privacy

Privacy policy

Last updated June 2026. We write our privacy policy the same way we write our product, plainly.

principle

Encryption

TLS 1.2+ in transit, AES-256 at rest. Tokenized payments via PCI compliant processors. Keys rotated quarterly.

principle

No surveillance

We do not sell personal data. We do not run third party ad trackers. Analytics are aggregated and anonymized.

principle

Data minimization

We collect only what is needed to deliver the product. Learners can export or delete their data on request.

principle

Regional residency

EU and UK customer data stays in regional buckets. US data stays in US regions. Bring your own bucket on enterprise plans.

What we collect

Account data (name, email, organization), learning activity (course progress, quiz outcomes, lab telemetry), and billing metadata. Sponsors additionally provide org name, billing contact, and cohort criteria.

How we use it

To deliver the platform, measure skill lift, prevent abuse, and meet legal obligations. Sponsor dashboards see only anonymized aggregates of their sponsored learners unless the learner opts in to identification.

Sharing

Sub processors include cloud hosting, email delivery, and payment processing. Each is bound by a DPA. We do not sell data to third parties. We respond to lawful requests with the narrowest scope permitted by law.

Your rights

Access, correct, export, or delete your data at any time via Settings or by writing to privacy@yetinel.com. EU, UK, and California residents have additional rights under GDPR, UK GDPR, and CCPA respectively.

Children

Yetinel is not directed to children under 16. We do not knowingly collect data from children. Contact us if you believe a minor has created an account.

Contact

Data protection officer: privacy@yetinel.com.