Privacy Policy
Last updated: 20 August 2026
This policy explains what ZeroDegrees ("we", "us") collects when you use zerodegrees.me, why, and what you can do about it.
We are a small independent operation. We do not sell your personal information, we do not share it with advertisers, and we do not run advertising or cross-site tracking on this site.
Contact: hello@zerodegrees.me
The short version
- Browsing the site anonymously collects no personal data and sets no cookies. Our analytics are cookieless and do not identify you.
- Creating an account collects your email address and a little profile information.
- Buying something sends you to Stripe, which handles the payment. We never see or store your card number.
- We keep a security log of sign-ins (IP address, browser, country) to protect your account.
- You can ask us to export or delete your data at any time.
What we collect
If you only browse
Nothing that identifies you. We use Cloudflare Web Analytics to count visits. Every page on this site loads a small analytics script from static.cloudflareinsights.com, a Cloudflare domain, and that script reports a page view back to us.
What a page view records: the URL you are on, the referrer (the page or search that sent you here, if any), your country, your browser and device type, and timing measurements for how quickly the page loaded. It sets no cookie, stores nothing on your device, and generates no identifier that would let anyone follow you between visits or across other websites. There is no profile of you to build, and none is built.
Our servers process your IP address transiently in order to deliver the page, as every web server must. The analytics do not retain it.
If you create an account
- Email address — required. Used to sign you in, verify your account, deliver what you buy, and send service messages.
- Password — stored only as a salted hash. We cannot read it.
- Display name, time zone, language preference — optional, to make the site usable.
- Marketing preference — whether you've opted in to non-essential email.
If you sign in with Google
Google sends us your name, email address, profile picture and Google account identifier. We do not receive your Google password and we cannot access anything else in your Google account. Google's own handling of the sign-in is governed by Google's Privacy Policy.
Security and sign-in records
Each sign-in, sign-out and password change is logged with the date, IP address, browser user-agent and country. This exists so you can review activity on your own account, and so we can detect abuse. It is not used for marketing or profiling.
If you buy something
- Purchase records — what you bought, when, the amount, and the identifiers Stripe gives us.
- Payment details are handled entirely by Stripe. We never receive, see or store your full card number. Stripe may collect a billing address for tax and fraud purposes; where we need it, we read it from Stripe rather than storing our own copy.
If you work through a track
- Progress records — which lessons you've completed and roughly where you left off, so the site can pick up where you stopped.
If you start an age-restricted track
A record that you confirmed you meet that track's minimum age, the age you confirmed, and the date. Nothing more — see the Age section below.
If you join the mailing list without an account
Your email address, when you asked, and which page you asked from. Nothing else — there is no account, no name and no profile behind it.
⚠️ We only add you after you click the link in a confirmation email. Until you do, the address sits unconfirmed and we send you nothing further; if you never click, it stays that way and the request expires. That is deliberate: it means an address typed in by mistake never ends up on a list.
To come off the list, use the unsubscribe link in any email we send, or email hello@zerodegrees.me. If you have an account you can also turn it off yourself under Marketing email on your account page — that removes you from the list as well as changing the setting.
What we deliberately do not collect
We do not ask for your phone number, your postal address, your date of birth, or your employment history. We do not run advertising pixels, and we do not use third-party marketing or social trackers.
Cookies
We set a session cookie when you sign in. It keeps you logged in and nothing else — it does not track you across other sites. It is strictly necessary for the service to work, which is why there is no cookie banner asking you to accept it.
Cloudflare Turnstile, which protects our sign-up and sign-in forms from bots, may set a short-lived technical cookie for that purpose. It is not used for advertising or profiling.
We do not use analytics, advertising, or social-media cookies. If that ever changes, this policy will change first and we will ask for your consent where required.
