Privacy policy
Last updated: September 28, 2026 · Version 2026-09-28.1
At Marsof Academy we process the minimum personal data needed for you to study, and we only send you marketing emails if you agree to them. Here we explain who processes it, why, on what legal basis, who receives it, how long it is kept and how to exercise your rights, under the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Spanish Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD).
Summary
- Controller: Carlos Gálvez Carrillo (carlosgc@marsofacademy.com).
- Why: to provide the academy (account, progress, tutor, Community and, if you go Pro, billing), keep it secure and comply with the law.
- We only email you news, new courses and offers if you agree (checkbox in Settings → Emails), and you can unsubscribe whenever you want.
- We don't sell your data, we don't do commercial profiling, and we don't use third-party analytics or trackers.
- Your data is stored on a server in the European Union and only reaches the providers listed below.
- You can download your data and delete your account yourself in Settings → Privacy and your data.
Data controller
- Controller: Carlos Gálvez Carrillo
- Tax ID (NIF/CIF): 49080222Q
- Address: Calle Corín Tellado, 19, 21130 Mazagón, Moguer (Huelva)
- Contact email, also for data protection: carlosgc@marsofacademy.com
We haven't appointed a data protection officer because, given the type and volume of data we process, it isn't mandatory (art. 37 GDPR and art. 34 LOPDGDD). For any question about your data, write to the contact email.
What data we process
- Account: email, display name, password (we only store its Argon2id hash: nobody can read it), language, preferences (theme, career goal, study hours) and the dates you signed up, verified your email and last signed in. If you signed up with an invite code, which one you used.
- Study: progress, exercise attempts and their results, quiz and exam answers, reviews, hints used, points (XP), achievements, notes, bookmarks, Workshop files, projects, explanations in your own words, interview-prep answers, placement test result and certificates.
- Community: the threads and replies you post, your votes, the threads you follow, your notifications, your reports and, if any, moderation measures on your account.
- Friends and chat: your friendships and requests, the people you block, your social privacy (who can send you requests and whether you appear in search), the messages you send (direct messages to your friends and in the course rooms), what you've read and, if any, your reports and chat suspensions. Images and files can't be sent. Messages are encrypted in transit (HTTPS) and stored on our server, but they are not end-to-end encrypted.
- AI tutor: the text of your questions and, as context, the code, error and tests of the exercise you're working on. We don't store the content of those conversations on the server; only a usage record (date, feature, provider, model and number of tokens) to enforce limits and control costs.
- Technical: the session cookie and, on the server, the hash of your sessions and CLI tokens. Your IP address is only used in memory, for a few minutes, to slow down abusive sign-in attempts: it isn't stored in the database or in the logs.
- Initial assessment: your answers to the assessment you take when you join the academy, the score calculated from them (1 to 10, also by area), when you took it and how long it took. It's used only so the academy knows the level of people starting out and for aggregate statistics; it doesn't change anything in your studies, it's never shared with anyone and it's deleted with your account.
- Messages with the academy: the messages the academy team sends you personally and your replies (and, if a copy is sent by email, that email).
- Communications: the emails you send us and our replies and, if you agree to receive news, that consent and the date you gave it.
We don't ask for special categories of data (health, beliefs, origin, etc.). Please don't include them in your messages, in the tutor or in your files.
Why we use it and on what legal basis
Providing the service you ask for
Creating and keeping your account, saving your progress, preparing your plan and reviews, grading exercises and exams, issuing your certificates, answering you through the tutor and showing the Community.
- Legal basis: performance of the contract you accept when signing up (art. 6.1.b GDPR).
Necessary emails
Confirming your email, resetting your password, warning you about security changes on your account and, if you go Pro, confirming your purchase. These emails aren't advertising: you get them even if you don't accept news.
- Legal basis: performance of the contract (art. 6.1.b GDPR) and, for the purchase confirmation, legal obligation (art. 6.1.c GDPR, together with art. 98.7 TRLGDCU).
Marketing emails (only if you agree)
If you tick «I want to receive news, new courses and offers by email» in Settings → Emails, we'll write to you from time to time with academy news, new courses and offers from Marsof Academy. Never from third parties. We keep the date you agreed.
- Legal basis: your consent (art. 6.1.a GDPR and art. 21 of the Spanish Law 34/2002 on information society services, LSSI).
- How to withdraw it: whenever you want, free of charge and without giving reasons, by unticking the box in Settings → Emails or with the one-click unsubscribe link in each of those emails (no need to sign in). Withdrawing it doesn't affect earlier emails.
Community and moderation
Publishing what you write, notifying you of replies and moderating: automatic filters (banned words and posting limits), reports and review by moderators. Moderation actions are logged.
- Legal basis: performance of the contract (art. 6.1.b GDPR) and legitimate interest in keeping a safe space and complying with the rules on digital services (art. 6.1.f GDPR).
