1. What this policy covers
This policy explains what personal data Atoi collects when you use a-to-i.com, why we collect it, who we share it with and what choices you have. It applies to visitors, learners and teachers alike.
2. What we collect
- Account details: your name, email address, preferred language and a hash of your password. If you sign in with Google or a passkey, we receive the identifier those services give us, never your Google password.
- Learning data: enrolments, lesson progress, quiz and project submissions, teacher feedback, live-lesson attendance and the certificates you earn.
- Payment records: what you bought, when, for how much, the payment method used and the reference the provider returns. Card numbers and wallet credentials are entered on the provider's own page and never reach us.
- Technical data: IP address, browser and device type, pages visited and error reports, kept in server logs for security and troubleshooting.
- Messages: anything you send to support or post inside a course.
3. How we use it
We use your data to run your account, deliver the courses you bought, issue and verify certificates, take payments and send receipts, answer your messages, keep the platform secure, and understand which lessons work and which need improving. We send transactional email only: verification links, receipts, lesson reminders and decisions about your submissions. We do not send marketing email and we do not sell your data.
4. Who we share it with
We share data only with the services needed to run Atoi, and only what each one needs:
- Payment providers process your payment and tell us whether it succeeded.
- Cloudflare hosts our media and sends our email; Vercel serves the website.
- Google receives your name and email when you choose to sign in with Google or join a live lesson held on Google Meet.
- Teachers see the name, progress and submissions of learners in their own courses.
- Anyone with a certificate code can see the name on that certificate, the course and the issue date on the verification page. That is what makes the certificate verifiable.
We disclose data to authorities only when the law requires it.
5. Cookies
We use a session cookie to keep you signed in, a cookie that remembers your theme and language, and Cloudflare's bot check on sign-in and sign-up forms. We do not use advertising cookies or third-party analytics trackers.
6. How long we keep it
Account and learning data are kept while your account exists. Payment records are kept for as long as accounting and tax rules require, usually several years. Server logs are kept for a short period, then deleted. When you delete your account we remove or anonymise the rest, except what we must keep by law and the public verification record of certificates you earned.
7. Your rights
You can see and correct your account details in your account settings. You can ask us for a copy of your data, for corrections, or for deletion of your account by writing to support@a-to-i.com. We answer within thirty days. If you are in a jurisdiction that grants further rights, such as objection or portability, you have those too.
8. Security
All traffic is encrypted, passwords are stored only as salted hashes, access to production systems is limited to the people who operate them, and backups are encrypted. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.
9. Children
Atoi is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
10. Changes to this policy
We may update this policy. The current version and its effective date are always on this page, and we announce material changes by email or a notice on the site before they apply.
11. Contact
Privacy questions and requests go to support@a-to-i.com.



