Privacy Policy
Effective 4 September 2026 · Version 1.0
1. Who is responsible for your information
Apex Human Technology, Inc. ("Apex Human", "we", "us"), of Rufino Pacific Tower, Legaspi Village, Ayala Avenue, San Lorenzo, Makati City, Philippines, is the personal information controller for the information described here. We are registered with the Philippine Securities and Exchange Commission under number SEC260826-OC10THPNHTCLCIR.
Data Protection Officer
- Michelle Jose
- privacy@apexhuman.ai
- Rufino Pacific Tower, Legaspi Village, Ayala Avenue, San Lorenzo, Makati City, Philippines
This policy covers apexhuman.ai and the Apex Human learning platform. It is written to the Data Privacy Act of 2012 (RA 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission.
2. The short version
- We collect what we need to sell you a course, teach you, prove you finished, and keep the
service working. Nothing is sold, and nothing is shared for advertising.
- What you type into the AI is sent to our AI provider so it can answer. It is not used
to train anybody's model.
- Your build prompts and tutor questions **can be read by the professor teaching your
course**, with credentials automatically stripped out, because a professor signing a certificate needs to see the work behind it. Anything before a "start fresh" line in the tutor is never shown to anyone.
- We record error reports and a masked sample of screen recordings so we can fix faults. Text
and typing are masked before they leave your browser.
- A certificate is publicly checkable by anyone you give its link to.
- Your information is processed outside the Philippines by our providers.
3. What we collect
3.1 Your account
Your name, email address, and a password, which is held in hashed form by our authentication provider and is never visible to us. If you sign in with an external account instead of a password, we receive that account's identifier, your name, your email address and its profile picture from the provider you signed in with. We also hold your role (student, professor, admin), when the account was created, and when you were last active.
If you upload a profile picture yourself, that picture is stored in a publicly readable bucket, because avatars are shown around the Platform. Please do not upload anything you would not want to be public.
We also store small interface preferences, such as how wide you dragged the lesson panel.
3.2 What you have bought
For each purchase: the course, the amount, the currency, any discount and the code used, the name of the payment method you used (for example "card"), the reference our payment processor gives the transaction, the status, and when it was paid or refunded.
We never receive your card number, CVV, or e-wallet login. Those go to the processor directly, on its own checkout page.
3.3 What you do on a course
- which lessons you have opened and completed, and when;
- how much of each video you have watched, including per-second playback data from our video
provider, which is what tells us where a lesson loses people;
- which chapters of a video you have reached;
- quiz results, meaning how many you got right out of how many, and whether that passed.
We deliberately do not record which answers you chose;
- documents a course asked you to read and accept, and setup steps you have completed;
- for an on-site workshop, that you attended and who marked you present;
- your certificate: its serial number, its verification link, the decision behind it, and who
made that decision.
3.4 Your workspace and the product you build
- your project, and the machine it runs on;
- every prompt you type to the build agent, and everything the agent replies. Credentials
are detected and stripped out of what you typed before it is stored;
- the status, duration, error codes and computing cost of each build run, and which lesson
you were on;
- which settings you have supplied, meaning the name of the variable and the time you
filled it in, and never the value. API keys and access tokens you paste go to your own workspace and are not written to our database. A token used to publish your product is not stored, not logged, and not written to disk.
3.5 The tutor
- your questions, the tutor's answers, and which lesson you asked from;
- how much each exchange cost us to answer;
- screenshots you attach. These are stored in a private bucket, readable only through
a short-lived signed link, because a picture of your screen is not something to leave lying at a public address. They are not shown on any staff screen.
3.6 Support, and messages we send you
Billing questions and refund requests you raise: the subject, your message, and the purchase you attached to it. Staff notes on how it was resolved are internal and are not shown to you. We also keep the in-app notifications we have sent you.
The emails we send are: a welcome message, a receipt when you buy, a note when a pre-ordered course opens, an acknowledgement when you raise a billing question, and, for professors, application decisions.
3.7 If you apply to teach
Your expertise, biography, years of experience, links you give us, which courses you want to teach, and the note written when a decision is made. This sits on the application, not on your profile, so a rejected application does not leave a half-built teaching profile behind.
3.8 Technical and diagnostic information
- Error reports when something breaks: what failed, where in the code, and the page you
were on.
- A sample of session recordings, meaning one session in ten, and every session in which
an error occurred. These are masked before they leave your browser, with all text, all form input and all images hidden, so what remains is layout and interaction rather than content. This matters because students type API keys into setup lessons, and an unmasked recording would be a second copy of exactly those secrets.
- We have switched off the collection of user identity, IP address, cookies, request
bodies, database values, AI prompts and in-memory variables in our error reports.
- Our hosting and video providers log IP addresses and browser information as part of
delivering pages and video to you. That is ordinary server logging, and it is theirs.
We use no advertising, marketing or cross-site tracking technology. There is no web analytics suite, no advertising pixel, and no third-party marketing cookie on the Platform.
