Privacy Policy
Effective Date: May 12, 2026 | Last Updated: May 12, 2026
1. Introduction and Scope
This Privacy Policy (“Policy”) describes how Tubiversity, Inc. (“Tubiversity,” “we,” “us,” or “our”) collects, uses, stores, processes, discloses, and safeguards your personal information when you access or use our websites, applications, APIs, and related services (collectively, the “Services”). By accessing or using the Services, you acknowledge that you have read, understood, and agree to the practices described in this Policy. If you do not agree, you must immediately discontinue use of the Services.
This Policy applies globally, subject to local legal requirements. We comply with the General Data Protection Regulation (“GDPR”) for users in the European Economic Area (“EEA”), the California Consumer Privacy Act (“CCPA”) / California Privacy Rights Act (“CPRA”) for California residents, and other applicable data protection frameworks.
2. Definitions
“Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, user, or household.
“Processing” means any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
“Data Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Information.
3. Information We Collect
We collect information that you provide directly, information generated automatically through your use of the Services, and information from third-party sources, as detailed below.
3.1 Information You Provide Directly
- Account Credentials: Email address, full name, and a salted, hashed password (we do not store plaintext passwords).
- User-Generated Content: Topic queries, curriculum titles, notes, progress markers, and any other text you input into the Services.
- Communications: Contents of emails, support tickets, or other correspondence you send to us.
- Voluntary Surveys: Demographic or feedback data you choose to provide.
3.2 Automatically Collected Information
- Log Data: IP address, browser type and version, operating system, referring/exit pages, timestamps, clickstream data, and device identifiers.
- Usage Analytics: Pages viewed, features used, search queries, session duration, error logs, and interaction patterns.
- Cookies and Similar Technologies: Essential session cookies, authentication tokens, and analytics identifiers. We do not employ third-party advertising cookies or cross-site tracking pixels.
3.3 Third-Party and AI-Processed Information
- YouTube Metadata: Video titles, descriptions, channel names, thumbnail URLs, and transcript snippets retrieved via the YouTube Data API. We do not download, store, or redistribute video files.
- AI-Generated Outputs: Structured curricula, lesson summaries, and learning paths generated by our artificial intelligence systems based on your queries and publicly available metadata.
4. Legal Bases for Processing (GDPR)
We Process your Personal Information only where we have a valid legal basis under Article 6 of the GDPR:
- Performance of a Contract: To provide the Services, authenticate you, and fulfill your requests.
- Legitimate Interests: To improve service quality, prevent fraud, ensure network security, and conduct internal analytics.
- Consent: For optional features such as marketing communications or advanced analytics.
- Legal Obligation: To comply with applicable laws, regulations, court orders, or governmental requests.
5. How We Use Your Information
We use the collected information for the following purposes:
- To create, maintain, and secure your user account;
- To generate, display, and manage AI-powered learning curricula and progress tracking;
- To communicate with you regarding service updates, security alerts, and support inquiries;
- To monitor, debug, and improve the performance, reliability, and user experience of the Services;
- To enforce our Terms of Service and prevent misuse, fraud, or illegal activity;
- To comply with legal obligations and respond to lawful requests from public authorities;
- To conduct aggregated, de-identified research and statistical analysis.
6. Cookies and Tracking Technologies
We use essential cookies strictly necessary for authentication, session management, and security. These cookies do not track you across third-party websites. We do not use web beacons, pixel tags, fingerprinting, or behavioral advertising networks. You may configure your browser to refuse cookies; however, disabling essential cookies will prevent authentication and impair core functionality.
7. Data Sharing and Disclosure
We do not sell, rent, lease, or otherwise monetize your Personal Information. We disclose information only in the following limited circumstances:
- Service Providers: We engage vetted subprocessors for hosting, database management, and analytics. All subprocessors are contractually bound to confidentiality and data protection obligations consistent with this Policy.
- Legal Compliance: We may disclose information if required by law, subpoena, court order, or governmental regulation, or if necessary to establish, exercise, or defend legal claims.
- Business Transfers: In the event of a merger, acquisition, reorganization, or asset sale, your information may be transferred subject to the acquirer’s adherence to privacy standards materially equivalent to this Policy.
- With Your Consent: We may share information for purposes you have explicitly authorized.
8. International Data Transfers
Our servers are located in the United States. If you access the Services from outside the United States, your Personal Information will be transferred to, stored, and processed in the United States. For EEA users, such transfers are safeguarded by Standard Contractual Clauses (“SCCs”) approved by the European Commission, or other legally recognized transfer mechanisms, ensuring an adequate level of protection.
9. Data Retention and Deletion
We retain your Personal Information for as long as your account remains active or as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements. Upon account deletion request, we will delete or irreversibly anonymize your Personal Information within thirty (30) days, except where retention is required by law or for legitimate business interests such as fraud prevention or financial record-keeping.
You may delete individual curricula, lessons, or progress data at any time via your dashboard. Such deletion is irreversible.
10. Security Measures
We implement industry-standard administrative, technical, and physical safeguards to protect your Personal Information, including TLS 1.3 encryption in transit, AES-256 encryption at rest, salted hashing of passwords, network firewalls, access control lists, and regular security audits. No method of electronic transmission or storage is one hundred percent secure; therefore, we cannot guarantee absolute security.
11. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your Personal Information:
- Access: Request a copy of the Personal Information we hold about you.
- Rectification: Request correction of inaccurate or incomplete information.
- Erasure (“Right to be Forgotten”): Request deletion of your Personal Information, subject to legal exceptions.
- Restriction: Request limitation of Processing in certain circumstances.
- Portability: Request transfer of your data to another controller in a structured, machine-readable format.
- Objection: Object to Processing based on legitimate interests or direct marketing.
- Withdraw Consent: Withdraw previously given consent at any time without affecting the lawfulness of prior Processing.
- Non-Discrimination: Exercise your rights without fear of discriminatory treatment or reduced service quality.
To exercise any of these rights, contact us at [email protected]?subject=Tubiversity%20Privacy%20Inquiry. We will respond within the timeframe required by applicable law (typically thirty days under GDPR).
12. Children’s Privacy
The Services are not directed to individuals under the age of thirteen (13), and we do not knowingly collect Personal Information from children under 13. If we become aware that we have inadvertently collected such information, we will promptly delete it. If you believe we may have collected information from a child under 13, please contact us immediately.
13. Third-Party Links and Content
The Services may contain links to or embed content from third-party websites, including YouTube. We are not responsible for the privacy practices, security, or content of such third parties. We encourage you to review the privacy policies of any third-party sites you visit. Our retrieval of YouTube metadata is governed by the YouTube Terms of Service and Google Privacy Policy.
14. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or service offerings. Material changes will be communicated via email or a prominent notice on the Services at least thirty (30) days before the effective date. Your continued use of the Services after such changes constitutes acceptance of the revised Policy.
15. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
Tubiversity, Inc.
Email: [email protected]?subject=Tubiversity%20Privacy%20Inquiry
Postal: Attn: Data Protection Officer, Tubiversity, Inc.
© 2026 Tubiversity, Inc. All rights reserved.