Privacy

Privacy policy

How Discerya collects, uses, shares and protects your personal data — in plain English.

Revision 2026-09-27.1 · 27 September 2026

Previous revisions, kept unchanged: 2026-09-15.2, 2026-09-15.1

Who we are

Discerya is an online learning platform for real estate professionals. For the purposes of data protection law, the data controller is Discerya, reachable at mahmoud.nassef@heirstoneconsulting.com. That address is the fastest way to reach us about this policy or about how your data is handled.

The short version

  • We collect what we need to run your account, your learning, the AI tutor, payments and security. Everything is listed below.
  • When you are signed in, the course pages you view, the time you spend active on the platform and your sign-ins are linked to your account.
  • Questions you ask the AI tutor, and written work you submit for AI feedback, are sent to OpenAI in the United States to generate a response. Your name and email address are not sent with them.
  • Payments are handled by Stripe. We never see or store your card number.
  • If you accept an invitation to a company workspace, that company can see your learning activity from the day you join, and nothing from before.
  • We do not sell your data or show advertising, and we use no analytics or advertising cookies. We count visits to the website with Cloudflare Web Analytics, which sets no cookies and gives us only totals.
  • You can delete your account yourself once any paid subscription has ended. Subscription and payment records are kept after deletion for accounting and tax purposes, without a link to you.

What we collect

Account and profile.

  • Your name, email address, password (our authentication provider stores only a secure hash of it), job title, country and language preference.
  • If you sign up on behalf of a company: the company name and the number of seats you asked for.
  • Your onboarding answers (career level, experience, current profession, objectives, specialism, markets, goals, time commitment, confidence and follow-up answers), used to recommend a learning path.

Learning activity.

  • Your enrolments, lesson progress and completions, quiz attempts including your answers and scores, topics you found difficult, and saved resources.
  • Written exercises (simulations) you submit, and the feedback on them, which may be generated by our AI reviewer.

Usage records, linked to your account.

  • Active time: while the dashboard or a lesson is open and visible on your screen, your browser records each active minute and, in a lesson, which course and lesson you are on.
  • The times you sign in.
  • Course pages you view. When you are signed in, each view is linked to your account; when you are not, the view is counted without any identifier.
  • Lesson access: which lessons you open and when, used to detect bulk copying of course content.

Security records.

  • A device identifier: a random value kept in a cookie on your browser (see Cookies below). When you open lessons while signed in, a scrambled (hashed) form of it is stored with your account, together with your browser and operating-system family, so we can see how many devices use one account.
  • Security events linked to your account, such as blocked attempts to copy lesson text, unusually fast lesson access, too many searches in a short time, or many devices in use at once. For search limits we record that a search happened, not what you searched for.
  • Your IP address and browser details, which our authentication provider stores with your sign-in sessions. Our application also reads your IP address, in memory only, to rate-limit the contact form and the AI tutor; it does not store it. Our hosting and database providers keep short-lived technical logs of requests (such as IP address, time and the address requested) to run and secure their services.

AI tutor.

  • Your questions, the tutor's answers and the conversation history, plus an automatically written summary of longer conversations so the tutor can follow them.
  • A request log for each question: the question text, which lesson it was about, usage and cost figures and, when our safety checks block an answer, the blocked text and the reason.
  • Your ratings of answers, and any extra question allowance an administrator grants you.

Consent records. Which version of our terms you accepted, when, in which language, and the exact wording.

Payments. Your plan, number of seats, price, subscription status and renewal dates, payment amounts and outcomes, and Stripe reference numbers for your customer record, subscription, invoices and payments, with the link to each invoice Stripe holds. You enter card details on Stripe's own checkout page; we never see or store your card number.

Company workspaces. If you are a member: your membership, role, cohort and the learning paths assigned to you. If a company invites you, the invitation (your email address, the role offered and whether you accepted).

