Privacy Policy
Last updated: September 22, 2026
Cedarras is an online course platform operated by Atchison Technology LLC (“we”, “us”). Course creators use Cedarras to publish courses; their students use Cedarras to take those courses. This policy explains what we collect, who can see it, and what we do with it.
There are three parties in Cedarras, and it matters which one is looking at your data:
- Cedarras — us. We run the platform and host the data.
- The course owner — the creator whose course you are taking. They control their own account and their own students.
- You — the student or the course owner, depending on which side of the product you are on.
Who is responsible for what
Cedarras holds two kinds of data, and the responsibility for each is different.
Learning records are handled for your course owner. Your enrollment, your progress, your quiz answers and scores, which lessons you opened, and the enrollment emails sent to you all exist because a course owner chose to teach you on Cedarras. We keep and use them on the course owner’s behalf and on their instructions, to run their course — in legal terms, we are their processor and they are the controller. Questions about why a course owner has your data, or what they do with it, are theirs to answer; we will help them answer them.
Account, sign-in and security data is ours. Your Cedarras account itself, your sign-in records, the records we keep to protect the service, error reports, email delivery records, and a course owner’s billing details are Cedarras’s own responsibility, and this policy governs them directly.
What we collect
Your account. Your email address, and your name if you or your course owner provided one. Whether you have set a password yet. If you set a password, we store a one-way hash of it — never the password itself.
Your enrollment. Which courses you are a student of, when your enrollment started and ended, and whether it is currently active. Enrollment in Cedarras is driven by tags in your course owner’s Kit.com account: when your course owner tags you for a course, you become a student of it; when they remove the tag, your enrollment ends. If your course owner allows it, you can also sign up for a Cedarras account from their site. When you set your password, we add your email address to their Kit.com audience. Signing up does not by itself put you in a course — your course owner’s tag does.
Your progress. Which lessons you have marked complete and when. Which lessons you have opened, when you first and last opened each one, and how many times. When you started a course and when you finished it.
Your quizzes. For each quiz you take: the questions you were shown, the answers you chose, and your score. If a course is graded, your overall grade for it.
Email we send you. We email you when you are enrolled in a course, and when you ask for a link to set or reset your password. We keep a record of when each enrollment email went out. If mail to your address bounces or is reported as spam, we record that, along with the reason the receiving mail server gave, and we stop sending to it. We send no marketing email. If you are a course owner, we will also email you about material changes to this policy or our Terms of Service.
Your sign-ins. When you sign in and out, whether a sign-in attempt failed, the IP address and browser user-agent of the request, and when your session expired or was ended. We keep these records for one year.
Course content you are given. Files, videos and text your course owner publishes. Cedarras does not ask you to upload anything.
Technical records. Ordinary server logs, and error reports when something in the application breaks. An error report may include your user id and email address, so we know who was affected and can contact you.
Payment, if you pay us. Students never pay Cedarras — what you paid your course owner, if anything, is between you and them. Course owners on a paid plan pay us through Stripe, our payment processor. You enter your card on Stripe’s own pages; we never see or store your card number. What we keep is an identifier for your Stripe customer and subscription, whether that subscription is currently paid, and the date it next renews. Your receipts and invoices come from Stripe and live in Stripe.
We do not run advertising, we do not sell anything about you, and we do not use your data to train AI models.
Cookies
Cedarras sets one cookie, for your signed-in session, and uses a second short-lived token to protect forms against cross-site request forgery. Both are necessary to sign you in. There are no advertising or tracking cookies on Cedarras pages.
Your course owner may enable their own page analytics on their student pages (see “What your course owner can see”). Those measure page views only, and the data goes to the course owner, not to us.
Our own website, cedarras.com, measures page views with Fathom Analytics, which sets no cookies and honors your browser’s Do Not Track setting.
What you can see
Signed in, you can see and change your own name and password, see every course you are a student of across every creator using Cedarras, and see your own progress through each one. You can undo a lesson you marked complete.
You cannot see other students. Cedarras has no student directory, no comments, no discussion, and no way for one student to see another’s progress or existence.
What your course owner can see
Your course owner runs the account that publishes the course. In Cedarras itself, they can see:
- You, in their student list. Your name and email address, whether you have set a password yet, whether email to you is bouncing or was reported as spam (and the reason given), and when they last sent you an enrollment email.
- Your enrollment in each of their courses. Whether it is active or ended, when you started, and when you finished.
- Counts, not names, for everything else. How many of their students have enrolled, started, completed or gone quiet; how many reached each lesson; where students most often stop; how students did on each quiz, on average. Quiz averages and per-question results appear only once at least 5 students have taken a quiz, so they never reveal how one student answered. Cedarras does not show a course owner which lessons you opened, which you marked complete, or your quiz answers and scores.
- Nothing about your other courses, from any other creator. Your activity in one creator’s course is invisible to every other creator.
Three things are worth being direct about, because they are not obvious:
Your email address is already theirs. You are their Kit.com subscriber — that is how you got into the course. Your email address, your name, and the tags on you live in their Kit.com account, which they control and which is outside Cedarras. This policy cannot govern what they do there; their own privacy policy does.
