Skip to content
cursare
PlatformDocs
Sign inGet started

Privacy Policy

Last updated July 27, 2026

CURSARE TECNOLOGIA LTDA ⁠-⁠ ME ⁠-⁠ CNPJ 45.583.539/0001-59 (“Cursare”) operates the platform and is responsible for this policy. This policy explains what personal data Cursare collects, why we collect it, and the choices you have. It applies to cursare.com, every organization page we host, and the Cursare dashboard. We process personal data under Brazil's General Data Protection Law (LGPD) and, where it applies, the European Union's General Data Protection Regulation (GDPR) and other applicable privacy laws.

Who controls your data

  • Cursare is a controller for the data needed to create and manage accounts, operate and secure the platform, provide support, administer staff seats and enrollment-volume ranges, keep required records, and meet our own legal obligations.
  • Organizations are controllers when they decide why and how to use learner data for their courses, enrollment questions, communications, analytics, or marketing. Cursare processes that data on their behalf where we provide the underlying platform, while remaining a separate controller for our own purposes described above.
  • Depending on your request, we may direct you to the relevant organization or work with it to respond. This division of roles does not reduce any responsibility imposed on Cursare or the organization by applicable law.

Information we collect

  • Account data — name, email address, password (stored only as a hash), the applicable age-account state, and anything an adult adds to a profile such as an avatar or bio. For a supervised minor account, we use only a broad age band, jurisdiction, assurance level and validity dates; we do not keep an exact birth date.
  • Learning activity — the courses you enroll in, your progress, quiz answers, reviews you write, and posts in course cohorts. This is what makes the product work: your progress has to live somewhere.
  • Organization data — if you run an organization: its name, branding, members, courses, and sales records.
  • Payment data — payments are processed by Stripe. Cursare never sees or stores your card number; we keep transaction details, billing identity, tax information, country, and records needed for receipts, refunds, payouts, fraud prevention, and accounting.
  • Communications and content — support requests, reviews, cohort posts, files, and other information you choose to submit through the service.
  • Technical and usage data — IP address, device and browser details, requested pages, timestamps, cookie or session identifiers, and security and diagnostic logs.

Purposes and legal bases

  • Contract and requested steps — to create accounts, provide enrollments and course access, record progress, issue certificates, process purchases and refunds, provide support, and send service messages such as verification, password reset, invitation, enrollment, and completion emails.
  • Legal obligations — to maintain tax, billing, transaction, and compliance records and respond to lawful requests from public authorities.
  • Legitimate interests — to secure and improve Cursare, prevent fraud and abuse, debug the service, understand product performance, enforce our terms, and establish or defend legal claims, after considering your rights and reasonable expectations.
  • Consent — for marketing communications, non-essential analytics or advertising technologies where consent is required, and other optional uses we explain when asking. You may withdraw consent at any time without affecting earlier lawful processing.
  • Instructors see the learning activity of learners enrolled in their courses so they can teach, provide support, and understand course performance. They do not receive your activity from unrelated organizations.

When information is required to provide a requested feature or meet a legal requirement, failing to provide it may prevent us or the organization from providing that feature.

Sensitive data and minors

Ordinary self-service signup remains for adults. A minor may use Cursare only through the dedicated supervised-account flow after an approved age and guardian-assurance process, a verified responsible adult, and affirmative authorization. The platform, organization and exact course offer must each be enabled and reviewed. See the child-friendly privacy notice.

We keep the normalized decision needed to operate the account, but not identity-document images, biometric templates, exact birth dates, or raw assurance-provider responses in ordinary product storage. A minor account cannot use public profiles, reviews, cohort discussions, intake file uploads, direct marketing, behavioral advertising, or organization analytics and ad tags. Its guardian can see the child's courses, progress, certificates and a minimal daily learning-time total, but cannot impersonate the child or edit learning progress. A child can see and dispute the relationship, report safety, privacy, age or content concerns, and transition the same account to adulthood after an approved review.

Cookies

Short links count clicks on the server, including the first visit before a privacy choice. Known bots and prefetches are excluded. A keyed hash of the IP address and browser user agent, scoped to each organization, estimates unique visitors and deduplicates clicks on the same link within each clock hour. Raw IP addresses are not stored in these events. These identifiers are pseudonymous, not anonymous, and are not linked to accounts by click counting. Network or browser changes can affect the estimates.

On an initial visit to a Cursare course, a signed context in the URL fragment preserves the link and variant for up to 30 minutes. Accepting marketing on that page creates the attribution cookie without counting another click. Rejecting optional storage creates no attribution cookie.