Notifications to the platform owner. When you sign up or enrol in a course, an event with your name (and, for sign-ups, your email address) is recorded and included in a notification email to the platform owner. Copies of those emails are kept in our email log.

Contact form. Your name, email address, organisation, the plan you are interested in and your message.

Visits to the website. When a page loads, your browser tells Cloudflare Web Analytics which page it is, the page you came from, your browser, operating system (with its version) and device type, and performance measurements such as how quickly the page loaded, how quickly it responded when you clicked or typed and whether its layout shifted. With those measurements it says whether you used a keyboard or a pointer and which part of the page was involved, identified by its name in the page's code, never by its content or anything you typed. Cloudflare works out your country from your IP address. It sets no cookies, stores nothing in your browser and does not follow you from site to site. We see only totals, never a list of visitors, and it is not linked to your account.

How we use it, and on what basis

  • To provide the service you signed up for (performance of a contract): your account, courses, progress, quizzes, the AI tutor and AI feedback, company workspaces, payments and account emails.
  • To keep the platform secure and protect our course content (legitimate interests): sign-in sessions, device counts, security events, lesson-access and search limits.
  • To understand and improve the platform (legitimate interests): how many people visit the website, which pages and where from (as totals), which courses are viewed, active time and, for administrators, which lessons prompt the most tutor questions. For that last purpose, tutor questions from many learners are grouped automatically and summarised by our AI provider; the results may quote example questions word for word, without names.
  • To keep accounting and tax records of subscriptions and payments, and to reconcile them with Stripe (legal obligation and legitimate interests).
  • To answer messages you send us (legitimate interests, or steps you ask us to take before a contract).

Who we share it with

Service providers that process data for us:

  • Supabase — our database and authentication, in the European Union (Paris, France).
  • Railway — hosts the web application. Every request between your browser and Discerya passes through it.
  • OpenAI (United States) — generates AI tutor answers, conversation summaries and AI feedback on written submissions, and turns text into search vectors (embeddings). It receives your question or submission, relevant lesson excerpts and recent conversation turns, but not your name or email address.
  • Stripe — payments. It receives your email address, your plan and seats, and your account ID; you give your card details to Stripe directly.
  • Resend (United States) — delivers the platform's notification emails. It receives the recipient, subject and content of each email.
  • Cloudflare (United States): Web Analytics counts visits to the website. It receives the page viewed, the referring page, your browser, operating system and device type, performance measurements (how quickly the page loaded and responded, and which part of the page was involved) and, to work out your country, your IP address; it sets no cookies and gives us only totals.

Other people who can see your data:

  • A company whose workspace you join. Once you accept an invitation, that company's workspace administrators can see your learning activity from the date you joined: progress, completions and scores. They cannot see your onboarding answers or anything from before you joined. Before you accept, the company sees nothing about you, not even whether your email address has an account with us.
  • Our administrators, who can see account, learning and payment data in order to run the service and support you.
  • Authorities, where the law requires us to disclose data.

We do not sell personal data.

International transfers

OpenAI, Stripe, Resend, Railway and Cloudflare are United States companies, so data they receive may be processed outside the European Union. Where that happens, the transfer relies on the safeguards in each provider's data processing terms.

Cookies and browser storage

We set no advertising or analytics cookies and use no trackers that follow you across sites. Visit counting (Cloudflare Web Analytics) uses no cookies or browser storage at all. These are all the cookies and browser storage the platform uses:

NameWhat it is forWhen it is setHow long it lasts
sb-edslpmyydlunbmzgbeey-auth-tokenKeeps you signed in. May be split into numbered parts (…-auth-token.0, .1).When you sign inUp to 400 days; removed when you sign out
sb-edslpmyydlunbmzgbeey-auth-token-code-verifierCompletes a sign-in, email-confirmation or password-reset link securely.During those steps onlyUntil the step is completed
localeRemembers your language.On your first visit (from your browser's language) or when you pick a language1 year
dsc_didA random device identifier, used to count how many devices use one account (security). Page scripts cannot read it.On your first visit, for every visitor, signed in or not1 year
cookie-notice-dismissedLocal storage, not a cookie: remembers that you closed the cookie notice.When you close the noticeUntil you clear your browser data
rel_chunk_reloadSession storage, not a cookie: prevents a reload loop after we release an update.Only after a page fails to loadUntil you close the tab

