Privacy Policy
Last updated: September 29, 2026
Introduction
SciMigo (“SciMigo”, “we”, “us”) builds developer education for complex engineering systems (courses, hands-on labs, workshops, and technical visualizations) and runs a learning site where anyone can study its courses with an AI tutor. This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and the choices you have.
It applies to the SciMigo website and web application at scimigo.com and learn.scimigo.com (courses, lectures, interactive labs, practice, and the AI tutor), and to the SciMigo Chrome extension. It does not apply to third-party sites we link to, which have their own policies.
If you have questions about anything below, email us at support@scimigo.com.
Information We Collect
Sign-in information
You can create a SciMigo account by signing in with Google or GitHub. Authentication is handled by Google Firebase Authentication; we never see or store your Google or GitHub password. From the sign-in provider we receive:
- Your email address
- Your display name and profile picture, when the provider supplies them
- A stable account identifier for the provider, which we store to recognize you on return visits
When you sign in with Google we request only the basic sign-in scopes — openid, email, and profile. We do not request or receive access to Gmail, Google Drive, Calendar, Contacts, or any other restricted or sensitive Google API data.
Information you provide
- Questions, prompts, and messages you send to the AI tutor, including any code you attach to or paste into them, and text you select on a course page to ask about
- Code you write and run in interactive labs, and answers you submit to practice and quiz questions
- Content you upload or submit when creating courses or lectures
- Feedback, support requests, and other communications with us
- Your email address, and anything you choose to tell us about what you are working on, if you join a course waitlist. We use the address to tell you when a course ships. We read what you tell us about your work, together with which page you signed up from, to decide which courses to build next. We do not sell it or give it to advertisers, and you can ask us to remove it at any time.
Learning activity
- Courses, modules, and lectures you open, and your progress through them
- Interface language and other account preferences
Learning events
Course pages send short activity records (“learning events”) to SciMigo’s own collector. They record what you did, not what you wrote: for example that you opened a module, spent time in a section of a lesson, ran a lab step, or passed or failed one of its checks. They never contain lesson text, your code, lab output, check messages, or your tutor questions and answers. They are linked to your account when you are signed in, and otherwise to a random identifier stored in your browser. Each kind of event has one fixed purpose:
- Your learning record — what you did in a course, so the tutor can see where you are and personalise its help to you, in that course only.
- Product analytics — aggregate funnels, such as how many learners start and finish a module, and where people come from.
- Quality monitoring — aggregate tutor speed, cost and ratings, and reports of confusing or incorrect course content.
When you delete your tutor history for a course (or all of it), your learning record for that course is deleted, and your product analytics and quality monitoring events are de-identified: they stay in our totals but can no longer be linked to you. Deleting a single conversation or answer does the same for the events about that conversation or answer. Closing your account deletes all of these events.
Payment information
If you purchase a paid subscription, payment is processed by our payment processor, Stripe. Stripe receives your payment details directly; SciMigo does not receive or store your full card number. We store your subscription tier and status so we can give you access to what you paid for.
Information collected automatically
- Usage data — pages and lectures viewed, features used, and approximate timing
- Device and browser type, operating system, and screen characteristics
- IP address, and the coarse (country- or region-level) location derived from it
- Cookies and similar storage, described under “Cookies and Local Storage” below
AI tutor conversations
The AI tutor is available when you are signed in. When you ask it a question, your browser sends the question to SciMigo’s servers together with where you are in the course (the lesson section, slide, or lab step), any text you selected to ask about and, if you ask from a lab, your latest run and check results and, for labs that run in the page, your current code. Labs that run on your own computer share only their output and results, never your files. Our servers add the relevant course material, send the request to our AI provider through an account SciMigo manages, and stream the answer back to you. You do not supply an AI provider key, and your browser never holds ours.
