Privacy Policy
Last updated: 14 August 2026
This policy explains what personal data the Cosmic LMS cloud service collects, why, and what you can do about it. The data controller is Individual Entrepreneur Nikita Kulachenkov (State Register of Legal Entities of the Republic of Armenia, registration number 273.1427529), contactable at contact@cosmiclms.app.
If you run the platform on your own infrastructure, we receive nothing and this policy does not apply to you.
1. Data we collect
Account data: name, email address, password (stored only as a hash), role, and the school you belong to. If you sign in with Google, we receive your name, email address and profile picture from Google instead of a password.
Content you upload: courses, lessons, files, videos and any material you add to them.
Learning data: which lessons a student opened and completed, submitted work, grades, test results and issued certificates.
Usage data: how much storage and bandwidth your school consumes — this is what the subscription is billed on.
Technical data: IP address, browser and device information in server logs, kept for security and abuse investigation.
2. Why we process it
To provide the Service — you cannot have an account, a course or a certificate without the corresponding data.
To bill subscriptions and calculate usage above plan allowances.
To send service email: address verification, password reset, notifications you enabled, and important announcements about the Service.
To keep the platform secure and investigate abuse.
The legal bases are performance of a contract with you, our legitimate interest in operating and securing the Service, and your consent where consent is required.
3. Cookies
We set one essential cookie holding your session token. It is host-only and cannot be read by other subdomains. Without it you cannot stay signed in.
We do not use advertising or cross-site tracking cookies.
A school administrator can connect their own Google Analytics account to their school. When they do, Google Analytics runs for visitors of that school and is subject to Google's privacy terms. It is off unless the school turns it on.
4. Who else processes the data
Railway — hosting of the application servers and the database.
Amazon Web Services — file storage (S3, Ireland region) and transactional email delivery (SES).
Cloudflare — DNS and email routing for our own domain.
Lemon Squeezy — payment processing as merchant of record. They receive your billing details directly; we never see or store your card number.
Bunny.net — video delivery, where a school uses video hosting.
Sentry — error reports, where enabled. Reports may include the URL, the user identifier and a stack trace.
Google — sign-in, if you choose to sign in with a Google account.
We do not sell personal data and we do not share it for advertising.
5. Where data is stored
Uploaded files and email delivery are handled in the European Union (AWS, Ireland). Application hosting is provided by Railway, and error reporting by Sentry, in the regions those providers operate.
Where data leaves the European Economic Area, it is transferred under the providers' standard contractual clauses.
6. How long we keep it
Account and learning data are kept while the account exists. When you delete your account, we delete it, along with your content, within 30 days, except where we must keep records for accounting or legal reasons.
Server logs are kept for a short period, typically no more than 90 days.
Payment records are kept by Lemon Squeezy for as long as their own obligations require.
7. Your rights
You can request access to your data, correction of it, deletion, a machine-readable export, or restriction of processing. Write to contact@cosmiclms.app and we respond within 30 days.
You can unsubscribe from non-essential email at any time. Service email required to operate your account cannot be switched off while the account exists.
If you are in the European Union and believe we handle your data unlawfully, you can complain to your national data protection authority.
8. Students of a school
If you are a student, the school that enrolled you decides what courses you take and can see your progress, submitted work and grades. For that data the school is the controller and we act on their instructions.
Requests to delete or correct such data are best sent to your school first; we will help them carry it out.
9. Children
The Service is not directed at children under 16. A school enrolling minors is responsible for obtaining the consent required in its own jurisdiction.
10. Changes
If we change this policy in a way that materially affects you, we notify you by email at least 30 days in advance. The current version is always published on this page with its date.