Privacy Policy

TechWalk is a study product, so most of what we hold is what you listened to and how you answered. This notice lists every category of it by name, why we have it, and how to get it back or get rid of it.

Effective 20 August 2026 · TechWalk — LEGAL ENTITY NAME TBC

1. Who is responsible

The data controller is TechWalk — LEGAL ENTITY NAME TBC, registered office REGISTERED ADDRESS TBC (company number COMPANY NUMBER TBC). Contact us about anything in this notice at support@techwalk.io.

We do not have a statutory Data Protection Officer — we are not required to appoint one — so data requests go to that same mailbox and are handled by the team.

2. What we collect

This is the complete list, taken from the data model rather than written from memory. We collect no special-category data, we run no advertising or cross-site tracking, and we never buy or sell personal data.

Account and profile

  • Email address (your sign-in identity, and where every code, receipt and notice goes)
  • First and last name, if you enter them during onboarding or in your profile
  • Profile photo, if you upload one — cropped to a 256px image and stored on your account record
  • An internal account identifier, the date the account was created, and the time you last signed in
  • Whether and when you finished onboarding

Settings you choose

  • Default playback speed
  • Email opt-ins for exam reminders, streak reminders and product news (nothing sends these emails yet — the setting is stored consent for when it does)
  • Your weekly listening-days goal

Billing

  • Your Stripe customer and subscription identifiers, your subscription tier, the raw billing status (active, past due, cancelled…), whether it is set to cancel at period end, and when the current period expires
  • When your welcome email was sent, and when you accepted these documents at checkout plus the version of the wording you accepted
  • Not your card details. The card fields at checkout are hosted by Stripe inside their own frames — card numbers never reach our code, our servers or our logs.

Learning progress

  • Which courses you are subscribed to, when you subscribed, and when you last opened each one
  • Your exact position in the course audio and the summary audio, which chapters you have completed, and when you last listened
  • Your best quiz score, whether you passed, how many attempts you have made and when the last one was
  • Your exam date, if you set one, and the estimated completion date derived from it
  • Per-topic and per-learning-point mastery percentages used to draw your knowledge map

Quiz and Quiz Master answers

  • Each quiz attempt: score, percentage, pass or fail, how many questions were right, when it started and finished, and how long it took
  • Each individual answer: the question and its explanation, which option was correct, which option you picked, whether you were right, how long you took, when you answered, and which topic and learning point it belonged to
  • Your mastery state per learning point: a probability that you know it, attempt and correct counts, a retention half-life, your consecutive-correct streak, when you last saw it, when it is next due, and when you first mastered it
  • Your current Quiz Master session: the learning points planned for it and how far through you are

Listening telemetry

The player writes an append-only event log — one row per continuous stretch of playback, plus sparse rows for seeks, session starts, speed changes and playback errors. This is what moves your progress bar and computes your listening time and streaks. Each row holds:

  • your account identifier, a timestamp, the calendar date on your device (so a streak is counted against your day, not ours), an event identifier and a per-listening-session identifier
  • which course, which stream (course or summary), the platform (web today) and the kind of event
  • the start and end position within the audio, the wall-clock time the stretch took, the playback speed, and which chapters it crossed
  • why the stretch ended (paused, seeked away, speed changed, track ended, a 60-second checkpoint, stream unloaded, error), and what caused it (an in-app control, the operating system's media controls, or the system itself)
  • for seeks: which gesture; for session starts: the position it resumed at; for errors: the error code and message

Aggregate statistics

  • Your current and longest daily streak, the calendar day your streak last counted, total listening time, and time listened per day of the current week

Support and diagnostics

  • The name, email address and message you send through a contact form or by emailing us, and our reply
  • Error reports from our backend functions, captured in Sentry, which can include the account identifier involved
  • Error reports from the app running in your browser, captured in the same Sentry account: what went wrong, the code it happened in, the page you were on, and — if you are signed in — your internal account identifier. Not your email address, and your IP address is not attached to them
  • Product-analytics events, from your browser and from our own systems: which pages were visited and a fixed list of milestones (a checkout started, a first minute listened, a subscription renewed). What identifies them depends on the choice in section 8 — an identifier stored on your device if you accepted, an identifier we never see if you declined
  • If you subscribed while accepting analytics: the analytics identifier your browser was using at checkout, stored on your account so the visit and the account can be recognised as the same person rather than two
  • Server logs from our backend. Log lines never contain your raw email address — where an email has to be referenced it is written as a one-way hash and/or your internal account identifier
  • Standard technical request data at our CDN and API (IP address, user agent, what was requested and when), used to serve and secure the service

Course votes

The homepage lets anyone — with an account or without one — pick the certifications they want us to build next and leave an email address for free beta access when those launch. If you have no account, this is the only thing we hold about you.