We use first-party cookies only where the product needs them: your session, language, security, and theme preference. These are necessary for the service. On the institutional pages of cursare.com, the technical Google Tag Manager container loads to apply Google Consent Mode and the visitor's recorded choices. It starts with analytics and advertising storage denied. Before authorization, consent-aware tags may send Google only cookieless technical signals such as consent state, timestamp, user agent, and referrer. Optional cookies, storage, and measurement are enabled only when the visitor authorizes the corresponding category. Cursare does not use behavioral advertising or cross-site tracking for its own advertising.

Organizations may enable Google Analytics or Google Tag Manager on their public pages. The consent state continues to control the storage and measurement that are permitted. This technical protection does not remove the organization's duty to use each tool lawfully and provide required information. These tools are suppressed in authenticated minor sessions regardless of organization configuration.

Who we share data with

We never sell personal data. We share it only with the processors that run the service:

  • Stripe — payment processing and payouts.
  • Resend — transactional email delivery.
  • Vercel — application hosting and file storage.
  • Cloudflare — video streaming, when an organization connects its own Cloudflare Stream account.
  • Google — delivery of the technical Tag Manager container and, according to your choices, Analytics and campaign attribution.

When you enroll in a course, the organization that publishes it receives your name, email, your answers to its enrollment questions, and your progress in that course — it needs those to teach you. For a minor learner, the organization does not receive assurance evidence, guardian private data, detailed usage history, or restricted safety evidence through its ordinary learner tools. We may also disclose data when required by law, to protect rights and safety, or as part of a corporate transaction subject to appropriate confidentiality and legal safeguards.

International transfers

Cursare and its service providers may process personal data outside your country, including in the United States and the European Economic Area, depending on where their infrastructure and support teams operate. Where a transfer requires a legal safeguard, the parties must use an applicable mechanism such as an adequacy decision, the standard contractual clauses approved by Brazil's data protection authority, the European Commission's standard contractual clauses, or another legally recognized safeguard. You may contact us for information about the mechanism relevant to your data and, where the law provides, a copy of the applicable safeguards.

Your rights

  • Confirm whether we process your data and obtain access to it.
  • Correct incomplete, inaccurate, or outdated data.
  • Request anonymization, blocking, restriction, or deletion where the legal requirements are met.
  • Request portability in a structured format where applicable.
  • Learn which entities receive your data and obtain information about international transfers.
  • Object to processing, withdraw consent, or request deletion of consent-based data, without affecting lawful retention or processing on another legal basis.
  • Request review of a decision based solely on automated processing when the law grants that right. Cursare may use automated tools to assist with fraud, security, abuse, and moderation, but does not currently make decisions producing legal or similarly significant effects solely by automated means.
  • Complain to the ANPD or your competent European data protection authority.

You can edit your profile or delete your account from Settings → Profile. For any other request, email privacy@cursare.com. We may verify your identity before acting. We respond within the period required by applicable law: under the LGPD, confirmation and simplified access may be immediate and a complete access statement is provided within 15 days; under the GDPR, requests are generally answered within one month. Rights are not absolute, and we will explain any lawful reason for denying or limiting a request.

Retention and security

We keep account and learning data while your account, enrollment, or the relevant course relationship remains active. We retain transaction, tax, security, audit, and dispute records for the periods required by law or reasonably necessary for their stated purposes. Minor daily usage aggregates contain only a local date, time zone, total active seconds, limit snapshot and block time; they do not contain page or lesson history and are scheduled for deletion after the configured retention period (90 days by default). Minimized age, guardian, audit and safety records follow their documented legal, dispute and safeguarding retention schedule; raw assurance evidence is not retained in normal operation. After deletion, limited copies may remain temporarily in backups until they are overwritten; data may also be anonymized so it no longer identifies you. We review retention using the purpose, legal requirements, sensitivity, volume, and risk of the data.

We use technical and organizational safeguards appropriate to the risk, including encryption in transit, hashed passwords, access controls, logging, and optional two-factor authentication. No system is completely secure. If a personal-data incident requires notice, we will notify the relevant authority, affected controller, and affected people within the deadlines and in the manner required by applicable law.

Contact, complaints, and changes

Contact Cursare's privacy channel at privacy@cursare.com. If your concern relates to an organization's course, you may also contact that organization directly. You may petition the ANPD after first contacting the controller, or complain to the competent supervisory authority where the GDPR applies. If we materially change this policy, we will announce the change before it takes effect when required.

cursare

The complete platform for teaching online — learn from people who do.

Get started
ProductPlatformCommon questionsDocs
FeaturesCourse editorCommerceAffiliatesCohorts & discussion
DevelopersDevelopersDeveloper guideAPI reference
© 2026 Cursare
AboutPrivacyTerms

Your privacy choices

The technical Tag Manager container is required to apply your choices. Analytics and marketing cookies and storage remain optional and stay off until you authorize them. Privacy Policy.

Sign-in, security, core functions and consent enforcement.

Audience measurement such as Google Analytics.

Marketing storage, campaign attribution and optional tags.