Privacy
Privacy policy
How Discerya collects, uses, shares and protects your personal data — in plain English.
Revision 2026-09-27.1 · 27 September 2026
Previous revisions, kept unchanged: 2026-09-15.2, 2026-09-15.1
Who we are
Discerya is an online learning platform for real estate professionals. For the purposes of data protection law, the data controller is Discerya, reachable at mahmoud.nassef@heirstoneconsulting.com. That address is the fastest way to reach us about this policy or about how your data is handled.
The short version
- We collect what we need to run your account, your learning, the AI tutor, payments and security. Everything is listed below.
- When you are signed in, the course pages you view, the time you spend active on the platform and your sign-ins are linked to your account.
- Questions you ask the AI tutor, and written work you submit for AI feedback, are sent to OpenAI in the United States to generate a response. Your name and email address are not sent with them.
- Payments are handled by Stripe. We never see or store your card number.
- If you accept an invitation to a company workspace, that company can see your learning activity from the day you join, and nothing from before.
- We do not sell your data or show advertising, and we use no analytics or advertising cookies. We count visits to the website with Cloudflare Web Analytics, which sets no cookies and gives us only totals.
- You can delete your account yourself once any paid subscription has ended. Subscription and payment records are kept after deletion for accounting and tax purposes, without a link to you.
What we collect
Account and profile.
- Your name, email address, password (our authentication provider stores only a secure hash of it), job title, country and language preference.
- If you sign up on behalf of a company: the company name and the number of seats you asked for.
- Your onboarding answers (career level, experience, current profession, objectives, specialism, markets, goals, time commitment, confidence and follow-up answers), used to recommend a learning path.
Learning activity.
- Your enrolments, lesson progress and completions, quiz attempts including your answers and scores, topics you found difficult, and saved resources.
- Written exercises (simulations) you submit, and the feedback on them, which may be generated by our AI reviewer.
Usage records, linked to your account.
- Active time: while the dashboard or a lesson is open and visible on your screen, your browser records each active minute and, in a lesson, which course and lesson you are on.
- The times you sign in.
- Course pages you view. When you are signed in, each view is linked to your account; when you are not, the view is counted without any identifier.
- Lesson access: which lessons you open and when, used to detect bulk copying of course content.
Security records.
- A device identifier: a random value kept in a cookie on your browser (see Cookies below). When you open lessons while signed in, a scrambled (hashed) form of it is stored with your account, together with your browser and operating-system family, so we can see how many devices use one account.
- Security events linked to your account, such as blocked attempts to copy lesson text, unusually fast lesson access, too many searches in a short time, or many devices in use at once. For search limits we record that a search happened, not what you searched for.
- Your IP address and browser details, which our authentication provider stores with your sign-in sessions. Our application also reads your IP address, in memory only, to rate-limit the contact form and the AI tutor; it does not store it. Our hosting and database providers keep short-lived technical logs of requests (such as IP address, time and the address requested) to run and secure their services.
AI tutor.
- Your questions, the tutor's answers and the conversation history, plus an automatically written summary of longer conversations so the tutor can follow them.
- A request log for each question: the question text, which lesson it was about, usage and cost figures and, when our safety checks block an answer, the blocked text and the reason.
- Your ratings of answers, and any extra question allowance an administrator grants you.
Consent records. Which version of our terms you accepted, when, in which language, and the exact wording.
Payments. Your plan, number of seats, price, subscription status and renewal dates, payment amounts and outcomes, and Stripe reference numbers for your customer record, subscription, invoices and payments, with the link to each invoice Stripe holds. You enter card details on Stripe's own checkout page; we never see or store your card number.
Company workspaces. If you are a member: your membership, role, cohort and the learning paths assigned to you. If a company invites you, the invitation (your email address, the role offered and whether you accepted).
Notifications to the platform owner. When you sign up or enrol in a course, an event with your name (and, for sign-ups, your email address) is recorded and included in a notification email to the platform owner. Copies of those emails are kept in our email log.
Contact form. Your name, email address, organisation, the plan you are interested in and your message.
