Skip to main content

InSkillSecPrivacy policy

Privacy policy

Short version: we collect what an account and a certificate require, nothing else. There is no advertising, no analytics and no tracking on this site.

Last updated: 2026-08-10

Who is responsible

Haythem Rehouma, established in Québec, Canada, decides what personal data this site collects and why. For enquiries about your data, including access and deletion requests, write to privacy@inskillsec.com.

This policy applies to inskillsec.com and to the learning platform behind it. It does not apply to third-party sites we link to.

What we collect, and why

You can read every public page — the home page, the catalogue, the Arsenal, course previews, the blog — without an account and without giving us anything. Data collection starts when you create an account.

  • Email address. Required to create an account, to send you a sign-in code, and to reset a password. This is the only mandatory field.
  • First name and last name. Optional, and used for one purpose: printing your name on a certificate. If you leave them empty, you simply get no name on the certificate.
  • Password, if you choose one. Stored only as a salted hash by our authentication provider. We never see it and cannot recover it.
  • Google account identifier, if you choose to sign in with Google. We receive your email address and a technical identifier, nothing else — no contact list, no Drive access, no profile browsing.
  • Course enrolments. Which courses you enrolled in and when.
  • Course progress. Which lessons you marked as complete, and when.
  • Quiz attempts. Your answers, your score and the date of each attempt, so that a certificate can be earned rather than claimed.
  • Certificates issued. The certificate number, the course, the date, and the name to print on it.
  • Purchase records, if you buy something. What you bought, the amount, the currency, the date, whether the payment succeeded, and the identifiers our payment provider gives us so the purchase can be matched to your account. Never your card number, which we never receive.
  • Technical logs. Our hosting and authentication providers record IP addresses, browser user agent, requested URLs, and sign-in timestamps. These logs exist to keep the service running and to detect abuse.

We never see your card. Payments, when you make one, are handled entirely by Stripe Payments Canada / Stripe Inc., which is the sole recipient of your card details — they never reach our servers. What we keep is the record of the transaction: what you bought, the amount, the currency, the date, its status, and the identifiers Stripe gives us so that your purchase can be matched to your account. We keep that record for as long as accounting law requires, even after you delete your account.

We do not use Google Analytics, Meta Pixel, advertising networks, session recording, heatmaps or any other audience-measurement tool. The site sets no tracking cookie. See the cookie policy for the complete list of what is stored in your browser.

Legal grounds

  • Performance of a contract: creating your account, giving access to a course you enrolled in, recording progress, issuing a certificate.
  • Legitimate interest: keeping the service available, preventing abuse and fraud, and defending our rights if needed.
  • Consent: only where it is genuinely optional, such as signing in with Google or entering your name for a certificate. You can withdraw it by removing the data from your account page.
  • Legal obligation: keeping records we are required to keep, and answering lawful requests from authorities.

Certificates are publicly verifiable

A certificate is only worth something if an employer can check it. Anyone holding a certificate number can look it up on our verification page and see the name printed on it, the course, and the issue date. Nothing else is exposed — not your email, not your progress, not your quiz answers.

This is a deliberate disclosure and the reason the name field is optional. If you would rather not have your name publicly linkable to a certificate number, leave the name empty, or ask us to revoke the certificate.

Who processes your data

We use a small number of providers, each for a specific technical role. They act on our instructions and may not use your data for their own purposes.

ProviderPurposeLocationTheir policy
Vercel Inc.Website hosting and deliveryUnited StatesPrivacy policy
Supabase Inc.Accounts, database, course progress and certificatesUnited StatesPrivacy policy
Resend (Plus Five Five, Inc.)Sending transactional emailUnited StatesPrivacy policy
Google LLCOptional sign-in with a Google accountUnited StatesPrivacy policy
Stripe Payments Canada, Ltd. (Stripe, Inc.)Payments, card dataCanada and United StatesPrivacy policy

We do not sell personal data, we do not rent it, and we do not share it with advertisers or data brokers. Data is disclosed to a third party only where the law requires it.

International transfers

Our providers are established in the United States and your data is stored there. Where you are protected by European or United Kingdom data protection law, these transfers rely on the European Commission Standard Contractual Clauses included in our agreements with those providers. Where you are protected by Quebec or Canadian law, we assess each provider before entrusting data to it, as required.

How long we keep it

  • Account, progress and quiz history: for as long as your account exists. Delete your account and they go with it.
  • Certificates: kept after account deletion, in reduced form — certificate number, course, date, and the printed name — because a certificate that stops being verifiable is worthless. Ask us and we will revoke it instead.
  • Purchase records: six years after the transaction, and kept even if you delete your account, because tax and accounting law requires it. Deleting your account does not erase an invoice.
  • Technical logs: kept by our providers for a short period, typically thirty days, then discarded.
  • Email correspondence with us: up to three years, so that we can follow up on an earlier exchange.

Your rights

Whatever your country, you can ask us to do the following, and we answer within thirty days.

  • Access a copy of the data we hold about you.
  • Correct anything inaccurate — you can change your name and email yourself from your account page.
  • Delete your account and the data attached to it.
  • Receive your data in a portable, machine-readable format.
  • Object to a processing based on our legitimate interest, or restrict it.
  • Withdraw a consent you previously gave, at any time.

Send the request from the email address of the account, to:

privacy@inskillsec.com

If our answer does not satisfy you, you may complain to a supervisory authority: the Commission d’accès à l’information du Québec, the data protection authority of your country in the European Union, or the Information Commissioner’s Office in the United Kingdom.

Security

Traffic is served over HTTPS only. Passwords are hashed, never stored in clear. Database access is restricted row by row, so one account cannot read another account’s progress or certificates. Administrative access is limited to the operator. No system is beyond reach, so if you find a weakness, tell us at:

security@inskillsec.com

Children

This site teaches offensive security techniques and is not intended for children. You must be at least 16 years old to create an account. If we learn that an account belongs to a younger person, we delete it.

Changes

When this policy changes materially — a new provider, a new category of data, a new purpose — we update the date at the top of this page and, if you have an account, we notify you by email before the change takes effect.