← Back

Privacy Policy

Last updated: June 2026

1. Information We Collect

We collect information you provide directly and information generated by your use of the Service:

  • Account info — your name, email address, and profile picture, obtained when you create an account or sign in. Authentication is handled by Supabase Auth (email/password or Google OAuth).
  • Usage data — pages visited, features used, session timestamps, and device or browser type.
  • Progress data — lessons completed, XP earned, streaks, and quiz responses, stored so we can deliver a personalised learning experience.

2. How We Use It

We use the information we collect to: provide and improve the Service; personalise your learning path and track your progress; send you important account or subscription notifications; diagnose technical problems and ensure security; and comply with legal obligations. We do not sell your personal data to third parties.

3. Data Storage

Your data is stored in a PostgreSQL database managed by Supabase and hosted on Amazon Web Services. Data is encrypted in transit (TLS) and at rest. Row-level security policies ensure each user can access only their own records.

4. Cookies and Analytics

We use session cookies strictly necessary for authentication. We also use PostHog, a product-analytics provider, to understand aggregate usage patterns and improve the Service (see Third-Party Services below). You can disable cookies in your browser; doing so will prevent you from staying signed in.

5. Third-Party Services

We rely on a small number of trusted sub-processors to run the Service:

  • Supabase — our authentication provider and database host (see Data Storage above). Supabase processes your account and progress data on our behalf.
  • Google OAuth — an optional sign-in method. If you use it, Google may collect data per their own privacy policy.
  • Stripe— for payment processing. Stripe handles all card data; we never see or store raw payment details. Stripe's privacy policy applies to billing data.
  • PostHog — our product-analytics provider. PostHog processes usage and event data on our behalf to help us understand and improve the Service.

6. Public Leaderboard (Opt-In)

Daily Scaffold has a public leaderboard. Your stats and a username are shown there only if you opt in — it is off by default. When enabled, the username you choose and your ranking metrics (such as XP and streak) are visible to other users and may be publicly accessible.

Please don't use a username that reveals personal information you'd rather keep private. You can change your username, leave the leaderboard, or opt back out at any time from the Leaderboard page; doing so removes your entry from public view.

7. Your Rights

Under GDPR and similar laws, you have the right to access, correct, export, or delete your personal data at any time. You can:

  • Request a copy of your data, or deletion of your account and all associated data, by emailing us at hello@dailyscaffold.com.
  • Contact us to correct inaccurate information or to raise a complaint.

8. Data Retention

We retain your account and progress data for as long as your account is active. If you delete your account, we will remove your personal data within a reasonable period, except where we are required by law to retain certain records longer (for example, billing records kept for tax purposes).

9. Contact Us

For privacy-related questions, requests, or complaints, contact our privacy team at hello@dailyscaffold.com.