Privacy policy
How Darskoum collects, uses and protects your personal data.
Last updated: 3 August 2026
Who is responsible for your data
Darskoum operates this learning platform and decides how the personal data described below is handled. For any question about this policy or your data, write to darskoum@gmail.com.
What we collect
Account details
Your full name, email address, password (stored only as a bcrypt hash — never in readable form), role (student, instructor or admin), and anything you choose to add such as a biography, profile picture or preferred language.
Learning activity
The courses you buy, your progress through lessons, quiz attempts and scores, certificates issued to you, reviews you write, wishlist and cart contents, and posts or comments you publish in a course community.
Orders and payments
Payments on this platform are simulated: no card is ever charged and no bank is contacted. We store the order, its total, a payment reference and the last four digits of the number entered. Full card numbers and security codes are never written to our database or logs.
Technical data
When you sign in we record the IP address and browser user-agent alongside the session, so that sessions can be reviewed and revoked. Server logs may briefly contain the same information.
Files you upload
Profile pictures, and — if you teach — course thumbnails, videos, PDFs and images attached to posts or quiz questions. These are stored on the server hosting the platform.
Why we use it
- To create and secure your account, and to keep you signed in.
- To give you access to the courses you enrol in and to track your progress and certificates.
- To confirm your email address, which is required before a purchase can be made.
- To let you reset your password when you ask for it.
- To pay instructors the share they are owed and to process withdrawal requests.
- To keep the platform working and safe — rate limiting, moderation of reported content, and preventing abuse.
Cookies
Darskoum sets only the cookies it needs in order to function. There are no advertising, analytics or third-party tracking cookies, and nothing is shared with advertisers.
| Cookie | Purpose | Lifetime |
|---|---|---|
access_token |
Keeps you signed in between page loads. | 15 minutes |
refresh_token |
Lets your session be renewed without signing in again. | 30 days |
lang |
Remembers whether you are browsing in English, French or Arabic. | 1 year |
cookie_consent |
Remembers that you have seen the cookie notice, so it is not shown again. | 1 year |
You can delete cookies at any time from your browser settings. Removing the session cookies simply signs you out; removing the language cookie resets the interface to English.
Email we send you
We send email only for account matters: confirming your address and resetting your password. We do not send marketing email, and your address is never sold or shared for advertising. Messages are delivered through an external SMTP provider, which processes your address in order to deliver them.
Who can see your data
- Instructors can see the name and email of the students enrolled in their own courses, and the name attached to reviews and community posts on those courses.
- Administrators can see account records, orders and withdrawal requests in order to run the platform and handle reports.
- Other learners see the name and picture you attach to public activity: reviews, community posts and comments.
- We do not sell personal data, and we do not share it with advertisers.
How long we keep it
Account and learning records are kept for as long as your account exists. Order records are kept longer where needed for accounting. Session records expire automatically, and password-reset and email-confirmation tokens are deleted as soon as they are used or expire.
Your rights
Depending on where you live, you may have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate details corrected — most of this you can edit yourself from your profile;
- ask for your account and data to be deleted;
- object to or ask us to restrict certain processing;
- receive your data in a portable format.
To exercise any of these, write to darskoum@gmail.com. In Morocco, personal data processing is governed by Law 09-08 and you may also contact the CNDP. If you are in the EEA, the GDPR gives you these rights and the ability to complain to your local supervisory authority.
How we protect it
Passwords are hashed with bcrypt and never stored in readable form. Session tokens are held in HTTP-only cookies that JavaScript cannot read, and password-reset and email-confirmation tokens are stored only as hashes. Traffic is rate limited and requests are sanitised against injection. No system is perfectly secure, but we aim to keep the platform up to date and to fix problems quickly.
Children
Darskoum is not intended for children under 16. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
If this policy changes, the revised version will be published on this page with a new date at the top.
Contact
Questions about this policy, or a request about your data? Write to darskoum@gmail.com.