  • The email address you gave, which certification you voted for, and when you first voted — one record per certification, so voting again changes nothing and counts once
  • Nothing else. No name, no IP address and no link to an account is stored on a vote, and a vote is never readable from the website by anyone, including you.

3. Why, and on what lawful basis

What we do with itWhich dataLawful basis (GDPR Art. 6)
Create and run your account, sign you in, serve the audio you paid forAccount, settings, secure-media credentialsPerformance of our contract with you — Art. 6(1)(b)
Save your place, track progress, score quizzes, adapt Quiz Master to what you find hard, draw your knowledge mapLearning progress, quiz and Quiz Master answers, mastery, listening telemetryPerformance of our contract with you — Art. 6(1)(b)
Take payment, renew and cancel your subscription, prove you accepted these termsBilling, consent recordPerformance of our contract — Art. 6(1)(b); legal obligation for tax and accounting records — Art. 6(1)(c)
Send transactional email: sign-in codes, activation, receipts, service noticesEmail addressPerformance of our contract with you — Art. 6(1)(b)
Send optional exam reminders, streak reminders or product newsEmail address and the relevant opt-inYour consent — Art. 6(1)(a), withdrawable at any time in Account → Settings
Count which certifications people want next, and email you free beta access when one you voted for launchesCourse votesYour consent — Art. 6(1)(a), given by submitting the form and withdrawable by emailing us
Keep the service working: error monitoring, debugging, capacity and abuse preventionDiagnostics, logs, technical request dataOur legitimate interest in a secure, working service — Art. 6(1)(f)
Understand which content works and improve itAggregate statistics and telemetry, plus visitor countsOur legitimate interest in improving the product — Art. 6(1)(f)
Recognise your device across visits, record how the screens behaved, and link analytics to your accountThe analytics identifier stored on your device, session replaysYour consent — Art. 6(1)(a), given or refused on the banner and changeable at any time (section 8)
Count visits and measure the same milestones when you have NOT consented to that identifierCookieless counts; the events our own systems record about your subscription and your learning milestonesOur legitimate interest in knowing whether the service works — Art. 6(1)(f). Nothing is stored on your device and no profile follows you between days
Answer your support messagesSupport correspondenceOur legitimate interest in supporting our users — Art. 6(1)(f)

You can object to processing we do on the basis of legitimate interests — see section 9. Withdrawing consent for the optional emails does not affect anything else.

Automated decisions

Quiz Master decides which question to show you next from a statistical model of what you already know. That is automated, but it only changes which practice question appears — it produces no legal or similarly significant effect, so the Art. 22 rules on automated decision-making do not apply. We do no profiling for advertising.

4. AI processing

When you have answered every reviewed question for a learning point, Quiz Master generates a new one using a large language model hosted by Amazon Bedrock. The prompt we send contains the learning point's identifier and description, the topic, the target difficulty, a single number representing how well you currently know that point, and the questions that learning point already has, so the new one is not a repeat. It contains no name, no email address and no account identifier — nothing in the prompt identifies you.

Bedrock runs the request inside AWS. AWS does not use content submitted to Bedrock to train its models or share it with model providers, and we have not enabled any prompt-logging feature. The generated question is stored in our own question bank, marked as pending review, and may be served to other learners too.

See the Terms of Service for what this means for accuracy, and how to report a question that looks wrong.

5. Who else processes it

These are everyone who processes personal data on our behalf. There are no others — no advertising network, no CRM, no email marketing platform, and no analytics vendor that receives personal data.

ProcessorWhat they do for usWhere
Amazon Web Services (privacy notice)All hosting: sign-in identities, the API and databases, audio storage and delivery, our backend functions, outbound email, question generation, and logseu-west-1 (Ireland); CDN edge locations worldwide
Stripe (privacy notice)Card processing, subscriptions, renewals, refunds, invoices and the self-service billing portalEU and United States
Sentry (privacy notice)Error monitoring, both in our backend functions and in the app running in your browser. Browser reports carry the error, the page it happened on and your account identifier — not your email address, and not your IP addressUnited States
PostHog (privacy notice)Product analytics. Page visits and a fixed list of product milestones, from your browser and from our own systems. Session replay — a reconstruction of how the screens behaved, with everything you type masked — happens ONLY if you accepted in section 8, as does linking any of it to your account identifier. It receives your IP address to work out an approximate country, and never your name or email addressEuropean Union (EU cloud)

We disclose personal data outside this list only where the law requires it, or to professional advisers under a duty of confidence. If we are ever acquired or merged, your data would transfer with the service and we would tell you first.

