Legal

Privacy Policy

Last Updated: September 24, 2026

Agentic Coding School is a trading name of Ray Amjad LTD (Company Number 14506459, United Kingdom). This Privacy Policy explains what personal data we collect and how we handle it.

What We Collect

  • Email: Used solely for our own communications:

    • Notifications when new lessons are published
    • Promotional emails about our classes and offers
    • Newsletter emails with my own thoughts about the agentic coding space

    When you create an account, you are opted in to these emails by default. You can manage each type independently in your account settings at any time, or unsubscribe from any email with one click. Your email is never sold, rented, or disclosed to third parties for their marketing purposes.

  • Order and billing info: Processed by our payment provider (Stripe) for purchases, refunds, and fraud prevention.
  • Unfinished checkout: If you start a purchase and do not complete it, we keep the email address you entered at the payment page, together with the discount code we issue you. We may send you up to three reminder emails about that purchase. This happens whether or not you have an account with us. Each of those emails carries a one-click unsubscribe link, and we send no further one after you use it.
  • Newsletter survey answers: When you confirm your newsletter subscription, we ask you four short questions: what your current role is, what you want an agent to do for you, one further question drawn from a set of thirteen, and finally a box asking, in your own words, what is the one thing you want your agent to do that it cannot do yet. The first two are a choice from a list. The third is usually a choice from a list, and is sometimes a box you type into. The last one is always a box you type into, it is optional, and you can leave it blank and move on.

    Your answers are stored against your account, including anything you type into a free-text box. We use them to decide what we teach and write about, and to choose which emails we send you. They are also sent to PostHog, and up to two tags are held against your contact in Bento: one for your role answer, and one marking you as somebody who may be buying for a team, which we work out from your role answer together with your answer to the second question. Both services are described under Third-Party Services below. They are deleted when your account is deleted.

  • Video searches: When you search the video library, we store the text of the search against your account, along with a count of its results, whether your account had access at the time, whether the search came from this site or from an MCP client you have connected to your account, any filter that client set for lessons you have or have not finished, and the time we recorded it. To find the lessons that match it, the text is sent to Google, and nothing that identifies you is sent with it. Everything in that record except your account identifier and our own timestamp also goes to PostHog, which attaches it to your account there and stamps a time of its own. Both services are described under Third-Party Services below. We use these records to understand how the service is used.

    On the site a search is recorded once you settle on it, and not once for every letter you type. On the search page that means when you stop typing, or when you open one of its results. In the Search every class box, only opening one of its results records the search. The record does not hold which result you opened. Google receives more than this: the site also searches while you are still typing, as the Google Gemini entry under Third-Party Services below describes.

  • Technical and usage data: We automatically collect the following when you use the service:

    • IP address
    • Device type, browser, and operating system
    • Pages visited, videos watched, and time spent
    • Access patterns and streaming behaviour
    • Interactions with the site, including clicks, scrolls, and navigation paths
    • Network and connection data, described in the next section
    • A device identifier, stored in a cookie on your browser, which lets us tell one machine from another on the same account. It is also one of the signals used to limit how many accounts can be created and how fast videos can be started, counted across every account signed in on that browser, as described under Automated Decision-Making below
    • A record of each sign-in, holding the date, your IP address, your country, your browser, and that device identifier
    • The country your connection resolves to, and the time zone your browser reports, used to decide whether a regional discount applies to you

    This data is used for account security, abuse detection (including scraping and account sharing), fraud prevention, understanding how visitors use the site, and product improvement.

Network and Connection Data

When your browser or player requests a page or a piece of video, we record details of the connection itself, beside the request:

  • The network provider your connection belongs to, its network operator name, and the approximate city and country it resolves to
  • The internet protocol version used, the status of each request, and the amount of video data transferred
  • Standard request headers your browser sends, such as the page you came from and your preferred language
  • Characteristics of the encrypted connection your client negotiates with us: the protocol version, the cipher agreed, a one-way hash of the cipher and extension lists your client offers, and the size of its opening message

We use the last of these to tell software apart, not to tell people apart. Every copy of the same browser produces the same values, so they cannot identify you, and they change when your browser updates. What they do show is one account streaming under two different clients at once, which is how a shared login and a download tool both appear. No account is ever suspended on this alone.