Your tutor conversations are kept until you delete them or close your account. This includes your questions, the tutor’s answers, and any code attached to or pasted into a question. We remove things that look like passwords, API keys, and other credentials before storing a conversation, but we do not remove ordinary code, so please do not paste anything you would not want kept. You control what is kept:
- Turn on “Don’t keep” in the tutor panel and the conversation’s new questions are answered but not saved, and are never used as context later.
- In the tutor’s History, you can delete a single answer, a whole conversation, or everything in a course. The tutor’s Context view shows what its next answer will use, and lets you delete earlier conversations from there too.
The chat beside our narrated video lectures, and the SciMigo Chrome extension, still use our earlier tutor: it keeps only the last ten messages of a conversation, for one hour, after which they expire. Those conversations do not appear in History.
The tutor uses your earlier conversations in a course as context when you ask about that course. A conversation in one course is never used to answer in another. We also record how much you use the tutor, to apply the limits of your plan.
We use tutor questions, after removing credentials and other identifying details and only in aggregate, to find what learners find confusing and to improve our courses. Individual conversations are not read by our staff except to answer a support request you raised, or where needed to investigate abuse or a security incident. Tutor conversations are never used to train AI models and are never shared with course sponsors.
Google User Data and Limited Use
SciMigo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, the Google account data we receive (your email address, basic profile, and account identifier):
- Is used only to create and authenticate your SciMigo account, to show you which account you are signed in as, and to associate your learning progress and subscription with you
- Is never sold, rented, or transferred to data brokers or information resellers
- Is never used for advertising, ad targeting, ad personalization, or ad measurement
- Is never used to train, fine-tune, or improve any AI or machine learning model
- Is not read by humans, except with your explicit consent to resolve a support request you raised, where necessary for security purposes such as investigating abuse, where required by law, or in aggregated and anonymized form for internal operations
You can review and revoke SciMigo’s access to your Google account at any time at myaccount.google.com/permissions. Revoking access stops future sign-ins; to also delete the data already associated with your account, see “Deleting Your Account and Data” below.
How We Use Your Information
We use the information described above to:
- Create your account, sign you in, and keep your session secure
- Deliver course content, labs, practice, and AI tutoring, and save your progress across devices
- Personalize your experience, such as remembering your interface language and where you left off
- Process subscriptions and apply the usage limits of your subscription tier
- Respond to your support requests and feedback
- Understand aggregate usage so we can fix problems and improve the platform
- Improve our courses from tutor questions and content reports, scrubbed and in aggregate
- Detect, prevent, and investigate abuse, fraud, and security incidents
- Comply with legal obligations
Where the GDPR or similar laws apply, we process this information to perform our contract with you (to provide the service), on the basis of our legitimate interests (to secure and improve the service), with your consent (for analytics cookies, where consent is required), and to comply with legal obligations.
We do not use your personal information, your AI tutor conversations, or your lab code to train AI or machine learning models, and we do not sell your personal information.
How We Share Information
We do not sell your personal information and we do not share it for cross-context behavioral advertising. We share it only with service providers that process it on our behalf, under contract and only for the purposes below:
- Google (Firebase Authentication) — account sign-in and session management
- Google Analytics — aggregate usage analytics, where enabled on the site
- Stripe — subscription payments and billing
- Amazon Web Services — hosting of our application servers and database
- Cloudflare — content delivery and storage of course and lecture media
- AI providers (such as OpenAI and Anthropic) — processing of the questions you send to the AI tutor, so that a response can be generated
Some courses are sponsored. We never share your tutor conversations, your learning events, or other information about you with course sponsors.
We may also disclose information if required by law, subpoena, or other legal process, or where we believe disclosure is necessary to protect the rights, safety, or property of our users, the public, or SciMigo. If SciMigo is involved in a merger, acquisition, or sale of assets, we will notify you before your information becomes subject to a different privacy policy.
Your AI tutor questions are sent to the AI provider that answers them. We recommend reviewing their policies, for example the OpenAI Privacy Policy and the Anthropic Privacy Policy. Please do not include personal, sensitive, or confidential information in your tutor questions.
