Privacy Policy
Effective date: 1 April 2026
1. Who We Are
Sculpt Ltd (“Sculpt”, “we”, “us”, or “our”) operates sculpt-os.com. We publish video courses, e-books, editorial articles, and short-form videos that teach founders, executives, and operators to make confident technical decisions — from evaluating AI and vendors to IP, hiring, and engineering strategy.
Questions about this policy can be directed to support@sculpt-os.com.
2. Data We Collect
Account data: When you create an account (including auto-created accounts on purchase), we store your email address and a hashed password. We never store plaintext passwords.
Payment data: Course and book payments are processed by Paddle. We receive a payment token and your email address confirming a completed transaction. We do not store card numbers, bank details, or any raw payment instrument data.
Course and book access records: We store which courses you are enrolled in, which books you own (including books included free with a course purchase), and your lesson and reading progress, so we can resume where you left off and grant access to purchased content.
Usage analytics: We use Google Analytics (GA4) to understand aggregate usage of courses, books, editorial, and shorts, and to improve the Service.
Log data: Our servers collect standard access logs (IP address, browser type, pages visited, timestamps). These are retained for up to 30 days for security and debugging purposes.
3. How We Use Your Data
We use your data solely to:
- Provide and operate courses, books, editorial, and shorts
- Grant and maintain access to courses and books you have purchased, and deliver course artifacts (worksheets, templates) to enrolled students
- Send transactional emails (purchase confirmation, account credentials, password reset)
- Understand aggregate usage of the Service (via Google Analytics) to improve content and the product
- Detect and prevent fraud and abuse
- Comply with legal obligations
We do not sell your data to third parties.
4. Legal Basis for Processing (GDPR)
Where the GDPR applies, we process your personal data on the following legal bases:
- Contract performance: Processing your email and payment token to deliver the course, book, or content you paid for.
- Legitimate interests: Security logging, fraud prevention, and service improvement.
- Legal obligation: Where required by applicable law.
5. Data Sharing
We share personal data with the following third-party processors only to the extent necessary to provide the service:
- Paddle: Payment processing for courses and books. Your email address and purchase details are transmitted to Paddle to process your transaction. We do not store card numbers or raw payment instrument data. Privacy Policy
- Resend: Transactional email delivery. Your email address is transmitted to Resend solely to deliver purchase receipts, account credentials, and notifications. Privacy Policy
- Google Analytics (GA4): Aggregate usage analytics. Google may process data in accordance with its own privacy policy. Privacy Policy
- Cloudflare (R2): Storage of course videos, downloadable course artifacts, and book files. Files are served to you via short-lived signed links generated only after we verify you own or are enrolled in the relevant content.
- Cloud infrastructure provider: Hosting and database services.
We do not share your data with any other third parties without your explicit consent, unless required by law.
6. Data Retention
- Account data (email, password hash): retained while your account is active. You may request deletion at any time.
- Course enrollment, book ownership, and progress records: retained while your account is active, so you retain access to content you have purchased.
- Payment records (token, email, timestamp): retained for 7 years for financial compliance purposes.
- Server access logs: 30 days.
- Aggregate analytics: retained per Google Analytics' standard retention settings.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your account and personal data
- Object to or restrict certain processing
- Receive your data in a portable format
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email support@sculpt-os.com. We will respond within 30 days.
8. Cookies
We only use cookies that are strictly necessary to operate the Service — specifically, a session cookie (set by NextAuth) that keeps you signed in. We do not use advertising or tracking cookies.
9. Security
We implement appropriate technical and organisational measures to protect your data, including encrypted connections (TLS), hashed password storage (bcrypt), and access controls on all databases. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Children
Sculpt is intended for use by founders, executives, and operators. We do not knowingly collect personal data from individuals under 16 years of age.
11. Changes to This Policy
We may update this policy from time to time. When we do, we will update the effective date at the top of this page. Material changes will be communicated by email to registered users.
12. Contact
For any privacy-related questions or requests:
Sculpt Ltd
support@sculpt-os.com