Why we're allowed to process this (UK/EU users)
| What | Legal basis |
|---|---|
| Running your account, delivering what you bought | Performance of a contract |
| Security logging, bot protection, fraud prevention | Legitimate interests — keeping accounts safe |
| Marketing email, whether or not you have an account | Your consent, withdrawable at any time |
| Keeping transaction records | Legal obligation — tax and accounting |
Who else processes your data
We use a small number of service providers. They act on our instructions and are not permitted to use your data for their own purposes.
| Provider | What they do |
|---|---|
| Cloudflare | Hosting, our database, file storage, bot protection, cookieless analytics |
| "Sign in with Google", if you choose to use it | |
| Resend | Sends our email — verification, password resets, receipts, security alerts, and the confirmation for our mailing list |
| Stripe | Processes payments. Stripe is an independent controller for payment data; see Stripe's Privacy Policy |
These providers are based in, or process data in, the United States. Where data is transferred out of the UK/EEA, those transfers rely on the safeguards each provider has in place, such as Standard Contractual Clauses.
Links to other sites
Our material links out to other organisations — state licensing authorities, regulators, and training or certificate providers. Some of those are affiliate links, meaning we may earn a commission if you buy something after clicking one. Our Terms of Service set out how we handle that; in short, it never changes what we recommend or the order we list it in.
What that means for your privacy:
- Clicking a link takes you off zerodegrees.me. From that point the destination sees whatever its own tracking normally sees — your IP address, your browser, the fact that you arrived from here, and any cookies it sets itself. That is their collection, under their privacy policy, and we can't control or switch it off.
- ⚠️ We do not sell or share your personal data with them — affiliate partners included. We don't pass on your email address, your account, or anything else you've told us. A commission is paid on a purchase you make with them, not on data about you.
- They are not our processors, and an outbound link collects nothing. No one is added to the table above by being linked to, and nothing extra is collected on our side because a link exists. A link is a link until you click it.
How long we keep it
- Account data — while your account is open.
- Security and sign-in logs — 12 months, then deleted.
- Progress records — while your account is open.
- ⚠️ Transaction records — kept for 7 years after the transaction, because tax and accounting law requires it. This means that if you delete your account, we cannot delete your purchase records. We anonymise them instead: they are detached from your profile and reduced to what the law requires us to keep.
- Deleted accounts — everything else is removed within 30 days.
Your rights
Whoever and wherever you are, you can:
- Get a copy of your data — email us and we'll send it to you.
- Correct anything wrong — email us and we'll fix it.
- Delete your account — email us, subject to the transaction-record exception above.
- Be removed from the mailing list — including if you never had an account. Use the unsubscribe link in any email, or email us with the address. Deleting an account removes its list entry too.
- Opt out of marketing email — turn off Marketing email on your account page, use the unsubscribe link in any marketing message, or email us. Service messages such as password resets and receipts can't be opted out of while you have an account, because they're part of the service.
If you're in the UK or EEA you also have the right to object to or restrict certain processing, the right to data portability, and the right to complain to your data protection authority if you think we've got it wrong. In the UK that's the ICO.
If you're in California: we do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. We don't use your data for cross-context behavioural advertising. You have the right to know, delete, correct, and not be discriminated against for exercising those rights.
To exercise any of these, email hello@zerodegrees.me. We'll respond within 30 days. Marketing preferences are self-service on your account page; export and deletion are still handled by email, and self-service controls for those are coming.
Age
You must be at least 16 to create an account. We don't knowingly collect personal information from anyone younger. If you believe a child has created an account, email hello@zerodegrees.me and we'll remove it.
Some tracks cover work with a legal minimum age, and each is marked with the age that applies to it. Before you start one, we ask you to confirm you meet it.
⚠️ We record only that you confirmed, and the date. We do not ask for or store your date of birth, and we don't ask for ID. That's a deliberate choice: the less we hold, the less there is to lose.
Security
Passwords are stored as salted hashes and never in plain text. Sessions use secure, HTTP-only cookies. Sign-in and sign-up forms are protected against automated abuse. Resetting your password signs out every existing session.
No system is perfectly secure, and we won't claim otherwise. If we discover a breach affecting your personal data, we will notify you and the relevant authority as required by law.
Changes to this policy
If we change how we handle your data, we'll update this page and change the date at the top. If the change is significant, we'll email you about it rather than hoping you notice.