Compendia

Privacy Policy

Last updated 23 August 2026

Compendia (“we”, “us”) runs learncompendia.com, where people read courses and work through graded problem sets. This page describes what we collect, why we collect it, and who else sees it. It describes what the service actually does rather than what it might one day do.

What Google gives us when you sign in

Compendia asks Google for three scopes and nothing else: openid, email, and profile. Between them they return your email address, your name, and the URL of your profile picture. That is the entire set.

We do not request, and therefore cannot read, your Google Drive, Gmail, Calendar, Contacts, Classroom, or any other Google service. There is no scope in the request that would permit it. We never receive your Google password.

Google also issues sign-in tokens, which are stored so that a session can be established. They are not used to reach any other Google service, because the scopes above do not permit one.

What we store

Account. Your name, email address, and profile picture URL. If an account is created with an email and password instead of Google, a hashed password — never a readable one.

Sessions. A session token, and the IP address and browser user-agent it was created from. That is security housekeeping: it is what lets an account tell its own sign-ins apart from somebody else’s.

Progress. Which lessons you have opened and which quizzes and problem sets you have passed, per course. A copy is kept in your browser’s local storage so the site works before it has heard back from the server.

Purchases. Which course was bought, the amount, the currency, and Stripe’s identifiers for the payment. We never receive or store a card number, expiry, or security code — those go directly to Stripe.

Code you run. Lessons let you run programs you write. Your code is executed in an isolated virtual machine that is created for that run and destroyed afterwards. It is not stored once the run finishes.

What we never do

  • We do not sell, rent, or trade personal information. There is no circumstance in which we would.
  • We do not serve advertising, and we do not allow anyone else to advertise here.
  • We do not use anyone's information for targeted advertising, on this site or anywhere else.
  • We do not build behavioural or advertising profiles.
  • We do not use student data, or anybody's code or answers, to train machine learning models.
  • We run no third-party analytics, no advertising pixels, and no cross-site trackers. The site loads no third-party script of any kind.
  • We do not disclose personal information to anyone except the processors listed below, or where the law requires it.

Schools and student data

Compendia is offered to Glendale Unified School District, and this section is the commitment that goes with it. Where a student signs in with a district account, we act as a school official with a legitimate educational interest under FERPA (20 U.S.C. § 1232g; 34 CFR Part 99), under the district’s direct control for the purpose of providing the service.

Pupil records stay the district’s. As required by California Education Code § 49073.1, any pupil record that reaches us remains the property of, and under the control of, the district. We claim no ownership of it. The district may inspect it, correct it, export it, or require its deletion, and we will act on such a request within 30 days.

SOPIPA. We comply with California’s Student Online Personal Information Protection Act (Business & Professions Code § 22584). We do not use covered information to target advertising, do not build a profile of a student except in furtherance of school purposes, do not sell covered information, and do not disclose it except as that Act permits.

Children under 13. Compendia is written for secondary-school and adult learners. Where a district provides accounts to pupils under 13, the district consents on the parent’s behalf under COPPA (15 U.S.C. §§ 6501–6506), as its agreement with Google Workspace for Education already contemplates. We collect from a child no more than we collect from anyone: an email address, a name, a picture URL, and what they have read. A parent or the district may ask us to review or delete it, and we will.

Minimum necessary. We ask Google for three scopes because three is what signing somebody in requires. We do not ask for a student identification number, a date of birth, an address, a phone number, a photograph, a grade, disciplinary information, or health information — and the district is not asked to send us any of it.

If something goes wrong. Should we discover a breach affecting district accounts, we will notify the district without unreasonable delay and in any case within 72 hours of confirming it, describing what happened, what was affected, and what we have done.

If this changes. We will not use district data for a new purpose without telling the district first. A district administrator with a question, an audit request, or a deletion request should write to theomirzakhanian@gmail.com.

Who processes data for us

Four providers, each acting on our instructions and none of them permitted to use your information for their own purposes. All data is held in the United States.

  • Google — sign-in only. Returns your name, email, and picture when you choose to sign in with it.
  • Stripe — payments. Handles the card details we never see, and tells us only that a payment succeeded and for what. Not used for accounts that pay nothing, which includes every district account.
  • Supabase — the database holding accounts, progress, and purchases.
  • Vercel — hosting, and the isolated virtual machines that run the code you write.

Cookies

One cookie, which keeps you signed in. It is not used for advertising and not used to follow you across other sites. During maintenance a second cookie may be set when an administrator uses a bypass link. There are no third-party cookies, because there are no third-party scripts.

How long we keep it

Account details, progress, and purchase records are kept while the account exists. Ask us to delete an account and we remove the account, its progress, and its session records within 30 days. We keep the minimum record of a completed purchase that tax law requires, and Stripe keeps its own transaction records independently of us. District accounts are deleted on the district’s request on the same 30-day basis, whether or not the account holder asks.

Your rights

Wherever you are, you may ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Depending on where you live you may also object to processing, restrict it, or complain to a data protection authority. Students and parents may exercise these rights directly or through the district. Write to theomirzakhanian@gmail.com and we will answer within 30 days.

Security

Connections are encrypted in transit. Passwords are stored hashed. The database is not reachable from the browser and is restricted to the single role the application uses, with row-level security enforced on every table. Code you submit runs in an isolated virtual machine created for that run and destroyed afterwards. Payment card details never reach our servers. No system is perfect and we do not claim otherwise, but we do not collect what we do not need, which is the part that actually reduces the risk.

Changes

If we change this policy the date at the top changes with it. A change that materially affects what we collect, who sees it, or what it is used for will be announced on the site, and notified to the district where district accounts are affected — not made quietly.

Contact

Questions, requests, complaints, or a district review: theomirzakhanian@gmail.com.