Visits to the website. When a page loads, your browser tells Cloudflare Web Analytics which page it is, the page you came from, your browser, operating system (with its version) and device type, and performance measurements such as how quickly the page loaded, how quickly it responded when you clicked or typed and whether its layout shifted. With those measurements it says whether you used a keyboard or a pointer and which part of the page was involved, identified by its name in the page's code, never by its content or anything you typed. Cloudflare works out your country from your IP address. It sets no cookies, stores nothing in your browser and does not follow you from site to site. We see only totals, never a list of visitors, and it is not linked to your account.
How we use it, and on what basis
- To provide the service you signed up for (performance of a contract): your account, courses, progress, quizzes, the AI tutor and AI feedback, company workspaces, payments and account emails.
- To keep the platform secure and protect our course content (legitimate interests): sign-in sessions, device counts, security events, lesson-access and search limits.
- To understand and improve the platform (legitimate interests): how many people visit the website, which pages and where from (as totals), which courses are viewed, active time and, for administrators, which lessons prompt the most tutor questions. For that last purpose, tutor questions from many learners are grouped automatically and summarised by our AI provider; the results may quote example questions word for word, without names.
- To keep accounting and tax records of subscriptions and payments, and to reconcile them with Stripe (legal obligation and legitimate interests).
- To answer messages you send us (legitimate interests, or steps you ask us to take before a contract).
International transfers
OpenAI, Stripe, Resend, Railway and Cloudflare are United States companies, so data they receive may be processed outside the European Union. Where that happens, the transfer relies on the safeguards in each provider's data processing terms.
Where your data is stored
Our database, including your account and learning data, is hosted by Supabase in the European Union (region eu-west-3, Paris, France). The providers listed above process the data they receive on their own infrastructure.
How long we keep it
| Data | How long |
|---|---|
| Account and profile details, onboarding answers, learning activity (enrolments, progress, quiz attempts, difficult topics, saved resources), written submissions and their feedback, AI tutor conversations and ratings, company workspace memberships and consent records | Until you delete your account |
| Sign-in sessions, with IP address and browser details (held by our authentication provider) | For the life of the session; deleted with your account |
| Sign-in times and active-minute records | 24 months, then deleted automatically |
| Course-page views made while signed in | After 12 months the link to your account is removed; the anonymous view count is kept |
| Lesson access log (content protection) | No automatic deletion yet (under review); deleted with your account |
| Security events | No automatic deletion yet (under review); when you delete your account they are kept without a link to you |
| Device records (hashed device identifier, browser and system family) | No automatic deletion yet (under review); deleted with your account |
| AI tutor request log | Question text is kept while your account exists and erased when it is deleted; the usage and cost figures are kept after deletion, without a link to your account; no fixed end date yet (under review) |
| Subscription records (plan, number of seats, price, status, dates, Stripe reference numbers) | Kept after your account is deleted, for accounting, tax and reconciliation with Stripe, without a link to your account; no fixed end date yet (under review) |
| Payment records (amounts, dates, status, Stripe reference numbers, and the link to each invoice held by Stripe) | Kept after your account is deleted, for accounting and tax purposes, without a link to your account; no fixed end date yet (under review) |
| Notifications to the platform owner about sign-ups and enrolments | Kept as an activity history; your name and email address are removed from them, and the link to your account is cleared, when you delete your account |
| Email log (copies of notification emails sent to the platform owner, which can name you) | No fixed limit yet (under review); kept, unchanged, after you delete your account |
| Invitations to a company workspace (the invited email address, role and status) | Kept by the workspace that sent them until that workspace is deleted, including after you delete your account; no fixed limit yet (under review) |
| Records of actions taken as a company workspace owner or administrator (workspaces created, invitations sent, learning paths assigned, settings changed) | Kept while the workspace or setting exists; the link to you is removed when you delete your account (for course descriptions edited by platform staff, the editor's account number stays with the edit) |
| Example tutor questions quoted, without names, in lesson insights for administrators | No fixed limit yet (under review); kept after you delete your account |
| Contact-form messages | 24 months, then deleted automatically |
“No fixed end date yet (under review)” means we have not yet set a time limit and the records are kept until we do; we will update this table when we have.
Our providers keep the data they receive under their own policies. In particular, Stripe keeps payment records as financial law requires, and OpenAI keeps data sent through its API for a limited period for abuse monitoring.
