We teach the law, we don't practice it — real legal education, not legal advice — explore the courses

Legal

Privacy Policy

Last updated: 9 September 2026

This policy explains what personal data Legally Smart Teens ("we", "us") collects when you use our website and courses at legallysmarteens.com (the "Service"), why we collect it, who we share it with, and the choices and rights you and your parent or guardian have over it. Because our learners are 13–18 years old, we've written this to be as plain and specific as possible rather than generic legal boilerplate.

Note on this document: this policy is drafted to accurately describe how the Service actually works today. It should still be reviewed by a qualified data-protection solicitor for your specific country/region before you rely on it as your final, binding policy — in particular to confirm the legal entity name, registered address, and governing law/regulator that apply to your business, and to fill in the bracketed details below.

1. Who this policy covers

This policy applies to learners, parents/guardians, instructors, and admins who use the Service. The data controller is [Company legal name], of [registered business address]. For any privacy question or request, contact info@legallysmarteens.com.

2. Information we collect

Account information

Guardian/parental consent information (ages 13–15)

If you tell us you're 13–15, the Service requires a parent or guardian's consent before you can enrol in a course. We collect your guardian's name and email address, email them a one-time consent link, and record the date and time they confirm it. This record exists specifically so we can show, if ever asked, that consent was actually given — it is not used for any other purpose.

Learning activity

Payment information

Purchases are processed by Fygaro, our payment provider — we redirect you to their secure checkout and never see or store your card number. We do keep a record of what was purchased, the amount, currency, and order status, so we can grant course access, handle refunds, and meet our accounting/tax obligations.

Communications

Live classes

Some courses include live sessions. Sessions hosted in-app use Jitsi (an open, embeddable video tool) — we don't record these ourselves. Some instructors instead schedule a session on Zoom or Google Meet and share a join link; those platforms have their own privacy policies that apply once you join.

Technical information

Like virtually every website, our hosting provider (Vercel) automatically logs standard technical data — IP address, browser type, pages visited, and timestamps — for security and reliability purposes. We use a small number of first-party cookies to keep you signed in and remember your theme preference; we do not use third-party advertising or tracking cookies.

3. How we use your information

We do not sell your personal data, and we do not use it to serve third-party advertising.

4. Who we share information with

We share the minimum data necessary with the following processors so the Service can function:

Instructors can see the names and progress of learners enrolled in their own courses, and admins can see platform-wide data needed to run and support the Service. We do not share your data with any other third party except where required by law.

5. International data transfers

Our database is hosted in the EU (Ireland). If you access the Service from outside the EU, your data will be transferred to and processed there.

6. How long we keep your data

We keep account and learning data for as long as your account is active. Order and payment records are kept for as long as required by applicable tax and accounting law, even after an account is deleted. Guardian-consent records are kept for as long as the associated account requires them, as evidence that consent was properly obtained.

7. Your rights, and your child's data

The Service is built with self-service data rights in mind:

If you are a parent or guardian and want to review, correct, or delete your child's data, or withdraw consent you previously gave, contact us at the email above and we will act on your request. If you believe your child (under 13) has created an account without your knowledge, please contact us immediately so we can remove it — the Service is not intended for children under 13, and account sign-up does not offer an age band below 13.

You may also have the right to lodge a complaint with your local data protection authority (for example, the ICO in the UK, or your national authority under EU GDPR).

8. Security

Data is encrypted in transit (TLS) and access to it is restricted by row-level database security policies, so, for example, one learner's data is never visible to another learner. Instructor and admin accounts can enable two-factor authentication. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, industry-standard steps to protect your information.

9. Changes to this policy

We may update this policy as the Service changes. Material changes will be announced via the in-app announcements feature or by email. The "last updated" date at the top of this page always reflects the current version.

10. Contact us

Questions about this policy, or a privacy/safeguarding concern you'd rather not put in the public contact form? Email info@legallysmarteens.com.