Our video player records diagnostic sessions through PostHog. A session may include the address, timing, and outcome of the network requests the page made, and the browser console messages our player writes. Request and response bodies are discarded before they are sent, apart from the video playlist itself, and credentials, signed links, and email addresses are removed from the addresses and headers that are kept.

If our systems see a fetching pattern that does not look like somebody watching a lesson, we may ask you to complete a human verification check (Cloudflare Turnstile) before your player is given its next playback token. Your IP address and the answer to that check are sent to Cloudflare to be verified.

We check your IP address against two IP intelligence services, IPinfo and proxycheck.io, which tell us the network it belongs to, the country it resolves to, and whether it belongs to a data centre or to an anonymising service such as a VPN, a proxy, Tor, or a private relay. We use that answer for two things: deciding whether a connection qualifies for our regional pricing discount, and investigating suspected misuse of course material. Each address is checked at most once a day, and the answer is held for a day so we do not ask again.

An anonymising or data-centre connection is refused the regional pricing discount. It is not blocked from the site, nothing is recorded against your account, and turning the service off and reloading the page is enough to be offered the discount again.

We are currently comparing those two services against each other. For that comparison we keep a record of what each one said about a connection. That record holds no account identifier and no full IP address: the address is shortened first, so it identifies a block of up to 256 addresses rather than your connection. We expect to keep the comparison running until October 2026.

Third‑Party Services

We use a limited number of third‑party services to operate. We do not sell, rent, or otherwise disclose your personal data to third parties for their own purposes.