Your progress can be sent to their Kit.com account. If your course owner sets it up, Cedarras adds tags to your Kit.com subscriber record when you start a course, finish a lesson, finish a section, or finish a course. It can also write your percent complete and your grade into fields on that record. Once it is in Kit.com, your course owner can see it there, per student, and it is governed by their policy, not ours.
They may run their own analytics. A course owner can connect their own Fathom Analytics site to their student pages. When they do, page views on those pages are measured by Fathom and reported to the course owner’s own Fathom account, under their own terms and privacy policy. Cedarras never sees that data.
What we can see
Our platform administrators can see everything stored in Cedarras. That is the honest answer, and it is what running the servers means. In practice we look at it to keep the service working, to investigate a problem, and to respond when a course owner or student asks us for help. We do not read it for any other purpose, and we do not share it with other creators or sell it to anyone.
Who else your data touches
- Amazon Web Services — hosting, databases, file storage, and sending email, in the United States (Oregon).
- Kit.com — your course owner’s audience platform, and the source of your enrollment. Cedarras reads your subscriber record and tags from the Kit.com account your course owner has connected. It also writes to that account: it adds you as a subscriber if you sign up yourself, and, if your course owner has set it up, it adds progress tags and your percent complete and grade.
- Honeybadger — error monitoring. Receives an error report when the application breaks, which may include your user id and email address.
- Fathom Analytics — on our own website, cedarras.com, for page views. And, only if your course owner has enabled it, on their own student pages, reporting to their Fathom account.
- Stripe — payment processing, and only for a course owner on a paid plan. Stripe receives their email address and their card details directly; we receive back only the identifiers and the paid/unpaid status described above. Students’ data is never sent to Stripe.
If your course owner has connected an AI assistant to their account, that assistant can read and write their course content, and read course-wide quiz averages (under the same rule). It cannot read any individual student’s records, enrollment, progress or quiz answers.
How long we keep things
- Your account and enrollment — for as long as the account exists. An ended enrollment is kept so your progress is not lost if your course owner re-tags you.
- Sign-in records — one year.
- Password links — a link to set a password works for 7 days; a password-reset link, for 1 hour. Each works once.
- Updates sent to Kit.com — the record of each one is kept for 30 days after it is delivered.
- Notifications from Kit.com — when Kit.com tells us a tag was added to or removed from you, we keep the notification for 30 days.
- Server logs — kept on our servers in size-limited files that are overwritten as new entries arrive, so older entries disappear on their own.
- Error reports — kept in Honeybadger for as long as our Honeybadger plan retains them, and deleted sooner when we no longer need them to fix a problem.
- Billing records — if you are a course owner who pays us, the Stripe identifiers on your account are kept for as long as the account exists. Your invoices are kept by Stripe under their own retention rules, not ours.
- Sessions — signed out after 30 days idle, and after 90 days regardless.
- Course content and files — until the course owner deletes them. Deleting a course deletes its files and its student records.
Your choices
You can change your name and password yourself, at any time, from your profile page. If you have not set a password, or have forgotten it, you can get a link to set one from the sign-in page.
To ask what we hold about you, to correct it, to have it deleted, or to get a copy of it, email us at support@cedarras.com. We first confirm the request comes from you — normally by replying to the email address on your account — and then respond within 30 days. For learning records we hold for a course owner, we may pass your request to them or act on their instructions, and we will tell you if we do.
Deleting your account removes your Cedarras record; it does not remove you from your course owner’s Kit.com audience, or remove progress tags and fields already sent there — for that, unsubscribe from their emails or ask them directly.
If you want out of a course, the fastest route is your course owner: enrollment is their tag, and removing it ends your enrollment.
If you are in the European Union or the United Kingdom
If the GDPR or the UK GDPR applies to you, a few more things are true.
Why we use your data. For learning records, the legal basis is your course owner’s, since we handle them on their behalf. For our own data, we rely on: contract, to give you the account and service you signed up for or were enrolled in; legitimate interests, to keep sign-in records, protect the service from abuse, and find and fix errors; and legal obligation, for billing records we have to keep.
Your rights. You can ask us for access to your data, a correction, deletion, a restriction on how we use it, or a copy in a portable, machine-readable form, and you can object to uses based on our legitimate interests. You also have the right to complain to your data protection authority. Use the address in “Your choices” above.
Where your data is. Cedarras stores and processes data in the United States (Oregon). Moving your data there is necessary to provide the service.
Course owners. If you are a course owner and need a data processing agreement for the student data we handle on your behalf, email support@cedarras.com and we will provide one.
Children
Cedarras is not intended for children under 13, and we do not knowingly collect information from them. Students aged 13 to 17 may use Cedarras only with a parent’s or guardian’s consent.
Changes
We may update this policy. The date at the top always says when it last changed. For a material change, we will email course owners at least 30 days before it takes effect.
Contact
Atchison Technology LLC — support@cedarras.com