Privacy Policy

Effective date: 7 July 2026 · Data controller: Ivelin Rangelov Likov, sole trader, 21 Bateman Road, London, E4 8ND, United Kingdom.

This policy explains what personal data Mathematics for Machine Learning (the “Service”) collects, why we collect it, and the rights you have over it under UK data protection law (the UK GDPR and the Data Protection Act 2018). We collect as little as we can.

1. Who we are

The Service is run by Ivelin Rangelov Likov, a self-employed sole trader based in the United Kingdom. For data protection purposes, that person is the “data controller” — the one responsible for your data — and is registered with the UK Information Commissioner’s Office (ICO) under registration reference ZC189750. You can reach us at [email protected] or by post at 21 Bateman Road, London, E4 8ND, United Kingdom. This policy, like the Service itself, is governed by the law of England and Wales.

2. What we collect, and why

DataWhy we collect itLawful basis
Your email address (with a password, magic link, or Google/GitHub sign-in via Supabase)To create and secure your account and let you sign in on any deviceContract
Course progress and preferences (lessons completed, practice scores, theme, language)Stored in first-party m4ml.* cookies on your device, and synced to your account when you are signed in, so you can pick up where you left offContract
Support messages (your email, the message text, your UI language, and which page you wrote from)To answer your question and fix problemsContract / legitimate interests
An anonymous presence signal (your country and the page you are on — no IP address is stored)To see roughly how many people are using the Service and whereLegitimate interests
Content-copy events: if you copy a sizeable amount of text (40+ characters) from a page, we record the page, the amount, a short excerpt of the copied course text, your country, and — when you are signed in — your account email. Text you type into forms is never capturedTo detect and prevent bulk copying (scraping) of the paid course contentLegitimate interests
Subscription and payment status (plan, renewal date, Stripe references)To give you the access you paid forContract

Payments are handled entirely by Stripe. Your card number goes straight to Stripe — we never see it and never store it.

We do not show advertising, sell your data, or send marketing emails. Our everyday analytics — Cloudflare Web Analytics plus a first-party page-and-interaction signal — are cookieless and collect no personal data, with one narrow exception: copying a sizeable amount of course text is logged as described in the table above, to protect the course content from bulk copying. With your consent, we also use Microsoft Clarity for anonymised heatmaps and session replays (which parts of a page people use, and where they get stuck) so we can make the Service clearer; because it uses cookies we load it only if you accept the cookie banner, and you can decline with no loss of function (see section 4).

3. Our lawful bases

4. Cookies and local storage

WhatTypePurpose
m4ml.* cookiesFirst-party, functionalRemember your progress, theme, and language on this device
Supabase session tokenStrictly necessaryKeeps you signed in; stored in your browser
Cloudflare Web AnalyticsCookielessAggregate page statistics — sets no cookies and stores no personal data
First-party interaction signalCookielessAn in-tab id (browser sessionStorage, cleared when you close the tab) so we can see which steps and buttons people use — never the values you type. Copying a sizeable amount of course text is logged as described in section 2
_clck, _clsk — Microsoft ClarityOptional · needs your consentHeatmaps and session replays to improve usability; input is masked (no keystrokes, passwords or card details). Set only if you click Accept on the cookie banner

The strictly-necessary and functional items above run without consent (UK rules only require consent for cookies that are not strictly necessary for the service you asked for). Microsoft Clarity is the one optional, non-essential tool, so we ask for your consent through a cookie banner and load it only if you click Accept — decline and the Service works fully. We set no advertising or cross-site ad-tracking cookies at all. To change your choice later, clear this site’s cookies in your browser and the banner returns.

5. Service providers (sub-processors)

We share the minimum necessary with a small number of providers who process data on our behalf:

Some of these providers are outside the UK. Where data leaves the UK, it is protected by UK GDPR safeguards — UK adequacy decisions or standard contractual clauses (SCCs) with the UK addendum.

6. How long we keep your data

7. Your rights

Under the UK GDPR you have the right to:

How to delete your account

You do not need to ask us. Sign in, open your account page, scroll to Delete account, type the confirmation word and confirm. This happens immediately and cannot be undone: your profile, learning progress, certificates, support messages and the sign-in itself are erased, and any active subscription is cancelled on the spot. Analytics rows that recorded your account are kept but stripped of anything identifying you.

One thing is deliberately kept: your payment and invoice records, including the customer record held by our payment provider. UK tax law requires us to keep business records for 6 years, which is a legal obligation and an exception to erasure under Article 17(3)(b) and (e) of the UK GDPR. They are never used to contact you again. If you would rather we did the deletion for you, email [email protected] and we will.

To exercise any of these, use the “Contact support” option on your account page or email [email protected]. We will respond within one month. If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office at ico.org.uk.

8. Security

We use reputable providers and sensible technical and organisational measures to protect your data, including encryption in transit and access controls on the database. No system is perfectly secure, but the small amount of data we hold keeps the risk low, and we work to keep it that way.

9. Children

The Service is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. If a change is significant we will give reasonable notice, for example a notice in the app or an email to account holders. The effective date at the top shows the current version.

11. Contact

Privacy questions or requests: use “Contact support” on your account page, email [email protected], or write to Ivelin Rangelov Likov, 21 Bateman Road, London, E4 8ND, United Kingdom.

12. Language

Language. This policy is written in English. We may show a translation in your language for convenience, but the English version is the legally binding one: if there is any difference in meaning, the English text prevails.