  • Stripe: payment processing. Receives billing and order information needed to complete your purchase. See Stripe's privacy policy for details.
  • Polar: payment processing, for purchases made before 10 January 2026. Polar was the seller of record then, so it holds the billing and order information for those purchases and still serves the billing page for them. No purchase made since that date reaches it. See Polar's privacy policy for details.
  • PostHog: product analytics and user experience tools. Collects usage data, behavioural insights, and interaction data to help us understand how visitors use the site and improve the experience. Also records session replays of video playback problems, including the network requests the page made and the browser console messages our player writes, as described under Network and Connection Data above. A company training enquiry is recorded there as well, so that we can see how many enquiries a page produced: that record holds your work email address, the domain of it, your team size, your job title, what the classifier said, and, from a page opened before 19 September 2026, the company and timeline that form asked for. It does not hold what you wrote about your team. It also receives a copy of each search we record in the video library, attached to your account, as described under Video searches in What We Collect above. See PostHog's privacy policy for details.
  • Microsoft Clarity: session replay and heatmap analytics. Records anonymised user sessions (clicks, scrolls, and page interactions) to help us identify usability issues and improve the site. Sensitive content is masked by default. See Microsoft's privacy statement for details.
  • Axiom: playback security logging. Records video playback events together with your IP address, network provider, approximate location, browser, and account identifier, so we can find shared accounts, scraping, and other misuse of course material. Each event also carries the device identifier and the connection characteristics described under Network and Connection Data above. See Axiom's privacy policy for details.
  • Cloudflare: video delivery, storage, and abuse protection. Serves every video request, which means it sees your IP address, your connection details, and what you requested. It also runs the human verification check described above. See Cloudflare's privacy policy for details.
  • Sentry: error monitoring. Receives a report when something breaks, holding the error, the page it happened on, and your account identifier. We send no name and no email address to it. See Sentry's privacy policy for details.
  • Bento: email delivery and marketing. Holds your email address, your email preferences, and a record of the emails we sent you, so that account, lesson, and newsletter emails can be delivered. It also holds the tags we keep against your contact, which is how we send a newsletter to the people it is for rather than to everybody. Two of those tags come from the newsletter survey described under What We Collect: the one for your role answer, and the one marking you as somebody who may be buying for a team. See Bento's privacy policy for details.
  • SendGrid (Twilio): email delivery. Sends the account emails Bento does not: the sign-in link, the password reset, the email-change notice, the welcome email, and a team invitation. It receives your email address and the contents of that message. See Twilio's privacy policy for details.
  • Rewardful: affiliate tracking. Records that a purchase followed an affiliate link, so the affiliate can be paid. See Rewardful's privacy policy for details.
  • Vercel: website hosting. Serves the site, so it processes your IP address and your requests. It also relays the requests our server makes to Microsoft Azure, described below. See Vercel's privacy policy for details.
  • PlanetScale: database hosting. Stores our database, which holds your account record. See PlanetScale's privacy policy for details.
  • Trigger.dev: background jobs. Runs scheduled work such as sending lesson notifications and processing uploaded video, and handles account data while doing so. See Trigger.dev's privacy policy for details.
  • IPinfo: IP intelligence. Receives your IP address and returns the network it belongs to, its operator and country, and whether it is a data centre or an anonymising service. We send no name, no email address, and no account identifier. Used for regional pricing eligibility and abuse investigation, as described under Network and Connection Data above. See IPinfo's privacy policy for details.
  • proxycheck.io: IP intelligence. Receives your IP address and returns the same kind of answer as IPinfo, which we compare against it. We send no name, no email address, and no account identifier. The answer is not stored against your account, and it never suspends anything. See proxycheck.io's privacy policy for details.
  • Upstash: caching and rate limiting. Holds short-lived records keyed by your IP address or by your email address, so that the discount check above is not repeated on every page and so that sign-in links cannot be requested in bulk. It also holds the counters behind the limits on how many accounts can be created and how fast videos can be started, not only the limit on how often sign-in links can be requested. A counter records only how many times something happened, and it is keyed by whatever that limit counts against, such as the device identifier described above, your IP address, your email address or your account identifier. Each one expires by itself, and none is kept longer than about twice the period it covers. Those limits are described under Automated Decision-Making below. See Upstash's privacy policy for details.
  • Discord: the student community. If you choose to link your Discord account, we store the identifier Discord gives us and the token that lets us add you to our server, and we send that identifier to Discord to add you and to remove you again. We do not read your messages. Unlink it in your account settings at any time. See Discord's privacy policy for details.
  • Zoom: the live office hours. We create each session's meeting on our own Zoom account, sending Zoom the session's title, start time and length, and we show members the link to join. We do not send Zoom your name, email address or any other account details. If you join a session, Zoom receives what you give it there, such as the name you enter, your audio and video if you turn them on, and anything you post in the chat. Sessions are recorded to our Zoom account from the start, and the recording is edited and shared with other students. See Zoom's privacy statement for details.
  • Slack: company training enquiries. If you send the enquiry form on our company training page, the name, job title, work email address, and team size you give, and what you write about how your team works, are delivered to our own Slack workspace so that we can reply, together with what the classifier below said about the enquiry. The form asked for a company and a timeline until 19 September 2026, and a page opened before that date still sends those two: we deliver them with the rest rather than refuse an enquiry that was typed in good faith. That form is the only thing that reaches Slack. See Slack's privacy policy for details.
  • TypeSafe AI: screening company training enquiries. An enquiry is sent to its Jev model as the name and job title you typed, the domain of your work email address, how many engineers you chose, and what you wrote about how your team works, and the answer is how likely it is that you are enquiring for a team. Your email address itself is never sent: the domain goes, the rest of the address does not. That answer decides only whether the booking calendar opens for you there and then, as described under Automated Decision-Making below. See TypeSafe AI's privacy policy for details.
  • Cal.com: booking the company training scoping call. When your enquiry is offered the calendar, the calendar is loaded from Cal.com into the page you are on, so Cal.com sees your connection and that page before you have booked anything. We fill the booking in for you, so it also receives your name, your full email address, and what you wrote about your team. Nothing is booked until you pick a time, and closing the page leaves your enquiry with us and no booking made. See Cal.com's privacy policy for details.
  • Google Gemini: search relevance. When you search the video library, the text of the search is sent to Google's Gemini embedding API, which turns it into the numbers we match against the lessons. We attach nothing that identifies you: no name, no email address and no account identifier, and the request is made by our server rather than by your browser. The words are your own, so whatever you put in them is sent as you wrote it. The site also searches while you are still typing, before you have settled on one, so Google receives more search text than we record. A search run by an MCP client you have connected to your account is sent the same way. See Google's privacy policy for details.
  • Microsoft Azure (OpenAI models): explanations of terms in lesson transcripts. When you tap a highlighted term in a transcript, the term, the follow-up questions you type under it, the answers already given in that conversation, and the lesson's title, transcript and summary go from our server, through Vercel's AI Gateway, to an OpenAI model that Microsoft Azure runs, which writes the explanation. We attach nothing that identifies you: no name, no email address and no account identifier, and the request is made by our server rather than by your browser. Vercel sends these requests only to a provider that has agreed with Vercel not to keep the data (zero data retention) and not to use it to train models. The words are your own, so whatever you put in a question is sent as you wrote it. See Microsoft's privacy statement for details.