Deleting your account
You can delete your account yourself from your profile settings in the dashboard, or ask us to do it by email. Deletion is permanent and cannot be undone.
Cancel any paid subscription first. While you have a paid subscription that is still live (active, awaiting its first payment, retrying a failed payment, or suspended), deletion is blocked. The same applies if you own a company workspace that has a live subscription or other members. Cancel the subscription (and, for a company workspace, remove its other members); once your paid access has ended, you can delete your account.
Erased straight away: your login, profile and sign-up details; sign-in sessions; onboarding answers; enrolments, progress, quiz attempts, difficult topics and saved resources; written submissions and their feedback; AI tutor conversations, messages, ratings and question allowances; records of a complimentary plan an administrator gave you; consent records; company workspace memberships, cohorts and assignments; active-time records and sign-in times; lesson-access records; and device records.
Kept after deletion, but no longer linked to you:
- Subscription records (plan, number of seats, price, status, dates and Stripe reference numbers), for accounting, tax and reconciliation with Stripe; the link to your account is removed and the record is marked as belonging to a deleted account.
- Payment records (amounts, dates, status, Stripe reference numbers and the link to each invoice held by Stripe), for accounting and tax purposes; the link to your account is removed.
- AI usage and cost figures, to account for what the AI service costs; the text of your questions and any blocked answers is erased and the link to your account is removed.
- Security events, which contain no name or email address but may contain technical details such as which lesson was involved, as a record of attempts to misuse the platform; the link to your account is removed.
- Course-page view counts, as anonymous statistics; the link to your account is removed.
- Notifications to the platform owner about your sign-up and enrolments, as a history of activity on the platform; your name and email address are removed and the link to your account is cleared.
- Records of actions you took as a company workspace owner or as an administrator, such as a workspace you created, invitations you sent or learning paths you assigned, because the company or the platform still relies on them; the link to you is removed.
Kept after deletion and not changed by it:
- Invitations to a company workspace that were sent to your email address, with their status, because they belong to the workspace that sent them.
- Copies of notification emails to the platform owner in our email log, which can name you, as a record of the emails the platform sent.
- Example tutor questions already quoted, without names, in lesson insights for administrators, because they are stored without any link to who asked them.
- For platform staff: the account number recorded against the course descriptions they last edited, as the edit history of the course catalogue.
- Records Stripe, OpenAI and Resend hold under their own policies.
- Emails already delivered, including notification emails in the platform owner's mailbox.
How long each of these is kept is set out in “How long we keep it” above.
Accounts deleted earlier. The erasure described above was introduced with the version of this policy dated 15 September 2026. Accounts deleted before it took effect were deleted without it, so some of their records still exist: notifications to the platform owner about their sign-up and enrolments, with their name and, for sign-ups, their email address; copies of the corresponding notification emails in our email log; and a few expired sign-in link records kept by our authentication provider, which hold the account's internal number but no name or email address. A one-off clean-up of these records has been prepared and is awaiting review; it has not been carried out yet. If you deleted an account before then and want these records erased, email mahmoud.nassef@heirstoneconsulting.com and we will deal with your request.
Your rights
You have the right to:
- access the personal data we hold about you;
- rectify it: you can edit your name, job title and country in your dashboard profile, and ask us to correct anything else;
- erase it (see Deleting your account);
- receive a copy in a machine-readable format (portability): there is no self-service export yet, so email us and we will send it;
- object to or ask us to restrict processing based on legitimate interests.
To exercise any of these rights, email mahmoud.nassef@heirstoneconsulting.com. You also have the right to complain to your local data protection authority.
Please do not put personal information about yourself or anyone else, client details or confidential material into AI tutor questions or written submissions.
Changes to this policy
When we change this policy we update this page and the date below. For significant changes we publish a new version of our terms: the next time you open your dashboard, lessons and quizzes, the onboarding questionnaire, company workspaces or the admin area, we ask you to review and accept it before you can continue.
Each version of this policy has a revision number as well as a date, and the terms you accept name the revision. This is revision 2026-09-27.1, dated 27 September 2026. Earlier revisions stay available, unchanged: revision 2026-09-15.2, revision 2026-09-15.1.
Last updated: 27 September 2026 (revision 2026-09-27.1). Questions? Contact mahmoud.nassef@heirstoneconsulting.com.