Privacy
Privacy policy
Effective 5 October 2026. This policy describes the edxCloud control plane at this website. It does not describe the Open edX site a campus runs for its own learners.
Two places data lives
A campus runs in the cloud account you connect, today DigitalOcean for the server, databases, and files. Learner accounts, enrolments, grades, course content, and uploaded files stay in that account. edxCloud does not host that database and does not receive a copy of it.
The control plane is the console you sign in to. It stores what it needs to deploy and operate the campus: your account, the workspace, deployment status, and the credentials you choose to connect.
What the control plane stores
- Your name, email address, password hash, and workspace role.
- Cloud account tokens, DNS tokens, and backup keys, encrypted at rest. They are not shown back to the browser.
- Server addresses, hostnames, deployment logs, health checks, and an audit log of actions taken in the console.
- The platform subscription: the plan, its status, and the customer id returned by the payment provider. Card numbers are not stored here.
Payments
The platform fee is collected by Creem, the merchant of record. Creem receives the billing email, the card, and the tax details the checkout asks for, and handles the invoice. DigitalOcean, Amazon, and Cloudflare bill their own services on the accounts you connect. Those invoices are not edxCloud invoices.
Cookies
The console uses a session cookie so you stay signed in, and a cookie that remembers the appearance setting. The public site does not run an advertising tracker.
How long it is kept
Account, workspace, deployment, and audit records are kept while the workspace exists and as needed to operate the service. High-volume monitoring samples and command output are deleted on the schedule published in the operations of the control plane. Closing a workspace does not delete the servers in your cloud account.
Who it is shared with
We do not sell personal information. We send a cloud or DNS provider the API calls you asked the console to make, using the token you stored. Creem receives the payment. Email that the console itself sends, such as an invitation or a password reset, goes through the mailer configured for the control plane.
Your requests
To ask for a copy of the account data the control plane holds, or to ask a question about this policy, email [email protected]. Sales questions go to [email protected].