Cookies

Our website and payment pages may use cookies and local storage for checkout, authentication, license management, and analytics.

The ones we set ourselves are:

  • Session: keeps you signed in.
  • Device: a random identifier for this browser, kept for one year, used to tell one machine from another on the same account. It is not readable by scripts on the page. It is also one of the signals used to limit how many accounts can be created and how fast videos can be started. The count kept against this identifier is per browser and covers every account signed in on that browser; other counts behind the same limits are kept against your internet connection and against your account, as described under Automated Decision-Making below.
  • Referral: records where you first arrived from, kept for one year, so a campaign or an affiliate can be credited for a purchase.
  • Preference: remembers choices such as your light or dark theme.
  • Country: the country your connection resolves to, kept for one day, so the first price you see already carries the tax and the regional discount that apply where you are.
  • Sign-in method: which method you last signed in with, and the date, kept for one year, so the sign-in page can offer you that method first. It holds no password and no token.

The third-party services listed above set cookies of their own.

Company Logos

If you use a company email address or invoice your purchase to a company, your company's logo may appear on our homepage to show where our students work. Your identity is never revealed to your employer or any third party. We only display the company logo, not who from that company is enrolled.

Automated Decision-Making

We use automated systems to detect account sharing, content scraping, and other violations of our Terms of Service. These systems may automatically suspend your account without prior human review. If you believe a decision was made in error, you have the right to request a human review by contacting us at r@rayamjad.com.

Whether your connection qualifies for the regional pricing discount is also decided automatically, from the IP intelligence check described above. That decision affects the price you are offered and nothing else: it suspends nothing and blocks nothing. You can change it yourself by turning off a VPN, a proxy, or a private relay and reloading the page.

Whether the booking calendar opens for a company training enquiry is also decided automatically, by the classifier described above. It reads the name, the job title, the email domain, the team size and what you typed about your team, and the page then either shows you the calendar or tells you we will reply by email. That decision changes nothing else. Your enquiry reaches us either way, and it reaches us before the decision is applied, so an answer we do not like, and no answer at all, both mean the email rather than the calendar. If you would rather pick a time than wait for the email, contact us at r@rayamjad.com.

How often a sign-in code may be asked for, how many accounts may be created, and how fast videos may be started are also decided automatically, by counting requests and refusing the ones that are over a count. Which counts apply depends on how you sign in, sign up or watch, and more than one of them can apply to a single request. A count is kept against things such as your email address, the device identifier described above, your IP address, or your account. A count kept against the device identifier covers every account signed in on that browser. A count kept against your IP address can be reached by somebody else on the same office, campus or home connection.

