Skip to main content
Back to Home
Data Protection & Privacy

Privacy Policy

Last updated: September 2026 • Version 2026-09-23 • Prodily PM Academy

Core Privacy Principle

Prodily PM Academy is designed around learner data ownership and privacy. We do not sell, rent, or trade your personal data. Your learning progress, spaced-repetition (SRS) records, quiz answers, and private reflection notes belong strictly to you.

1. Data Controller & Scope

This Privacy Policy applies to the web application, APIs, and educational services operated under Prodily PM Academy ("the Service", "we", "us", "our"). It explains what information we collect when you access our platform (https://prodily.adityagangwani.me), how that data is stored and used, and the rights you have regarding your information.

Who controls your data

Prodily is operated by Aditya Gangwani as a sole proprietor. Prodily is not a separately incorporated company or registered entity. Operating address: 68 Bapu Bazaar Jaipur, Rajasthan, 302003.

Accounts are created only by individuals who confirm at signup that they accept these documents and are of the minimum age stated in the Terms of Service. The acceptance is recorded with a timestamp and the version of the documents shown.

2. Information We Collect

To deliver an interactive, gamified 90-lesson Product Management learning experience, we process specific categories of data based on your platform interactions:

  • Authentication Credentials: When registering, we store your email address and authentication identity securely.
  • Learner Profile: Your optional display name, handle (username), avatar image, bio, target role, target company, career stage, and professional links (LinkedIn, GitHub, Twitter). Profiles are private by default unless you explicitly enable public portfolio sharing.
  • Learning Activity & Progress: Completed lesson records, quiz attempt scores, total XP earned (recorded via an immutable progress ledger), active streaks, spaced-repetition (SRS) flashcard schedules, lesson bookmarks, and private self-reflection notes.
  • Capstones & Certificates: Draft and submitted module capstone projects, earned achievement badges, and issued completion certificates. Each certificate is identified by a unique, randomly generated certificate code (`PMA-2026-XXXXXX`). Verification works by looking that code up against our certificate registry — there is no cryptographic hash or signature embedded in a certificate, and the code itself is the identifier.
  • Support & Feedback: Messages and ratings submitted through our feedback tools or direct support communications.

3. How We Use Your Information

We process your data strictly to operate and improve the educational service:

  • Persisting your lesson progress, streak counters, and Skill Radar competency analytics across devices.
  • Scheduling spaced-repetition (SRS) review queues for active flashcards.
  • Issuing verifiable digital completion certificates and rendering optional public portfolios (`/p/[username]`).
  • Sending essential transactional emails (account verification, password resets, level-up milestones, and weekly recaps) via Resend.
  • Maintaining platform security, rate limiting, and preventing automated abuse.

4. Data Security & Row Level Security (RLS)

We implement industry-standard technical controls to ensure your data remains confidential and secure:

  • Row Level Security (RLS): 100% of user-owned database tables in Supabase enforce strict RLS policies. Your learning progress, reflection notes, and settings can only be accessed by your authenticated session.
  • Secure Cookie Transport: Authentication session tokens are stored in HTTP-only, encrypted cookies (`SameSite=Lax`, `Secure` in production) to prevent client-side XSS extraction.
  • Zero Client Secret Leaks: Administrative service keys are restricted strictly to server-side API routes and are never bundled into client browser JavaScript.

5. Third-Party Service Subprocessors

We work with a minimal set of trusted cloud infrastructure providers:

Supabase Inc. (Database & Auth Infrastructure)

Stores encrypted user profiles, application state, and handles authentication sessions.

Resend Inc. (Transactional Email Delivery)

Processes recipient email addresses strictly for delivering system notifications and transactional emails. We honor direct unsubscribe preferences on non-critical categories.

Google Analytics 4 (Aggregate Usage Metrics)

Measures anonymous navigation flows (`curriculum_view`, `hero_cta_click`). GA4 is configured with default IP anonymization and collects zero PII (no emails, names, quiz responses, or reflection text). GA4 and Google Tag Manager are not loaded at all unless you accept optional cookies — see §6.

6. Cookies & Local Storage

Strictly necessary — always on

  • Authentication session cookies (`sb-access-token`, `sb-refresh-token`): HTTP-only cookies required to keep you signed in. Without them the Service cannot function, so they are not subject to consent.
  • Cookie preference cookie (`prodily_cookie_consent`): Records the choice you make in the cookie banner, for 180 days, so we do not ask again.
  • Local storage preferences: UI theme selection (`dark`, `light`, `system`), active tab state, and a client-side curriculum search index cache. Stored in your browser only and never sent to us.

Optional — set only after you accept

None of the following is loaded or set until you choose "Accept optional" in the cookie banner. If you reject, the scripts are never injected and the cookies are never written. You can change your choice at any time using the Cookie preferences control in the site footer.

  • Google Analytics 4 (`_ga`, `_ga_*`): Aggregate, PII-free usage measurement — which pages and CTAs are used. Duration: Up to 2 years.
  • Google Tag Manager: Tag container, loaded only when configured by the operator. Duration: Session.
  • `prodily_referrer`: Remembers which learner referred you, so a referral can be credited after signup. Duration: 30 days.

7. Permanent Account Deletion & Rights

You retain full right to access, export, or permanently delete your account data at any time:

  • Self-Service Permanent Deletion: Navigating to Settings → Danger Zone → Delete Account triggers a hard cascading deletion. This permanently purges your user profile, progress rows, XP events, capstone drafts, SRS flashcards, reflection notes, and deletes your identity from Supabase Auth.
  • Data Export & Rectification: You may update your profile details at any time via Settings or contact support to request a copy of your personal data.

8. Grievance & Privacy Contact

Questions about this Privacy Policy, requests to access, correct or delete your data, and complaints about how your data has been handled all go to the contact below. We acknowledge every request within 7 days of receipt and aim to resolve it within 30 days.

Founder & Grievance Officer

Aditya Gangwani

68 Bapu Bazaar Jaipur, Rajasthan, 302003

hello@prodily.adityagangwani.me

This Privacy Policy reflects a September 2026 internal legal and privacy audit and is pending review by qualified counsel before the Platform's final public launch. It is the operator's current, good-faith description of how the Service handles data, not legal advice.