everything you do in a course, under its own privacy policy — it sets its own cookies and loads Google reCAPTCHA on its pages. That observation is theirs, not ours; we do not add our own collection on top of it, and we keep what we send them to a minimum.
Stripe
Processes every payment. Stripe sees what you bought, when, and your payment details. We keep only the event id and what it granted — card data never touches our systems.
Azure
Microsoft Azure storage holds the course files themselves. Access logs exist on Microsoft’s side; we provision no extra logging of our own there.
Vercel
Serves this site. As the host, Vercel sees every request and keeps standard server logs for a limited time. Its analytics product is installed in our code but switched off — and our own rule is that it cannot be switched on before this page says so.

What none of them get from our own code: no analytics beacons, no pixels, no fingerprinting, no server-side record of your progress or watch-time, and no stored inference about you as a learner.

Why there is no cookie banner

There is no cookie banner on this site because there is nothing to consent to: browsing sets zero cookies and loads zero trackers. A banner here would be theatre. The one self-serve exception (the pomodoro timer cookie, above) exists only after you press its button, and holds nothing about you.

Questions

If anything on this page reads as spin, or you find a cookie or a script this page says should not exist, say so and we will fix the practice or the page — in that order: connect@jarrettheintz.com.

Contact page · Copyright & IP