A refusal is not always visible to you. Usually it is: the page says the limit has been reached and asks you to wait. But a request for a sign-in code that is over a limit on how many accounts may be created is answered as though the code had been sent, and no code arrives.

These decisions are rate limits and nothing more: they add nothing to your account record and they suspend nothing. Every counter behind them expires by itself. None is kept longer than about twice the period it counts over, and none longer than about two days, measured from the first request that counter counted. If you think you were refused in error, contact us at r@rayamjad.com.

Children's Privacy

Our classes are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us to delete it.

Your Rights

You may request access to, correction of, or deletion of your personal data at any time.

  • Account deletion: If you have never purchased, you can delete your account from your account settings. When you do, your personal data is permanently removed from our database. Playback security logs are the one exception, and are preserved. A record of a checkout you started and did not complete is a second one: the row stays, with its link to your account removed, and we erase it on request. A record of a search you ran is a third one: the row stays, with its link to your account removed, and we can only erase it on request while your account still exists. See Data Retention below.
  • Subscriptions and past purchases: If you have an active subscription, or have purchased from us at any point, please contact us at r@rayamjad.com to arrange account deletion. We keep purchase records while they are needed for legal, tax, or accounting obligations.
  • Retention exceptions: Some information may be retained where required for legal, tax, or accounting obligations, or where we need it to protect course material against misuse.
  • Right to complain: You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your personal data in accordance with applicable law.

Data Retention

  • Account data: Retained while your account is active and deleted when you delete your account.
  • Billing records: Retained for up to 7 years after the transaction date, as required by UK tax and accounting law.
  • Analytics data: Retained in accordance with PostHog's and Microsoft Clarity's respective data retention settings.
  • Sign-in and device records: Retained while your account is active and deleted when your account is deleted.
  • Newsletter survey answers: The answers you give on the newsletter confirmation page, the free-text one included. Retained while your account is active and erased with it when you delete your account. What PostHog holds follows the analytics retention above, and we ask Bento to delete your contact, and the tags on it, when your account is deleted.
  • Unfinished checkout records: The email address you entered at the payment page, the discount code we issued you, and which reminders were sent. Kept as the record of an order that was started, including after you complete the purchase. Preserved when you delete your account, with its link to your account removed. Write to us to have one erased.
  • Search records: The text of a search and the rest of what we store with it, as described under Video searches in What We Collect above. No fixed retention period: nothing deletes them on a schedule. Preserved when you delete your account, with their link to your account removed, so write to us while your account is open to have yours erased. The copy PostHog holds is a separate record, it keeps your account identifier, and it follows the analytics retention above.
  • IP intelligence records: The answer about an IP address is held for one day and then discarded. The record kept for the comparison between the two services holds a shortened address and no account identifier, so it cannot be traced back to you, and it is deleted when the comparison ends.
  • Playback security logs: Retained for up to 24 months from the date of the event, and preserved when you delete your account. We rely on these logs to find and to prove misuse of course material, so we do not delete them on request. They are never used to contact you or to build a marketing profile.

Security

We implement reasonable technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

International Transfers

Our payment and licensing providers may process limited personal information in multiple countries, including the United Kingdom, the European Economic Area, and the United States. Where required, appropriate safeguards are used by those providers. The text of a video library search is also sent to Google's Gemini embedding API, described under Third-Party Services above, and may be processed outside the United Kingdom and the European Economic Area. What you share in a live office hours session on Zoom, described there too, may likewise be processed outside the United Kingdom and the European Economic Area. What is sent to Microsoft Azure to explain a transcript term, also described there, is processed in the United States.

Changes to This Policy

We may update this policy. If we make material changes, we will update the date above and, where appropriate, notify recent purchasers.

Contact

Agentic Coding School, a trading name of Ray Amjad LTD (Company Number 14506459, United Kingdom).

General and data protection inquiries: r@rayamjad.com