Privacy Policy

Your data, and your learners’ data.

What we collect from people who use ModuleMinder, what we record when one of your courses runs, and what we never touch.

Last updated 2 October 2026

Draft for legal review. This document describes how ModuleMinder works today, but it has not yet been reviewed by a lawyer and is not yet in force.

1. Who we are

ModuleMinder is a licence management and content intelligence service for people who create and sell eLearning. It is provided by [Legal entity name], a company registered in England and Wales under number [Company number], whose registered office is at [Registered office address] (“ModuleMinder”, “we”, “us”).

This policy covers the ModuleMinder app at app.moduleminder.com, the licence server your courses talk to, and this website. For anything about your data, write to privacy@moduleminder.com.

2. The short version

  • We collect what we need to run your account: your name, business, email address and billing status. Card details go to Stripe, never to us.
  • When one of your courses runs, we record that it ran, not who ran it. The snippet never reads the learner’s name or ID from the LMS.
  • We do not sell data, show adverts, or use advertising or analytics trackers.
  • Deleted modules, licences and clients are kept for 30 days so you can change your mind, then removed for good.
  • You can export everything we hold about your account from Settings at any time.

3. If you have an account

For your account, we are the data controller. We collect:

  • Account details: your full name, business name and email address, and your password, which we store only as a salted one-way hash (scrypt). We cannot read it.
  • Your business profile: what you tell us when you sign up, such as how many courses you make a year, your team size, number of clients, main authoring tool, website and how you heard about us.
  • Settings: your time zone, alert thresholds, quiet hours and email preferences.
  • Billing: your plan, your Stripe customer and subscription references and their status, and renewal dates. Stripe collects and holds your card details; we never see or store them.
  • Sign-in records: for each signed-in session, the IP address and browser it came from and when it expires. Email verification and password reset links also record the IP address that asked for them. We use these to keep your account secure.
  • What you send us: messages to support or through our contact form.

4. People you add to ModuleMinder

You can store details of other people in your account:

  • Client records: an organisation’s name, sector, location, LMS and address, and optionally a contact’s name, role, email address and phone number.
  • Alert recipients: the name and email address of anyone you choose to receive alerts about a licence. Every alert email has a link that lets that person stop them, and we honour it straight away.

For this information you are the controller and we process it on your behalf, only to provide the service. Please make sure you are allowed to share it with us. We never contact your clients.

5. Learners taking a course

When a course carrying the ModuleMinder snippet runs on an LMS, it talks to our licence server. ModuleMinder is built so that we never learn who the learner is.

What we record

  • A random session identifier, created for that playback and linked to nothing about the person.
  • When the course started, whether it was a fresh start or a resume, and when it ended.
  • The web address and origin of the page the course runs on, and technical details of the LMS’s SCORM interface, so we can show you where your content is deployed.
  • How long the course was active.
  • If you use reporting: what the course itself reported to the LMS, meaning completion, pass or fail, score, bookmark position and question-level results. Question-level results include the answer given, so if a course asks learners to type free text, that text is included.

What we never do

  • The snippet never reads the SCORM learner name or learner ID elements (cmi.core.student_name, cmi.core.student_id and their SCORM 2004 equivalents).
  • We never ask the LMS for, or store, learner names or email addresses.
  • Reporting is shown to you as module-level totals and distributions, never as a row per person.
  • We do not set cookies in the learner’s browser or track learners across sites.

Like any web server, ours sees the IP address of each request a course makes. It is written to our operational logs, which we keep only for security and troubleshooting, and it is not stored with the usage records above.

Our role: the creator decides to deploy ModuleMinder in their course, so for this information we act as a processor on the creator’s behalf. A data processing agreement is available on request.

6. Content you upload

You do not need to give us your content: the snippet goes into your own project. If you choose to upload a published package instead (Rise 360 and Camtasia modules work this way), we store that zip so we can build a licensed copy for each client. It stays yours. We use it for nothing else, and it is deleted when you remove it or when its module is deleted.

7. How we use information, and why we’re allowed to

What we doLawful basis (UK GDPR)
Run your account, count launches, apply licences and show you reportsPerforming our contract with you
Send alerts, digests, verification and password reset emailsPerforming our contract with you
Take payment and keep financial recordsContract, and our legal obligations (for example tax law)
Keep the service secure, prevent abuse and fix faultsOur legitimate interest in running a safe, reliable service
Improve ModuleMinder using aggregated, non-identifying statisticsOur legitimate interest in improving the product
Send news and offersYour consent, which you can withdraw at any time

8. Who we share it with

We never sell personal data. We share it only with:

  • Stripe, which processes subscription payments.
  • Our hosting and infrastructure providers, who run the servers and database the service lives on.
  • Our email delivery provider, which sends alert and account emails.
  • Google Fonts: the app and this website load their typefaces from Google, so your browser’s IP address is visible to Google when a page loads.
  • Professional advisers, and authorities where the law requires it.
  • A buyer or successor, if ModuleMinder is ever sold or merged, under the same protections.

A current list of the providers we use is available from privacy@moduleminder.com.

9. International transfers

Some of our providers, Stripe among them, may process data outside the UK. Where they do, we rely on an adequacy decision or on the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, so your data has equivalent protection.

10. How long we keep it

InformationHow long
Your accountUntil you close it, then deleted within 30 days
Modules, licences, clients and their usage dataUntil you delete them, then a 30-day grace period, then permanently deleted
Uploaded packagesUntil you remove them or delete their module
Signed-in sessions30 days, or until you sign out
Verification and password reset linksUntil used or expired
Billing recordsAs long as tax and accounting law requires (usually six years)
Operational logsOnly as long as needed for security and troubleshooting

11. Cookies

The app sets one cookie, mm_session, which keeps you signed in. It is strictly necessary, cannot be read by scripts, is only sent over a secure connection, and expires after 30 days. This website sets no cookies, and neither uses analytics or advertising trackers. The snippet in your courses sets no cookies in the learner’s browser.

12. Security

All traffic is encrypted in transit. Passwords are stored as salted scrypt hashes, and verification and reset links are stored only as hashes too. Session cookies cannot be read by scripts. Each account can only ever see its own modules, clients and data, and access to production systems is restricted to the people who need it. If a breach ever affects your data, we will tell you and, where required, the Information Commissioner’s Office.

13. Your rights

Under UK data protection law you can ask us to:

  • give you a copy of your data (Settings → Data & privacy exports it as a file);
  • correct anything that’s wrong;
  • delete your data;
  • restrict or object to how we use it;
  • transfer it to another service.

Write to privacy@moduleminder.com and we will reply within one month. Learners: because we do not know who you are, we usually cannot find records about you. Please contact the organisation that gave you the course, which can ask us on your behalf.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk.

14. Children

ModuleMinder accounts are for businesses and professionals aged 18 or over. Courses may be taken by learners of any age, but we do not collect information that identifies them.

15. Changes to this policy

If we make a significant change, we will email account holders before it takes effect. The date at the top of this page always shows when it last changed.