Privacy Policy
Effective 15 August 2026
LectureMoment is operated by ZenXmind LLC. This page describes exactly what we collect. It is short because we collect little: there are no accounts, no advertising, no tracking cookies, and nothing is sold to anyone.
If you only browse and answer free questions
We store, in your browser and not on our servers:
- A random device id — a random string, not linked to your identity, used to spot one purchase being shared across many machines.
- Your progress — which questions you answered and whether you got them right, per pack, so a refresh does not lose your place. Kept for 30 days.
On our servers we record:
- Counters — how many people opened a pack, reached the paywall, or clicked through to checkout. These are totals per day, with no identifier attached. We cannot tell from them who did what.
- A hashed IP address — used to rate-limit abuse, and to stop one visitor voting repeatedly on which topic we build next. We store the hash, never the address itself.
If you buy
Payment is handled entirely by Stripe. We never see or store your card details.
From the completed payment we store:
- Your email address— to send your access link and to let you recover access later. If you paid using Apple’s Hide My Email, we only ever see the relay address Apple gives us, not your real one.
- Stripe’s payment and session identifiers, the amount, and the currency — so we can match a support request to a payment.
- A record of what you bought, so we know what to unlock.
We also record a hashed device id and hashed IP against your unlock token, to detect a single purchase being shared widely. The limits are set far above normal personal use.
Who else processes this
- Stripe — payments. They are the controller of your payment data; see their privacy policy.
- Supabase — our database, where the above is stored.
- Vercel — hosting, and cookieless page-view analytics that does not identify individuals.
- Cloudflare — DNS, security, and email forwarding for our contact address. Cloudflare also runs a cookieless visitor-count script on our pages.
- Resend — delivers the access email.
We do not use advertising networks and we do not sell or rent data to anyone.
Cookies
We set one cookie, after a purchase: it holds your unlock token so access survives your browser clearing local storage. It is httpOnly, so page scripts cannot read it, and it does nothing except unlock what you bought. We use no advertising or tracking cookies, which is why you are not being asked to accept any.
How long we keep it
Purchase records are kept as long as your access is valid, and as long as tax and accounting rules require. Abuse-detection counters roll off after a week. Funnel counters are aggregate and hold nothing about you. Browser storage is yours to clear at any time.
Your rights
You can ask us what we hold about you, ask for it corrected, or ask us to delete it. Email [email protected] and we will respond within 30 days.
Deleting your purchase record removes your access, since the record is what proves you bought it. We will say so before acting, so you can decide.
If you are in the UK or EU, our basis for processing is performance of a contract (giving you what you paid for) and legitimate interests (keeping the service working and preventing abuse). You may complain to your local data protection authority.
Children
This is not directed at children under 13, and we do not knowingly collect anything from them.
Changes
If this policy changes, the effective date above changes. We will not start collecting materially more than this without saying so here first.
Questions about any of this? Email [email protected].