Privacy notice
This notice covers how InternStudio's Learning Management System handles data for partner organizations and the people using it — organization admins, instructors, and students — as well as visitors who submit a training request through the "Partner with us" page.
Information we collect
InternStudio does not offer public self-signup. The information it holds comes from two sources:
- Accounts provisioned by a partner organization or InternStudio — name, email, phone (where provided), role, and organization for organization admins, instructors, and students.
- Training requests submitted through the "Partner with us" form — organization name and type, contact person, email, phone, expected participant count, preferred dates, and any message provided.
- Learning activity tied to a student's enrollment — course progress, quiz attempts and scores, live-class attendance, and issued certificates.
How this information is used
To provide access to enrolled courses and live classes, track progress and attendance, issue certificates, respond to training requests, and otherwise operate the platform on behalf of the organization that provisioned an account. It is not sold, and it is not used for advertising.
Who can access your data
Access is scoped by role and enforced at the database level, not only in the application: an organization admin can see only their own organization's students and batches; an instructor can see only the students in batches they are assigned to; a student can see only their own account, enrollments, and progress. InternStudio staff can access data platform-wide to operate the service.
Certificate verification
The public certificate-verification page shows only a certificate holder's name, course, organization, completion date, and validity status — never an email, phone number, or other contact detail — and only to someone who has the specific certificate code being checked.
Where data is stored
Data is stored in InternStudio's managed Supabase project (PostgreSQL database, authentication, and file storage). Connections use HTTPS. Passwords are hashed and managed entirely by Supabase's authentication service — InternStudio never sees or stores a password in plain form.
Third-party services
InternStudio uses Supabase for hosting, database, authentication, and file storage; YouTube (Unlisted) to host lesson videos; and Google Meet for live-class links. These providers process data only as needed to deliver those features.
Data retention and deletion
Specific retention periods and a self-service deletion flow are not yet finalized. Until they are, a request to access, correct, or delete your data can be made using the contact below.
Changes to this notice
This is a working draft and will be revised as InternStudio's data practices and this notice are formally reviewed. It does not yet carry a version date for that reason.
Contact
Questions about this notice or a request regarding your data can be sent to team.internstudio@gmail.com.