6. Where your data lives

Your account, your learning data and your telemetry are stored and processed in AWS's Ireland region (eu-west-1). That is inside the EU, so no transfer safeguard is needed for the bulk of what we hold — a deliberately favourable position for an EU-facing product.

  • Question generation uses an EU-resident Bedrock inference profile, so prompts stay within AWS's European regions.
  • Course audio is delivered by a global CDN. A request from outside the EU is served by an edge location near you, so the request itself (your IP address, your temporary playback credentials, what you asked for) is handled there.
  • Stripe processes payments through its European entity and may transfer data to its US affiliates. Sentry is US-based. Both operate under data processing agreements with the transfer safeguards set out there — Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
  • Product analytics goes to PostHog's EU cloud and stays in the EU, whichever answer you gave in section 8.

7. How long we keep it

WhatHow long
Account, settings, learning progress, quiz and Quiz Master answers, mastery, listening telemetryFor as long as your account exists. Erased within 30 days of a verified deletion request
Billing records (payments, invoices, tax data) held by us and by StripeRetained for the statutory accounting and tax period even after the account is deleted — typically six years
Your recorded acceptance of these documentsKept while the subscription is live and afterwards for as long as a payment dispute or claim remains possible
Server logs30 days in production; 7 days in our development environments
Error reports in Sentry, from our backend and from your browserSentry's configured event-retention window (90 days by default)
Product analytics in PostHog (and session replays, if you accepted them)PostHog's configured retention window (session recordings default to 30 days). Anything linked to your account is erased with it; withdrawing consent stops the identifier and any new replay immediately
Support emailKept in the support mailbox while it is useful, then deleted
Course votesKept while the vote is still useful — until the certification you voted for has launched and we have emailed you about it. Deleted at any point on request
Database backupsDeleted rows remain restorable from point-in-time backups until they age out of the recovery window (up to 35 days), after which they are gone from backups too

8. Cookies and device storage

One thing here is optional, and we ask before it happens: storing an analytics identifier on your device. Everything else is strictly necessary to run the service you asked for. Declining does not switch measurement off — it switches it to a form that stores nothing on your device, keeps no profile of you between days, records no session replay, and is never linked to your account. Below is everything in both categories.

Optional — only if you accept

WhatWhereWhat it is for
ph_… (a cookie and a matching local-storage entry, set by PostHog)Cookie and local storage, first-partyA random id for this browser, so a returning visit can be recognised as the same one and a journey through the app joins up. Accepting also enables session replay and lets your activity be linked to your account. Decline and none of this is set
techwalk_consentLocal storageYour answer to that question, so we stop asking and so a 'no' is actually honoured. Strictly necessary in its own right: a consent choice that is not remembered is not a choice

If you decline

We still count visits and the same short list of product milestones, but cookielessly: PostHog derives a temporary identifier at its end from your IP address and browser, using a salt that is rotated and discarded, so nothing is stored on your device and nothing identifies you from one day to the next. No session replay runs, and none of it is attached to your account. That processing rests on our legitimate interest in knowing whether the service works (section 3), not on your consent — because it does not touch your device, which is what the consent rule below is about.

Separately, and either way, our own systems record the facts of your subscription — a checkout completing, an account being created, a renewal, a failed payment, a cancellation — and a short list of learning milestones: starting a Quiz Master session; the moment a topic or a whole course reaches our “mastered” mark; finishing a course recording or its summary; and passing a total-listening-time milestone (1, 5, 10 and 25 hours). Those come from our servers, not from your browser, so they are recorded against your account either way; they are how we know the paid service is working at all. We do not record what you answered or what you were listening to at any moment — only that a milestone was reached. They are covered by the same section 3 entry.

You can change your mind at any time, and it takes effect immediately: “Cookie preferences” in the site footer, or Account → Settings → Data & privacy if you are signed in. Turning it off stops the identifier and the replay there and then, and deletes nothing you would want kept.

