Last updated: June 29, 2026
DR.LEARNING adheres to the principle of data minimization. We collect only the personal data that is necessary for the operation of the Platform and the delivery of educational services. We do not collect sensitive categories of personal data (such as health information, biometric data, political opinions, or religious beliefs) unless voluntarily provided by you in course discussions or AI chat interactions, in which case such data is promptly pseudonymized. We do not engage in bulk data collection, data scraping, or the indiscriminate storage of user communications beyond what is strictly required for the functionality you use.
When you create an account, we collect: your full name, email address, a password (stored as a salted hash), your role (student, instructor, parent, etc.), and optional profile information such as a profile picture and phone number. When you enroll in courses or make purchases, we collect billing name and address, transaction records, subscription plan type, billing frequency, and payment status. When you use the Platform, we collect usage data including pages visited, time spent, course progress, feature interactions, playback logs, and assessment results.
To protect instructor content and deter unauthorized recording or sharing, the Platform displays a runtime watermark overlaid on all video content during playback. The watermark displays your first name and a masked identifier — NOT your full email address. For example, a user named 'Ahmed Mohamed' with email 'ahmed.mohamed@example.com' will see 'Ahmed — a*******@e****.com'. This is a deliberate privacy-minimized design: the full email address is never rendered in the watermark. The watermark is generated server-side at the start of each viewing session and is session-specific. No persistent record of the rendered watermark content is stored after the session ends.
The Platform records playback activity for each video session, including: session start and end timestamps, total watch duration, seek events, pause and resume events, playback speed changes, and video quality selections. Playback logs are used to calculate Qualified Watch Time for the Learning Share Engine, to detect fraudulent or automated viewing activity, to diagnose streaming performance issues, and to improve the learning experience. Playback logs are retained in aggregate form for analytics purposes for 36 months. Individual session logs are deleted or pseudonymized after 6 months.
All video content is delivered through Signed URLs — time-limited, token-authenticated streaming links. Each Signed URL contains an encrypted token that encodes: the student's user ID (not email or name), the specific video or lesson identifier, a session timestamp, and an expiration timestamp. The Platform's CDN and video streaming infrastructure process these tokens to verify authorization before serving any video content. Signed URL tokens are short-lived (typically 1–4 hours) and are not stored in logs or databases after expiration. Token generation and verification are performed automatically by the streaming infrastructure; no human access to token contents occurs.
The Platform employs forensic anti-piracy measures to investigate unauthorized distribution of course content. If content protected by runtime watermarking is found on third-party websites or file-sharing networks, the Platform may extract the watermark from the leaked recording to identify the session and account associated with the leak. This forensic analysis is initiated only after a confirmed piracy report and is conducted in compliance with applicable data protection laws. The watermark data extracted during forensic analysis is used exclusively for piracy investigation and enforcement action and is not retained beyond the conclusion of the investigation.
The student identity watermark displayed during video playback is generated using only your first name and a masked email identifier. The masking process replaces all characters after the first character of the local part (before the @) with asterisks and replaces the domain name with its first character followed by asterisks and the TLD. For example: 'Ahmed — a*******@e****.com'. This ensures that even if the watermark is captured in a screen recording or photograph, the viewer cannot reconstruct your full email address or full name. The Platform never displays full email addresses, full names beyond the first name, phone numbers, or account identifiers in the runtime watermark.
All payment processing on the Platform is handled by our trusted third-party payment providers: Paddle and Stripe. Paddle acts as the Merchant of Record for all card payments, which means Paddle processes, settles, and is responsible for all payment transactions, including refunds and chargebacks. Stripe is used for additional payment method processing. When you make a payment, these providers receive your billing name, billing address, email address, IP address, transaction amount, and order details. Your full credit card number, CVV, and expiration date are processed directly by the payment provider's systems and are never stored on the Platform's servers. The Platform retains only transaction identifiers, payment status, the last four digits of your card, and the payment method type. For detailed information, refer to Paddle's Privacy Policy and Stripe's Privacy Policy.
