Privacy policy
Last updated: 17 August 2026
Criterium is a platform for building, publishing and running online courses. This policy explains what personal data we process, why, who we share it with and how you stay in control of it, under the General Data Protection Regulation (GDPR) and the French Data Protection Act.
1. Who is responsible
For your account, this website and our own measurement, Criterium is the data controller. You can reach us at:
Email: contact@criterium.app
Data belonging to a training organisation
Inside an organisation's workspace, the organisation decides what learner data is collected and why: it is the controller, and Criterium acts as its processor, on its instructions and under contract. If you are a learner and want your data corrected or deleted, ask the organisation that enrolled you first; we assist them, and we will act directly if you would rather write to us.
2. Data we process
We collect only what the platform needs to work, and we keep the categories below separate from one another:
Account data
Your name, email address, interface language, the organisations you belong to and your role in each. Passwords are stored only as a one-way hash, never in clear text. An account created for you by an organisation starts with no password and is claimed through a single-use activation link.
Content you upload
The documents, PDFs, links, images and text you add as course sources or as attachments, plus your organisation's logo and brand images. Files are stored in our European object storage.
Content generated for you
The lessons, quizzes, presentations, podcast scripts and audio, and images the platform produces from your sources, along with their revision history so you can go back.
Learning data
Enrolments, which activities were opened and when they were last opened, activities marked complete, quiz answers and scores, assignment submissions with their attached files, grades and feedback.
Assistant conversations
Your messages to the authoring agent and the actions it takes on your behalf, learners' exchanges with the course assistant and chatbots, and the credits each run consumed, which is what we meter and cap.
Usage and audience data
With your consent only: pages viewed, features used and the channel that brought you to the site (see section 10). Without consent, nothing is collected from your browser beyond the record of your refusal.
Technical and diagnostic data
When something breaks, an error report is sent to our monitoring tool: the page or endpoint involved, the browser or server version, the technical stack trace and, if you were signed in, your account identifier. Credentials, tokens and content bodies are stripped before sending.
Plan and billing data
Your plan, your billing periods, your credit consumption and, on a paid plan, the customer reference held by our payment provider. Card details never reach our servers.
Email and contact data
The transactional emails we queue for you (recipient, subject, template, delivery status), the bounce and complaint records that stop us writing to an address that rejects our mail, and the address you give us if you join the waiting list or the newsletter.
3. Legal bases
Each processing activity rests on one of the following bases:
- Performance of the contract: creating and running your account, your courses and your learners' access.
- Legitimate interests: keeping the service secure, preventing abuse, fixing defects and understanding aggregate product usage.
- Consent: analytics cookies, the newsletter and waiting-list emails. You can withdraw it at any time without affecting the service.
- Legal obligation: accounting and tax records, and responding to lawful requests.
4. What we use it for
We process your data to:
- run, secure and support the platform and the courses published on it;
- produce the content you ask the AI features for, and attribute its cost to the right account;
- give organisations the progress and results of the learners they enrolled;
- manage plans, credits, usage limits and invoicing;
- send the transactional emails the service needs (activation, password reset, enrolment);
- diagnose defects and improve the product;
- meet our legal obligations and defend our rights.
5. Who we share it with
We never sell personal data and we never share it for advertising. We rely on a short list of processors, each bound by a data processing agreement:
Hosting and storage
Hetzner Online GmbH (Germany) hosts our servers, our database and our file storage. Your primary data stays in the European Union.
AI providers
Google (Gemini models, for text, images and podcast voices) and OpenRouter, which routes the authoring agent's requests to the selected model. They receive the sources and instructions needed to produce what you asked for, as processors. We use only models whose providers state that they neither retain the data sent to them nor train on it.
Analytics
PostHog (European region) for product usage and Google Analytics for site audience. Neither is loaded before you consent, and neither is used for advertising (see section 10).
Error monitoring
Sentry, for crash and error reports only. Session replay and behavioural recording are switched off.
Email delivery
Our email provider (Resend, or the SMTP relay configured for the deployment) receives the recipient's address and the message we composed.
Payments
Stripe, for paid plans and course sales. Payment details are collected by Stripe directly and are never stored by us.
We may also disclose data where the law requires it, or where it is necessary to enforce our terms of use.
6. How long we keep it
We keep each category only as long as it is useful, then delete it:
- Account data: for as long as the account is active, then up to three years after closure for legal and accounting purposes.
- Courses and sources: until you delete them; a deleted course is purged for good fourteen days later.
- Learning data: for as long as the organisation's workspace needs it. The organisation can delete it at any time.
- Conversations and generated content: until you delete them from your dashboard.
- Activation, invitation and password-reset links: they expire within hours or days of being issued.
- Analytics: the consent cookie lasts twelve months; error reports are kept for up to 90 days.
7. Your rights
Under the GDPR you have the following rights:
- Access: obtain a copy of the personal data we hold about you.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted (the “right to be forgotten”).
- Restriction: ask us to limit how we process your data.
- Portability: receive your data in a reusable format, or have it transferred.
- Objection: object to processing based on our legitimate interests, and withdraw your consent at any time.
To exercise any of these rights, write to us at the address below. We answer within one month. If your data sits inside a training organisation's workspace, we may need to pass the request on to that organisation, and we will tell you when we do.
8. Security
We encrypt data in transit (TLS) and at rest, host our infrastructure in the European Union, store passwords as one-way hashes, and keep every organisation's workspace strictly separated so none can read another's data. Access inside a workspace follows the role each person holds, authentication endpoints are rate-limited, and administrative access is limited to what support genuinely requires. When a Criterium administrator opens a workspace at its owner's request, the session is flagged as such and excluded from all analytics.
9. International transfers
Our infrastructure and database are in the European Union. Some processors (AI providers, Google Analytics, Sentry, our email provider) may process data outside the EU. In those cases the transfer relies on the European Commission's Standard Contractual Clauses or on the EU-US Data Privacy Framework, and is covered by a data processing agreement.
10. Cookies
We use cookies that are essential to running the platform: authentication cookies to keep you signed in, your language preference, and the record of your analytics choice. We use no advertising cookies and no trackers sold on to third parties.
The record of your choice is kept in a first-party cx_analytics_consent cookie for twelve months, whichever way you answer, and no analytics script is loaded before you have answered.
Analytics
With your consent only, we use PostHog (servers located in the European Union) to measure feature usage, and Google Analytics to measure site audience and understand which channel brought you here. Neither is used for targeted advertising. You are asked on your first visit: if you decline, no analytics cookie is set and nothing is collected from your browser. You can change your mind at any time below.
You have not made a choice yet.
11. Minors
Criterium is built for training organisations and learning professionals; creating an account requires being 18 or over. Learners of any age may be enrolled by their organisation, which is responsible for obtaining the consent its own law requires. In that case we collect nothing beyond what is needed to follow their progress through the course.
12. Changes to this policy
We may update this policy as the product evolves. The date at the top always reflects the latest version, and we notify you by email or through the platform whenever a change materially affects you.
13. Complaints
If you believe your data protection rights have been breached, you can lodge a complaint with a supervisory authority. In France, that authority is the CNIL.
14. Contact us
For any question about this policy or about how we handle data, write to us:
Email: contact@criterium.app