Strictly necessary — no choice to make

WhatWhereWhy it is strictly necessary
Sign-in tokens (entry names beginning CognitoIdentityServiceProvider.)Local storageWithout them you are not signed in. Written only after you sign in; cleared when you sign out. They stay on your device and are never sent to us automatically — your browser attaches them to nothing
CloudFront-Policy, CloudFront-Signature, CloudFront-Key-Pair-IdCookies, first-partyShort-lived credentials that let the CDN release the paid audio to you and nobody else. Set only for signed-in subscribers; they expire on their own
__stripe_mid, __stripe_sidCookies, set by Stripe on the checkout page onlyStripe's fraud prevention on the payment form. Taking payment safely is part of the service you asked for
themeLocal storageRemembers the light/dark choice you made. It exists only because you set it

Why there is nothing else

  • No advertising, heatmap or A/B-testing script is loaded anywhere in the app, and no third party is allowed to track you from here to another site.
  • Error monitoring runs in your browser as well as on our servers. It reports crashes so we can fix them; it does not record your screen and it stores nothing on your device, so it is not part of the choice above.
  • Fonts are self-hosted: they are downloaded at build time and served from our own domain, so your browser never contacts a font provider.
  • The one development-only script we use is compiled out of production builds entirely.

The split above is Article 5(3) of the ePrivacy Directive (as implemented in Ireland by S.I. 336/2011): storing information on your device, or reading what is already there, needs your consent unless it is strictly necessary for the service you explicitly asked for. Sign-in tokens, the CDN credentials that release your audio, Stripe's fraud check on the payment form, your theme choice and the record of this decision all clear that bar. An analytics identifier does not — which is why it is a question rather than an announcement, and why declining costs you nothing: every feature works identically either way.

You can clear or block any of these in your browser at any time. Clearing the sign-in tokens signs you out; blocking them, or the CDN cookies, means you cannot sign in or play the audio.

9. Your rights, and how to use them

Under the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected. Your name and photo are editable yourself in Account → Profile.
  • Erasure — have your data deleted; see section 10.
  • Portability — receive the data you gave us, and the data generated by your use of the service, in a machine-readable format.
  • Restriction — ask us to pause processing while a dispute about accuracy or legitimate interests is resolved.
  • Objection — object to processing we base on legitimate interests.
  • Withdraw consent — for the optional emails, in Account → Settings, at any time.

To use any of them, email support@techwalk.io from the address on your account — that is how we verify a request is really yours, and we will ask you to re-send from it if it arrives from anywhere else. We respond within one month, and tell you if a complex request needs the two-month extension the GDPR allows. There is no charge.

You can also delete some of your own data without asking us: Account → Settings → Data & privacy erases your course progress, your quiz answers, or your Quiz Master data, each independently and immediately.

If you have no account and only voted for a course, the address you voted with is the address to email us from — it is the only thing that ties the vote to you, and it is how we verify the request. Tell us and we will delete the vote.

If you think we have handled your data badly, please tell us first — but you have the right to complain to the Irish Data Protection Commission (www.dataprotection.ie) or to the supervisory authority where you live or work.

10. Getting your account erased

There is no self-service delete button, because deletion has to cancel your live payment subscription as well as remove your sign-in identity and your data — a one-click control that got any part of that wrong would leave people billed for accounts they can no longer reach. We run it as an audited manual process instead.

Email support@techwalk.io from your account address. We confirm what deletion means, wait for your explicit go-ahead, then:

  • cancel any live subscription with Stripe immediately, so billing stops first
  • delete your sign-in identity, so nobody can sign in as you
  • delete your listening telemetry, every question and quiz attempt, your mastery records, your Quiz Master sessions, your course subscriptions and your account record
  • delete any course votes cast from your address
  • confirm to you, in writing, that it is done

This completes within 30 days of your request. Two things survive it, and we would rather say so than pretend otherwise: billing and tax records that we are legally required to keep (see section 7), and rows inside database backups until those backups age out of the recovery window — unreachable by the service from the moment of deletion.

11. Security

  • Everything is encrypted in transit, and at rest in AWS.
  • The API enforces ownership per record: your progress, answers and mastery rows are readable only by your own signed-in session, and several of them are not client-readable at all.
  • Course audio is not on the public internet — it is released by the CDN only against short-lived signed credentials issued to a subscribed, signed-in account.
  • Card data never touches our systems; it goes straight from your browser to Stripe.
  • Our logs are written not to contain your raw email address.
  • Access to production data is limited to the people who need it and is done through audited AWS roles.

No service is perfectly secure. If a breach affects your personal data and is likely to be a risk to you, we will notify the Irish Data Protection Commission within 72 hours and tell you where the law requires it.

12. Children

TechWalk is for adult professional learners and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has an account, email us and we will remove it.

13. Changes to this notice

We will update this notice when what we do changes — a new feature, a new processor, a new purpose. The effective date at the top always reflects the current version. If a change materially affects you, we will email you before it takes effect rather than quietly republish the page.

Questions about this document? Email support@techwalk.io — we usually reply within a day.