Privacy Policy
Last Updated: August 8, 2026 · Effective: August 8, 2026
1. Who We Are
learnwleo.com is operated by Pathion Inc. ("we," "us," "our," or "Company"), operating as LILO Learning.
This Privacy Policy explains what we collect, why, how long we keep it, and what choices you have.
Two kinds of users. Some of you signed up directly. Others use the platform because your school or instructor made it available as part of a course. The rules differ, so where they do, we say so. See Section 12: Students Enrolled Through an Institution.
2. What We Collect
2.1 You give us
- Account: email address, full name, profile picture, email verification status (via Google OAuth)
- Learning activity: code you write and submit, test and execution results, assignments and projects completed, time spent, study plan preferences, custom test cases, pre- and post-problem reflections
- You submit: bug reports (with screenshots or video), feature requests, course feedback and ratings, resume uploads (Academy), support messages
- Outcome information you provide: graduation year, job search status, offers received. We may ask you about this during and after the program. Answering is voluntary. If you are enrolled through an institution, outcome information you provide may be shared with that institution — see Section 12.
2.2 Collected automatically
- Learning behavior: run and submit counts per session, code changes after failed tests, time on task, tab-switch frequency, large-paste detection, engagement scores
- Session recording: we record browsing sessions via Mixpanel. Password fields are masked and never recorded. You can turn this off in account settings.
- Usage: pages visited, features used, interactions, referral source
- Device: device type, operating system, browser family and major version, session ID
What we no longer collect: we previously logged full IP addresses and complete user-agent strings. We stopped. IP addresses are truncated (last octet removed) and used only transiently for rate limiting and abuse prevention. They are not retained in learning records.
2.3 From third parties
From Supabase/Google OAuth: email address, full name, profile picture, verification status. Referral source, if you arrived via a referral link.
Why we collect behavior data, plainly: we track how you work through problems so we can tell whether the platform is actually teaching you anything, and so instructors can see who is struggling before an exam does. That is the product. We would rather say so than bury it.
3. How We Use It
- Deliver the service: run your code, return test feedback, track progress
- Personalization: learner profile, recommendations, identify knowledge gaps
- Measure learning outcomes: determine whether the platform improves performance, individually and in aggregate
- Instructor reporting: progress and struggling-student indicators for your instructor, where the platform is used in a course
- Improve the product: usage patterns, bug identification, feature adoption
- AI-assisted learning: generate teaching-assistant feedback and learning narratives from your submission history
- Communication: enrollment confirmations, submission notifications, password resets
- Fraud and integrity: detect unauthorized access and academic-integrity issues
- Legal compliance: records for tax, audit, and legal obligations
5. How Long We Keep It
Two different clocks, because they serve different purposes.
5.1 Identity and outcome data — up to 5 years
| Data | Retention |
|---|---|
| Name, email, graduation year | Up to 5 years from last activity |
| Program participation and completion | Up to 5 years |
| Outcome information you share (offers, placement) | Up to 5 years |
| Completion certificates | Indefinite |
Why 5 years. Measuring whether this platform actually helps people get engineering jobs requires following outcomes past graduation. A 90-day window cannot answer that question. This is the smallest identifiable set that makes long-term outcome measurement possible: name, email, graduation year. We do not retain IP addresses, device fingerprints, or browsing history for this purpose.
What this means in practice. We keep your contact information so we can ask, later, how your job search went. You are never required to answer. If you do answer, and you were enrolled through an institution, that information may be shared with them (Section 12). If you would rather we not retain your information for this purpose, email privacy@learnwleo.com and we will remove you from outcome tracking while leaving your account intact.
5.2 Learning activity data — up to 24 months
| Data | Retention |
|---|---|
| Code submissions and test results | Up to 24 months |
| Decision traces (run/submit history) | Up to 24 months |
| Time on task, engagement scores | Up to 24 months |
| Learner profiles (AI-generated) | Up to 24 months |
| Session recordings | Up to 24 months |
| Custom test cases, study preferences | Up to 24 months |
5.3 Operational data — short
| Data | Retention |
|---|---|
| Truncated IP (rate limiting) | 30 days |
| Application logs | 30 days |
| Login history | 90 days |
| Bug reports and attachments | Until resolved, then 6 months |
| Resumes (Academy) | Program duration + 1 year |
| Backups | 30 days after deletion from primary |
5.4 De-identified data
Aggregated or de-identified data that cannot reasonably be re-identified may be retained indefinitely for research, efficacy measurement, and reporting.
5.5 Changes to these periods
These periods apply to data collected on or after August 8, 2026. Data collected under our previous policy remains subject to the retention periods stated at the time of collection.
5.6 What is not automated yet
We are honest about this: we do not currently run automated deletion. Retention limits are enforced through periodic manual review. Automated enforcement (TTL indexes, scheduled deletion jobs) is in development. Until it ships, if you want your data deleted sooner, email privacy@learnwleo.com and we will handle it.
6. Your Choices
6.1 Access your data
Email privacy@learnwleo.com with "Data Access Request" in the subject. We respond within 30 days. Identity verification required.
