Last updated October 2, 2026
Privacy Policy
This policy explains how Wisdify collects, uses, shares, and protects information when you use our web app, mobile app, courses, certificates, billing flows, and related services.
Information We Collect
- Account information, including your name, email address, password credentials, verification status, and account settings.
- Learning and CPE records, including enrollments, playback progress, checkpoint answers, final assessment attempts, completions, certificate snapshots, and feedback you choose to submit.
- Billing and access information, including subscription or purchase status, product entitlements, invoice metadata, payment method brand and last four digits, and external billing identifiers. Full payment card numbers are handled by Stripe, not stored by Wisdify.
- Device, app, and diagnostic information, including mobile device labels, push notification tokens, app version, platform, browser user agent, approximate sign-in country, pseudonymous device and network identifiers, hashed IP data used for playback/session integrity, error reports, and redacted mobile diagnostic logs when diagnostics are enabled.
- Content and files handled by the service, including course audio, cover art, certificate PDFs, exported certificate archives, and operational records created by administrators.
How We Use Information
- To create and secure your account, verify your email address, authenticate sessions, reset passwords, and prevent unauthorized access.
- To deliver the learning experience, track podcast-style playback, enforce anti-skip and assessment rules, sync progress across devices, support offline/retry workflows, and issue CPE certificates.
- To manage subscriptions, one-time purchases, plan limits, invoices, refunds, billing support, and access to paid or free content.
- To document and respond to payment disputes, chargebacks, fraud reports, and suspected misuse, including by comparing transaction, policy-acceptance, account-access, course-progress, completion, certificate, and communications records.
- To send transactional messages, such as verification emails, password reset emails, certificate exports, billing notices, and course or certificate notifications.
- To send learning emails, such as course reminders, CPE deadline notices, course recommendations, and new-course announcements, and to decide which to send. For these emails we record whether each was delivered, whether it was opened (using a small image in the email), and whether you studied afterward. We do not track which links you click. Every learning email links to your email preferences, where you can choose fewer emails or unsubscribe.
- To troubleshoot, audit, improve reliability, identify connected accounts and investigate possible plan-limit evasion, abuse, or fraud, maintain accreditation records, and comply with legal, tax, accounting, security, and CPE sponsor obligations.
Cookies, Local Storage, and Mobile Storage
- The web app uses cookies and similar browser storage to keep you signed in, protect requests, remember site access settings, associate sign-ins from the same browser for abuse investigation, register the app as an installable web app, and support playback.
- The mobile app stores authentication tokens in secure device storage and may cache catalog, enrollment, playback, certificate, and queued sync data locally so the app can load quickly and recover from network interruptions.
- You can clear local app data by signing out, deleting the app, clearing browser data, or closing your account. Some server-side CPE and billing records may remain as described below.
When We Share Information
- Service providers process information for us, including hosting and database infrastructure, email delivery, billing, payment processing, background jobs, push notifications, media storage, country-level IP lookup, analytics, and error monitoring. Depending on configuration, these providers may include Stripe, SMTP2GO or another email delivery provider, Expo, IPinfo, Sentry, PostHog, Trigger.dev, Railway, S3-compatible storage providers, and WordPress or WooCommerce integrations.
- Billing and account integrations may receive or send the information needed to reconcile products, subscriptions, user status, and payment events, including Stripe and connected WordPress or WooCommerce systems when configured.
- When needed to prevent fraud or respond to a payment dispute, we may share relevant transaction, policy-acceptance, account-access, course-progress, completion, certificate, and communications records with payment processors, banks, card networks, fraud-prevention providers, and our professional advisers or service providers.
- We may disclose information if required by law, to protect rights and safety, to investigate fraud or abuse, during a business transaction, or with your direction or consent.
- We do not sell personal information, and we do not use learner data for third-party advertising tracking.
Retention and Account Deletion
- You may request account deletion from the app. Deletion disables sign-in, revokes sessions, removes or deactivates ordinary account access, and clears eligible local app data.
- Because Wisdify provides continuing professional education, we retain compliance records needed to verify course completion, assessment history, certificates, audit events, billing history, tax/accounting records, security logs, and legal obligations.
- We also retain transaction, policy-acceptance, account-access, course-progress, completion, certificate, and communications records for as long as reasonably necessary to handle payment disputes, prevent fraud, establish or defend legal claims, and meet legal, tax, accounting, audit, and CPE sponsor obligations.
- Mobile diagnostic log uploads are designed for short-term support use and are swept after about 30 days. Some operational logs, backups, and audit records may persist longer where necessary for security, compliance, or disaster recovery.
- Sign-in observations containing approximate country and pseudonymous device or network identifiers are retained for about 90 days. The latest sign-in country and time remain with the account security record after the detailed observations expire.
- If you want to access, correct, delete, or ask about your information, contact us at the address below. We may need to verify your identity before acting on a request.
Security
- We use technical and organizational safeguards designed to protect information, including encrypted transport, password hashing, token rotation, access controls, request validation, and limited administrative access.
- No online service is perfectly secure. Please use a strong, unique password and contact us promptly if you believe your account has been compromised.
Your Choices
- You can update your account profile, change your password, sign out, close your account, and manage notification permissions through the app or your device/browser settings.
- Marketing communications, if introduced, will include opt-out controls. Transactional messages related to your account, security, billing, or CPE records may still be sent when necessary.
- Push notifications are optional and can be disabled in your device or browser settings.
Children
- Wisdify is intended for accounting, finance, and other professional learners. It is not directed to children, and we do not knowingly collect personal information from children under 13.
Changes
- We may update this Privacy Policy when our practices, services, or legal obligations change. We will post the updated policy here and revise the last updated date.
Contact Us
Questions or privacy requests can be sent to hello@wisdify.com.