The Platform uses automated fraud detection systems to identify and prevent unauthorized, fraudulent, or abusive activity. These systems analyze: payment patterns, IP address geolocation, device fingerprints (browser type, operating system, screen resolution), behavioral patterns (navigation speed, click patterns), and account activity anomalies (multiple accounts from the same device, unusual login locations). Fraud detection data is processed in real time and retained for a maximum of 12 months. Automated decisions may result in payment holds, account restrictions, or transaction reviews. You may request a manual review of any automated fraud detection decision by contacting our support team.
The Platform maintains security logs for all user accounts. These logs record: login timestamps and IP addresses, logout events, failed login attempts, password change requests, profile modification events, payment method changes, session token issuance and revocation, and account status changes (suspension, termination, reactivation). Security logs are retained for 12 months and are accessible only to authorized Platform personnel for security incident investigation and account recovery purposes. Logs are stored in tamper-evident storage and are reviewed periodically for suspicious patterns.
For instructors, the Platform maintains financial records including: Learning Share Engine earnings calculations, Qualified Watch Time logs, payout history and withdrawal requests, emergency withdrawal records, tax identification information (where required for compliance), and banking details for payout processing. Instructor finance records are retained for the duration of the instructor's account and for 7 years thereafter to comply with tax and financial reporting obligations. Instructor financial data is not used for any purpose other than calculating and processing compensation under the Instructor Agreement and Learning Share Engine. Instructor banking details are stored in encrypted form with restricted access.
DR.LEARNING does not sell, rent, lease, trade, or otherwise monetize your personal data. We do not share your personal data with third parties for their own marketing or advertising purposes. We do not engage in behavioral advertising, cross-context behavioral tracking, or the creation of advertising profiles based on your educational activity. The only instances in which we share personal data are: (a) with our authorized service providers (payment processors, CDN providers, email delivery services, AI providers) who need the data to perform services on our behalf, under strict data processing agreements; (b) when required by law, regulation, or valid legal process; (c) with your explicit consent for a specific purpose.
You have the following rights regarding your personal data under applicable Egyptian data protection requirements: the right to access your personal data held by the Platform; the right to request correction of inaccurate or incomplete data; the right to request deletion of your personal data, subject to legal retention obligations; the right to restrict or object to processing of your data; the right to data portability where applicable; the right to withdraw consent where processing is based on consent; and the right to lodge a complaint with the competent data protection authority. To exercise any of these rights, contact us at the email address below. We will respond within 30 days of receiving your verified request.
We retain your account data for as long as your account is active. Upon account deletion, personally identifiable information is removed or pseudonymized within 90 days, except where legal, regulatory, or financial obligations require longer retention. Playback logs and analytics data are retained in aggregate form for up to 36 months. Instructor financial records are retained for 7 years after account closure. Security logs are retained for 12 months. Fraud detection data is retained for 12 months. Signed URL tokens are not retained after expiration. Watermark rendering data is not retained after the viewing session ends.
We implement technical and organizational security measures to protect your personal data, including: encryption in transit (TLS 1.3) and at rest (AES-256), access controls based on the principle of least privilege, regular security audits and penetration testing, pseudonymization and anonymization of data where possible, automated anomaly detection for security incidents, and secure data center infrastructure. Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. We will notify you and applicable regulators of any data breach involving your personal data within the timeframes required by law.
We use essential cookies for authentication and session management. These are necessary for the Platform to function. Analytics cookies help us understand how you use the Platform to improve your experience. You may control cookie preferences through your browser settings. Disabling essential cookies may prevent the Platform from functioning correctly. We do not use advertising cookies, third-party tracking cookies, or social media tracking pixels.
Our AI tutor, study planner, and recommendation engine process your chat messages, course history, and learning preferences to generate personalized responses and suggestions. Conversations are stored to improve AI quality and are processed in accordance with our AI Provider's data processing terms. You should not share sensitive personal information in AI chat sessions. AI conversation data is pseudonymized and retained for up to 12 months.
For privacy inquiries, data access requests, correction requests, deletion requests, or complaints, contact our data protection team at office@drlearningacademy.com or write to us at: DR.LEARNING — CAREER STATION, Egypt. We will acknowledge receipt of your request within 5 business days and respond substantively within 30 days.