6.2 Delete your account
Email privacy@learnwleo.com with "Account Deletion Request." There is no self-service delete button. Requests go through identity verification and a check for legal holds, then are processed by our team.
We delete your account record, study preferences, planner state, and learner profile. We anonymize submissions, test results, decision traces, and engagement scores. Anonymized records are retained for legal and analytical purposes.
If you are enrolled through an institution, see Section 12 — deletion of institutional records is governed by our agreement with your school.
6.3 Turn off session recording
Account settings → Privacy Settings → "Disable Session Recording." This works today and takes effect immediately. Other analytics continue.
6.4 Data portability
Email privacy@learnwleo.com with "Data Export Request." JSON or CSV, within 30 days.
6.5 Do Not Track
We do not currently respond to DNT browser signals. No uniform standard exists for honoring them. Use the session-recording toggle in Section 6.3 instead — that one works.
7. Security
We use TLS 1.2+ in transit and encryption at rest for our primary datastores. Access to production systems is limited to team members who need it, and administrative access requires multi-factor authentication.
We are a small company and we will not overstate this. We have not completed a SOC 2 audit or a third-party penetration test. Both are on our roadmap. If you are an institution evaluating us, we will share our full security documentation on request.
No system is completely secure.
8. AI and Machine Learning
On-device (default): AI tutoring and session narratives run locally in your browser using Qwen via ONNX. No data leaves your device for these.
Cloud fallback (when on-device is unavailable): Cloudflare Workers AI for real-time hints; Google Vertex AI (Gemini) for learning narratives and pattern analysis. Code submissions and test results are sent for processing and are not retained by those providers for training.
Institutional mode: cloud fallback can be disabled per institution, so no student content leaves the device.
Training: we do not train or fine-tune any model on your data. We use pre-trained models for inference only. Your code is never used to train our models or anyone else's.
Human oversight: AI output is assistive. It provides hints and feedback. It does not assign grades or make binding determinations about you. Your instructor retains authority.
9. Children's Privacy
Our service is not directed to children under 13. If we learn that a child under 13 has provided personal information without verifiable parental consent, we will delete it and close the account. Parents and guardians: contact privacy@learnwleo.com.
Where the platform is made available to secondary-school students through a school, the school is responsible for obtaining any required consent.
10. International Transfers
Your information is processed and stored in the United States. We do not target our services to the EU/EEA or UK. If you use the service from outside the U.S., you consent to transfer and processing here. EU/EEA users with concerns: privacy@learnwleo.com.
11. State Privacy Rights
We do not sell or share personal information for targeted advertising, and never have.
We are not currently a "business" subject to the California Consumer Privacy Act, because we fall below all applicable thresholds. Some U.S. state privacy laws may still grant you rights to access, correct, delete, or obtain a copy of your data. Email privacy@learnwleo.com and we will honor any request the law requires, and generally any reasonable request regardless.
12. Students Enrolled Through an Institution
This section governs if your school, college, or instructor provided access to this platform as part of a course.
Our role. We act as a school official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)(i)(B)). Your institution controls your education records. We process them only for purposes your institution authorizes in our written agreement.
Your rights, accurately stated. FERPA gives you the right to inspect and review your education records, to request amendment of records you believe are inaccurate, to consent to certain disclosures, and to file a complaint with the U.S. Department of Education.
FERPA does not include a right to erasure. Deletion of institutional records is governed by our agreement with your institution, not by individual request. Requests to access or amend your records should go to your institution, which will direct them to us. We respond within the timeframe required by our agreement and, where applicable, within 45 days.
Re-disclosure. We do not re-disclose your education records except to the subprocessors listed in Section 4, each bound by contract, consistent with 34 CFR § 99.33(a).
Outcome reporting. Where your institution has engaged us, we report on student progress and outcomes to that institution. This includes information you volunteer about your job search and offers received. Answering those questions is always voluntary.
After you graduate. If you continue to use the platform or respond to our outcome questions after you are no longer enrolled, you are doing so in a direct relationship with us, governed by this policy rather than by FERPA. Records created while you were enrolled remain education records under your institution's control.
No training, no marketing, no sale. Institutional data is never used to train AI models, never used for marketing, and never sold.
Separation. Data from institutional deployments is not combined with data from our direct-to-consumer users, and is never used for recruiting or hiring purposes.
13. Contact
Privacy: privacy@learnwleo.com
Legal: legal@learnwleo.com
Security reports: security@learnwleo.com
We respond within 30 days for data requests, 7 business days otherwise.
14. Changes
We may update this policy. Material changes will be posted here with an updated date and, where appropriate, emailed to you. Changes to retention periods apply prospectively (Section 5.5).
Changes in this version
- Consolidated two previously conflicting privacy policies into this single document
- Corrected the description of where code executes (in your browser, not on Cloudflare servers)
- Removed claims about automated deletion that were not accurate
- Removed the claim that we respond to DNT signals
- Corrected security descriptions to reflect what we actually have today
- Stopped collecting full IP addresses and complete user-agent strings
- Extended retention for learning and outcome data, applied prospectively
- Added Section 12 for institutionally-enrolled students