Stripe's checkout page, on stripe.com, sets its own cookies under Stripe's privacy policy. We treat the cookies above as necessary to provide the service securely, so we do not ask for cookie consent. You can block or delete them in your browser, but you will not be able to stay signed in without the session cookie.

Where your data is stored

Our database, including your account and learning data, is hosted by Supabase in the European Union (region eu-west-3, Paris, France). The providers listed above process the data they receive on their own infrastructure.

How long we keep it

DataHow long
Account and profile details, onboarding answers, learning activity (enrolments, progress, quiz attempts, difficult topics, saved resources), written submissions and their feedback, AI tutor conversations and ratings, company workspace memberships and consent recordsUntil you delete your account
Sign-in sessions, with IP address and browser details (held by our authentication provider)For the life of the session; deleted with your account
Sign-in times and active-minute records24 months, then deleted automatically
Course-page views made while signed inAfter 12 months the link to your account is removed; the anonymous view count is kept
Lesson access log (content protection)No automatic deletion yet (under review); deleted with your account
Security eventsNo automatic deletion yet (under review); when you delete your account they are kept without a link to you
Device records (hashed device identifier, browser and system family)No automatic deletion yet (under review); deleted with your account
AI tutor request logQuestion text is kept while your account exists and erased when it is deleted; the usage and cost figures are kept after deletion, without a link to your account; no fixed end date yet (under review)
Subscription records (plan, number of seats, price, status, dates, Stripe reference numbers)Kept after your account is deleted, for accounting, tax and reconciliation with Stripe, without a link to your account; no fixed end date yet (under review)
Payment records (amounts, dates, status, Stripe reference numbers, and the link to each invoice held by Stripe)Kept after your account is deleted, for accounting and tax purposes, without a link to your account; no fixed end date yet (under review)
Notifications to the platform owner about sign-ups and enrolmentsKept as an activity history; your name and email address are removed from them, and the link to your account is cleared, when you delete your account
Email log (copies of notification emails sent to the platform owner, which can name you)No fixed limit yet (under review); kept, unchanged, after you delete your account
Invitations to a company workspace (the invited email address, role and status)Kept by the workspace that sent them until that workspace is deleted, including after you delete your account; no fixed limit yet (under review)
Records of actions taken as a company workspace owner or administrator (workspaces created, invitations sent, learning paths assigned, settings changed)Kept while the workspace or setting exists; the link to you is removed when you delete your account (for course descriptions edited by platform staff, the editor's account number stays with the edit)
Example tutor questions quoted, without names, in lesson insights for administratorsNo fixed limit yet (under review); kept after you delete your account
Contact-form messages24 months, then deleted automatically

“No fixed end date yet (under review)” means we have not yet set a time limit and the records are kept until we do; we will update this table when we have.

Our providers keep the data they receive under their own policies. In particular, Stripe keeps payment records as financial law requires, and OpenAI keeps data sent through its API for a limited period for abuse monitoring.

Deleting your account

You can delete your account yourself from your profile settings in the dashboard, or ask us to do it by email. Deletion is permanent and cannot be undone.

Cancel any paid subscription first. While you have a paid subscription that is still live (active, awaiting its first payment, retrying a failed payment, or suspended), deletion is blocked. The same applies if you own a company workspace that has a live subscription or other members. Cancel the subscription (and, for a company workspace, remove its other members); once your paid access has ended, you can delete your account.