Security and abuse prevention
Limiting sign-in attempts, protecting accounts, detecting abuse, making backups and fixing incidents.
- Legal basis: legitimate interest in protecting the service and its users (art. 6.1.f GDPR). You can object; we'll consider your case, although some measures are essential for the service to be secure.
Running the academy and helping you
Whoever runs the academy can see each student's record in order to give support, manage access and payments (for example, a refund or a gifted access) and fix incidents: account data (display name, email, language, sign-up and last sign-in dates, whether the email is verified and whether you accept news), progress per course, study time, XP and certificates, access type (free or Pro) and subscription, payments and open sessions (number and type of device, to detect shared accounts). They can't see your password or your card details.
- Legal basis: performance of the contract (art. 6.1.b GDPR) and legitimate interest in managing the service and preventing abuse (art. 6.1.f GDPR).
Improving the academy
Aggregated statistics: how many people study, where they get stuck, which questions are badly worded. Only counts and threads already visible in the Community are used for this.
- Legal basis: legitimate interest in improving the courses (art. 6.1.f GDPR).
Complying with the law and defending rights
Handling your requests, keeping what the law requires and, if needed, bringing or defending claims.
- Legal basis: legal obligation (art. 6.1.c GDPR) and legitimate interest (art. 6.1.f GDPR).
Consent is only the legal basis for marketing emails. If we ever wanted to do something else that requires it, we would ask you separately and you could withdraw it at any time.
Payments and billing
If you go Pro, we also process:
- Subscription data: Stripe's customer and subscription identifiers, the plan, status and dates, the amounts charged and the payment events (type, date and amount).
- Proof of your purchase: the version of the terms you accepted and the date and time of that acceptance and of your consent regarding withdrawal.
- Your card and other payment and billing details (address or tax ID, if you give them) are collected and processed by Stripe on its pages: they never reach our server.
Purposes and legal bases: charging and managing your subscription (performance of the contract, art. 6.1.b GDPR); issuing invoices and keeping the accounts (legal obligation, art. 6.1.c GDPR); and being able to prove your purchase and your consent if there is a claim (legitimate interest, art. 6.1.f GDPR).
Retention: while the subscription lasts and, afterwards, blocked for the applicable legal periods: 6 years for accounting books, documents and vouchers (art. 30 of the Spanish Commercial Code) and 4 years of limitation for tax obligations (arts. 66 et seq. of Law 58/2003, General Tax Law). If you delete your account, we first cancel your subscription in Stripe and then delete it from our database; the amounts remain only as anonymous statistics, and the invoices and the proof of consent are kept for those periods in our Stripe account.
Who else can see your data
We don't sell or share your data. It can be seen by:
- Other people with an account on Marsof Academy: your display name, your avatar and your Community profile (level, streak, demonstrated skills, posts and best answers). Never your email. If you turn on «Show me in search», other students can find you by your display name and see you in their friend suggestions (for sharing a course or a forum thread). Your direct messages are only seen by the friend in that conversation; room messages, by the students who open the room. Anyone with the code of one of your certificates can verify it and see your display name and what it states (course, date and results).
- Community moderators (they see your account with the email partly hidden) and whoever runs the academy, who sees each student's record described in «Running the academy and helping you», only to manage it. In the chat, moderators have no access to direct messages: they only see a message when someone reports it, together with the three before it in that conversation as context (copied into the report).
And these providers, which process it on our behalf (processors), only on our instructions and under a contract that complies with art. 28 GDPR:
- Server provider (Contabo GmbH (Alemania)), in the European Union: hosts the application, the database and the backups.
- Email provider (IONOS): receives your address and the content of the emails we send you (the necessary ones and, if you accept them, the news) in order to deliver them. The messages you write to us arrive in the carlosgc@marsofacademy.com mailbox, which has its own mail provider.
- The AI tutor runs on our own server (an open model with Ollama or, if unavailable, rule-based hints): your questions aren't sent to third parties.
- Stripe Payments Europe, Ltd. (Ireland) and its group companies, such as Stripe, Inc. (USA): they process payments and issue invoices on our behalf. To prevent fraud and meet its own legal obligations (for example, anti-money-laundering rules), Stripe acts as an independent controller under its privacy policy (stripe.com/privacy). Transfers to the USA rely on the EU-US Data Privacy Framework and/or standard contractual clauses.
- If we keep a backup outside the server, it is encrypted before leaving it and stored with a storage provider in the European Union or with the safeguards described in the next section.
- Where applicable, the tax or accounting adviser who helps us meet our obligations, only with the billing data.
Also public authorities, judges and courts, but only when a law requires us to disclose it.