Cookies and Local Storage
We use a small number of cookies and browser storage entries:
- Authentication — set by Firebase Authentication to keep you signed in. Required for accounts to work.
- Preferences — for example a
NEXT_LOCALEcookie holding your interface language, and local storage entries holding your settings. If you use a lab’s “Run on my computer” panel, local storage also holds the pairing token that lets this site reach agent-runtime on your computer, and which lab versions you have approved. The AI tutor keeps, in your browser, which course sections you have already viewed (to tell a first view from a return visit), whether you turned off its hint suggestions, and, for the current browser tab only, which conversation is open. - Analytics — set by Google Analytics, where enabled, to measure aggregate usage.
You can block or delete cookies in your browser settings. Blocking authentication cookies will prevent you from signing in; blocking preference storage means your settings will not persist between visits.
Data Retention
- Account and learning data — kept while your account is active, and deleted after you close your account as described below.
- AI tutor conversations, including code attached to or pasted into a question — kept until you delete them in the tutor’s History or close your account. Conversations with “Don’t keep” turned on are not stored.
- Learning events — your learning record is kept until you delete your tutor history for the course or close your account; product analytics and quality monitoring events are de-identified when you delete your tutor history, and deleted when you close your account.
- Lab work saved to your account — kept so you can return to it, and deleted with your account.
- Server and security logs — kept for a limited period for security and troubleshooting, then deleted.
- Billing records — kept for as long as tax and accounting law requires, even after account deletion.
- Aggregated and anonymized statistics — which can no longer identify you, may be kept indefinitely.
Deleting Your Account and Data
You can delete your AI tutor conversations yourself at any time, one answer, one conversation, or a whole course at once, from the tutor’s History. Conversations are removed immediately; the learning events tied to them are deleted or de-identified, as described under “Learning events” above, within 24 hours.
You can ask us to delete your SciMigo account and the personal information associated with it at any time. Email support@scimigo.com from the email address on your account with the subject “Delete my account”.
We will confirm your request and delete your profile, learning progress, learning events, tutor conversations, and lab work from our production systems within 30 days, and from our backups within 90 days. Information we are legally required to keep, such as billing records, is retained for the required period and then deleted.
Deleting your SciMigo account does not delete your Google or GitHub account. To separately revoke SciMigo’s access to your Google account, visit myaccount.google.com/permissions.
Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Delete your personal information
- Receive a portable copy of the information you gave us
- Object to or restrict certain processing, and withdraw consent you previously gave
- Not be discriminated against for exercising these rights
To exercise any of these rights, email support@scimigo.com. We will respond within 30 days. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
Data Security
We protect your information with measures including encryption in transit (HTTPS/TLS), authentication through an established identity provider rather than passwords we store ourselves, access controls limiting which staff can reach production data, and keeping payment card data entirely with our payment processor. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
International Data Transfers
SciMigo is operated from the United States, and our service providers may process your information in the United States and other countries. These countries may have data protection laws that differ from those in your country. Where required, we rely on appropriate safeguards, such as the European Commission’s standard contractual clauses, for these transfers.
Children’s Privacy
SciMigo is intended for learners aged 13 and over. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us personal information, email support@scimigo.com and we will delete it. If you are between 13 and the age of majority where you live, please use SciMigo with the involvement of a parent or guardian.
Chrome Extension
The SciMigo Chrome extension is designed so that nothing leaves your browser without your action:
- No silent collection: no data is transmitted automatically — you must click to send a request
- Transparency: you can see exactly what text will be sent before it is submitted
- Editing control: content can be reviewed and edited before transmission
- No background processing: the extension processes data only when you activate it
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and change the “Last updated” date above. If the changes are material, we will give you additional notice, such as a notice in the application or an email to the address on your account.
Contact Us
For any question or request about this Privacy Policy or your personal information, contact us at support@scimigo.com. You can also reach us through our GitHub Discussions.