Erased straight away: your login, profile and sign-up details; sign-in sessions; onboarding answers; enrolments, progress, quiz attempts, difficult topics and saved resources; written submissions and their feedback; AI tutor conversations, messages, ratings and question allowances; records of a complimentary plan an administrator gave you; consent records; company workspace memberships, cohorts and assignments; active-time records and sign-in times; lesson-access records; and device records.

Kept after deletion, but no longer linked to you:

  • Subscription records (plan, number of seats, price, status, dates and Stripe reference numbers), for accounting, tax and reconciliation with Stripe; the link to your account is removed and the record is marked as belonging to a deleted account.
  • Payment records (amounts, dates, status, Stripe reference numbers and the link to each invoice held by Stripe), for accounting and tax purposes; the link to your account is removed.
  • AI usage and cost figures, to account for what the AI service costs; the text of your questions and any blocked answers is erased and the link to your account is removed.
  • Security events, which contain no name or email address but may contain technical details such as which lesson was involved, as a record of attempts to misuse the platform; the link to your account is removed.
  • Course-page view counts, as anonymous statistics; the link to your account is removed.
  • Notifications to the platform owner about your sign-up and enrolments, as a history of activity on the platform; your name and email address are removed and the link to your account is cleared.
  • Records of actions you took as a company workspace owner or as an administrator, such as a workspace you created, invitations you sent or learning paths you assigned, because the company or the platform still relies on them; the link to you is removed.

Kept after deletion and not changed by it:

  • Invitations to a company workspace that were sent to your email address, with their status, because they belong to the workspace that sent them.
  • Copies of notification emails to the platform owner in our email log, which can name you, as a record of the emails the platform sent.
  • Example tutor questions already quoted, without names, in lesson insights for administrators, because they are stored without any link to who asked them.
  • For platform staff: the account number recorded against the course descriptions they last edited, as the edit history of the course catalogue.
  • Records Stripe, OpenAI and Resend hold under their own policies.
  • Emails already delivered, including notification emails in the platform owner's mailbox.

How long each of these is kept is set out in “How long we keep it” above.

Accounts deleted earlier. The erasure described above was introduced with the version of this policy dated 15 September 2026. Accounts deleted before it took effect were deleted without it, so some of their records still exist: notifications to the platform owner about their sign-up and enrolments, with their name and, for sign-ups, their email address; copies of the corresponding notification emails in our email log; and a few expired sign-in link records kept by our authentication provider, which hold the account's internal number but no name or email address. A one-off clean-up of these records has been prepared and is awaiting review; it has not been carried out yet. If you deleted an account before then and want these records erased, email mahmoud.nassef@heirstoneconsulting.com and we will deal with your request.

Your rights

You have the right to:

  • access the personal data we hold about you;
  • rectify it: you can edit your name, job title and country in your dashboard profile, and ask us to correct anything else;
  • erase it (see Deleting your account);
  • receive a copy in a machine-readable format (portability): there is no self-service export yet, so email us and we will send it;
  • object to or ask us to restrict processing based on legitimate interests.

To exercise any of these rights, email mahmoud.nassef@heirstoneconsulting.com. You also have the right to complain to your local data protection authority.

Please do not put personal information about yourself or anyone else, client details or confidential material into AI tutor questions or written submissions.

Changes to this policy

When we change this policy we update this page and the date below. For significant changes we publish a new version of our terms: the next time you open your dashboard, lessons and quizzes, the onboarding questionnaire, company workspaces or the admin area, we ask you to review and accept it before you can continue.

Each version of this policy has a revision number as well as a date, and the terms you accept name the revision. This is revision 2026-09-27.1, dated 27 September 2026. Earlier revisions stay available, unchanged: revision 2026-09-15.2, revision 2026-09-15.1.

Last updated: 27 September 2026 (revision 2026-09-27.1). Questions? Contact mahmoud.nassef@heirstoneconsulting.com.

Privacy policy · Discerya