International transfers
Your data is stored in the European Union. It can only leave the European Economic Area (EEA) when one of the providers above processes it outside it (for example, in the USA). In that case the transfer relies on one of the GDPR safeguards: an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework if the provider is certified (art. 45 GDPR), or the standard contractual clauses approved by the Commission, with supplementary measures where needed (art. 46 GDPR). You can ask us for more information or a copy of those safeguards at carlosgc@marsofacademy.com.
How long we keep it
- Account, study and certificates: while you have the account. If you delete it, they are removed from the database immediately (and your certificates can no longer be verified). They disappear from backups as these rotate: within about 8 weeks at most.
- Community: your posts are kept while the Community exists so as not to break other people's conversations, but when you delete your account they are anonymised («deleted account»). If you ask for it when deleting, their text is also erased.
- Chat: a direct conversation is deleted 12 months after its last message; room messages after 90 days; declined friend requests after 30 days. When you delete your account, your friendships, blocks and room messages are deleted immediately; in your direct conversations, the other person keeps their copy read-only with your name replaced by «Deleted user», and open reports are kept until resolved. Reports and their copy of the reported message are deleted 12 months after being resolved; expired suspensions after 30 days.
- One-time links (confirm email, reset password, change email): they expire in 1 to 48 hours and are deleted the day after being used or expiring.
- Sessions: 30 days at most (or until you sign out); closed ones are deleted after 30 days. Revoked or expired CLI tokens and invites: deleted after 30 days.
- Community notifications already read: 6 months. Moderation and administration log: 12 months.
- Initial assessment and messages with the academy: for as long as you have the account; they're deleted with it.
- Tutor usage record: while you have the account.
- Consent to receive news: while you keep it. When you withdraw it we stop sending news immediately and the date you gave it is deleted.
- Server technical logs: they contain no IP or personal data and rotate by size, overwriting themselves.
- Emails you send us: as long as needed to help you and, afterwards, while any liability may arise.
When the law requires us to keep something, we keep it blocked (art. 32 LOPDGDD): only available to judges, courts and authorities, and we delete it when the legal period ends.
Your rights and how to exercise them
You can exercise, free of charge and at any time, your rights of:
- Access: knowing what data of yours we process and getting a copy.
- Rectification: correcting inaccurate data. You change your display name, email and preferences yourself in Settings.
- Erasure: deleting your data. You can delete your account yourself in Settings → Privacy and your data.
- Objection: objecting to processing based on our legitimate interest.
- Restriction: asking us to stop using your data while a claim is resolved.
- Withdrawing your consent to news at any time: in Settings → Emails or with the unsubscribe link in each email, without affecting earlier emails.
- Portability: receiving your data in a structured format. Settings → Privacy and your data → download your data (JSON).
For anything you can't do in the academy, write to carlosgc@marsofacademy.com from your account email (if you write from another one, we may ask you to prove your identity). We'll reply within one month at most, extendable by two more months in complex cases after letting you know (art. 12.3 GDPR).
If you think we haven't handled your data properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) or with the data protection authority of your EU country of residence. We'd appreciate it if you wrote to us first so we can try to fix it.
Automated decisions
We don't make decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you (art. 22 GDPR).
The academy does automatically calculate, from your results, your progress, your mastery of each skill, which lessons unlock, what to review and when, the grade of exercises and exams and whether you meet a certificate's requirements. This adapts your study to you; it isn't a profile with legal effects: certificates aren't official qualifications and everything can be improved by practising again. The AI tutor's assessments (for example, of an explanation of yours) are for guidance only. If you disagree with a result, write to carlosgc@marsofacademy.com and a person will review it.
The Community's automatic filters only stop a specific post; measures on your account are decided by a person.
Adults only
Marsof Academy is only for adults (18 or older) and is not aimed at minors. When you sign up you confirm that you are an adult. We don't knowingly process data of minors: if we learn that an account belongs to a minor, we will close it and delete its data.
How we protect your data
- Everything travels encrypted (HTTPS with HSTS) and the session is kept in a protected cookie.
- Passwords hashed with Argon2id; sessions, email links, invites and tokens stored only as hashes.
- Your exercise code runs isolated in your browser, never on our server.
- Hardened server (firewall, key-only access, automatic security updates), application in an unprivileged container and strict security headers.
- Role-based access to data: moderators see emails partly hidden and their actions are logged.
- Chat: direct messages only between friends, blocking, reports, sending limits and a word filter. Messages travel encrypted (HTTPS) and are stored on the server without end-to-end encryption: nobody on the team reads them except what is reported.
- Daily backups with restricted access.
No system is infallible. If we suffered a security breach posing a risk to you, we would notify the AEPD within 72 hours at most and, if the risk were high, you too (arts. 33 and 34 GDPR).
Changes to this policy
If we change this policy, we'll update the date and the version shown above. If the change is significant, we'll let you know in the academy (we'll ask you to read and accept the new version) or by email before it applies.