Privacy Policy

Kordo LLC · Last updated August 13, 2026

Kordo is a training platform for organizations. This policy explains what we collect, why, and what we do with it — in plain language, because a privacy policy you can't read isn't protecting anyone.

One idea organizes everything below: your organization's training data belongs to your organization.We collect what the service needs to function, we don't sell it, we don't run ads, and we don't use your content to train AI models.

What we collect, and why

Account information. Your name, email address, organization name, and role (owner, admin, manager, or learner). This is how you sign in and how the product knows what to show you.

Content your organization creates. Courses, lessons, quizzes, policies, and any documents or images uploaded to generate or illustrate them. Documents you upload for course generation are processed transiently — we extract the text, generate your course, and discard the file rather than storing it. Lesson images and PDFs you attach to lessons or policies are stored in access-controlled, organization-scoped storage. Everything is visible only within your organization and processed solely to provide the service.

Training records.Lesson completions, quiz attempts and scores, policy acknowledgments, and certificates. Keeping these records is the product's purpose: they exist so your organization can demonstrate who completed what, and when.

Billing information. Payments are processed by Stripe. Card numbers never touch our servers; we store your subscription plan, its status, and the Stripe identifiers needed to manage it (customer and subscription IDs, seat and credit limits, billing period).

Technical information.Like nearly every web service, our hosting and error-tracking providers record IP addresses and browser information in server logs and crash reports, which we use to keep the service running and secure. Our product analytics are deliberately minimal: events are tied to a random user ID and role — never your name or email — with no session recording and no input capture. One first-party collection of our own: to rate-limit the free course preview on our homepage, we store a salted hash of the visitor's IP address — never the address itself — and routinely purge that ledger.

Cookies

We use essential cookies only: the session cookie that keeps you signed in. Our analytics do not set cookies (they use browser local storage), and we set no advertising or cross-site tracking cookies of any kind. One caveat that isn't ours: if a lesson embeds a YouTube video, playing it connects your browser to Google (we use YouTube's privacy-enhanced mode, and Google's own privacy policy applies to playback).

AI features

When your organization generates a course from a document or topic, or a learner uses the in-lesson assistant, the relevant content is sent to our AI provider — Anthropic, with OpenAI configured as a fallback — to produce the result. The same applies to the free course preview on our homepage, which anonymous visitors can use. Under both providers' commercial API terms, content submitted through the API is not used to train their models. We don't use your content to train models either.

If you were invited by your organization

If you use Kordo as a learner or manager, your organization invited you, controls what training you're assigned, and can see your training records. We process your data on your organization's behalf; questions about how your employer uses your training records should go to them first. Requests you send us that concern organization-controlled data will be handled together with your organization.

Who we share data with

Nobody, except the service providers required to run Kordo — and never for their own advertising or resale. Each processes data only to provide their function to us:

  • Supabase — database, authentication, and file storage (hosted on AWS, United States)
  • Vercel — application hosting
  • Anthropic — AI course generation and the learning assistant (OpenAI as fallback)
  • Resend — transactional email (sign-in links, invitations, reminders)
  • Stripe — payment processing
  • PostHog — product analytics (pseudonymous usage events: random ID and role, never your name or email)
  • Sentry — error monitoring

We would also disclose data if legally compelled to — and if a business transfer (merger, acquisition) ever involved your data, this policy would continue to apply to it.

One deliberate exception: certificates. Each certificate carries a verification code, and anyone who has that code can view the certificate's details — recipient name, course, organization, and date. That's the point of a verifiable certificate; share the code only with people you want to verify it.

Where data lives

Kordo is operated from the United States and data is stored and processed there. If you use Kordo from elsewhere, you're trusting us to handle it under this policy and US law.

Retention and deletion

We keep your organization's data while its account exists — including when a subscription lapses or is cancelled, so your organization can export its records or return. Deletion happens when the account is closed, which is an explicit request, not a side effect of cancelling. Training records of archived members are retained deliberately — they are your organization's compliance history, and freeing a seat is not the same as erasing the record. When an organization closes its account, its data is deleted within a reasonable period, allowing for backup cycles. To request deletion — of an account, an organization, or specific personal data — email support@getkordo.com and we'll act on it promptly, honoring the access, correction, and deletion rights that apply to you under your local law. For training records your organization controls, we'll handle the request together with your organization, as described in “If you were invited by your organization” above.

Security

All traffic is encrypted in transit. Your organization's data is isolated by per-organization access controls enforced at the database layer. The one designed exception: organization logos live in publicly addressable storage so they can render on pages like certificates — don't upload anything sensitive as a logo. Sign-in uses one-time email links or Google — we never store passwords.

Children

Kordo is a workplace product for businesses. It is not directed at children, and we don't knowingly collect data from anyone under 16.

Changes to this policy

If we make a meaningful change, we'll post it here with a new date and, for significant changes, notify account owners by email. Continued use after a change means you accept it.

Questions

Email support@getkordo.com — a person reads it.

Adapted from Basecamp's open-source policies (CC BY 4.0). © Kordo LLC, Wyoming, USA.