3.9 Cookies and similar storage
We use only what the service needs:
| What | Why | | --- | --- | | Session and authentication cookies | To keep you signed in, and to refresh your session. Strictly necessary, and the Platform cannot work without them. | | Local browser storage | Small interface state, such as panel sizes. | | Diagnostics storage | Our error-monitoring provider stores a session identifier in your browser to tie a recording to an error. |
Blocking session cookies will stop you being able to sign in.
4. Where it comes from
Mostly from you. Also from an external sign-in provider, if you choose to sign in that way; our payment processor, which tells us a payment succeeded and by what method; our video provider, which reports playback progress; and our own systems, which record what you have completed.
5. Why we use it, and on what legal basis
Under the Data Privacy Act we must have a lawful criterion for each use. Ours are:
| What we do with it | Why | Lawful criterion | | --- | --- | --- | | Create and run your account | You cannot have a course without one | Performance of our contract with you | | Take payment, issue receipts, handle refunds | To sell you the course | Contract, and legal obligation for tax records | | Deliver lessons and video, and remember your progress | It is the service | Contract | | Run the tutor and the build agent | The teaching itself | Contract | | Decide and issue certificates, and let them be verified | You asked for the credential | Contract | | Answer your billing questions | To help you | Contract | | Email you about a course you bought | To tell you it is ready, or that it opened | Contract | | Improve the curriculum from drop-off and question patterns | To find the lesson that is not landing | Our legitimate interests, balanced against your privacy. We look at patterns, not people | | Monitor errors and record masked sessions | To find and fix faults | Our legitimate interests in a service that works | | Prevent fraud, abuse and payment reversal abuse | To protect the business and other students | Our legitimate interests | | Keep accounting and tax records | The law requires it | Legal obligation | | Show your product in our marketing | Only if you tick the optional box | Your consent, which you may withdraw at any time |
We do not use your information for automated decisions that have a legal effect on you. Whether you have completed a course is arithmetic, meaning lessons finished and quizzes passed, and a person decides whether the certificate is issued.
We do not sell your information, and we do not share it for anyone's advertising.
6. The AI features, specifically
This deserves its own section, because it is the part people most reasonably want to know about.
What is sent to our AI provider:
- your question or your build instruction, as you typed it;
- the context needed to answer it, meaning the lesson you are on, its objective, its
transcript, and the recent conversation;
- any screenshot you attach to a tutor question;
- for the build agent, the files in your own project.
What that provider may do with it. We use a commercial API, under terms that do not permit your prompts or the answers to be used to train their models.
What we deliberately do not send anywhere:
- your prompts and the AI's answers are excluded from our error monitoring, so they never
reach that provider;
- credentials are stripped out of build prompts before we store them;
- the values of API keys you paste are never in our database at all.
Retention. Conversations are kept as described in section 9, so you can come back to your work, and so a professor can see it when deciding a certificate.
7. Who inside Apex Human can see your information
Admin staff can see your account details, what you have bought, your progress and quiz record, your billing messages, and your attendance at on-site workshops.
A professor can see, for their own courses only, the students enrolled, their progress and quiz record, and the prompts and tutor questions those students typed, with credentials automatically removed. This is deliberate, and it is worth being plain about: a professor being asked to put their name to your certificate needs to see the work behind the arithmetic, and a count of prompts does not show it.
Two things are never shown to anyone:
- tutor questions from before you last chose "start fresh", which are counted, never read;
- the screenshots you attach to tutor questions, which do not appear on any staff screen.
Professors cannot see revenue, other professors' courses, or students who are not theirs. Access is enforced in the database query, not by hiding buttons.
8. Who we share it with
We use these providers to run the service. Each processes your information on our instructions, and only for what we use them for.
| Kind of provider | What it handles | | --- | --- | | Managed database and authentication | The database, and account sign-in | | Application hosting | Serving the Platform to your browser | | File storage | Avatars, slide decks, screenshots you attach | | Video platform | Lesson video, automatic captions, playback analytics | | Payment processor | Card and e-wallet payments, and refunds | | Email delivery | The emails we send you | | AI provider | The tutor, the build agent, and internal drafting tools | | Error monitoring | Error reports and masked session recordings | | External sign-in provider | Signing in without a password, if you choose it | | Cloud compute | The machine that runs the product you build |
This table names kinds of provider rather than companies, deliberately. We change a provider from time to time, and a policy that prints names is out of date the day we do, which is worse for you than one that does not. The current list, by name, is yours on request: email privacy@apexhuman.ai and we will tell you who holds what.
We may also share information:
- with professional advisers such as lawyers, accountants and auditors, under a duty of
confidence;
- where the law requires it, or in response to a valid order from a court or a regulator.
We will tell you unless we are prohibited from doing so;
- with a buyer or successor, if the business is reorganised or sold, on notice to you;
- to establish or defend legal claims, or to prevent fraud or harm.
9. Sending information outside the Philippines
Most of the providers above process information outside the Philippines, principally in the United States and the European Union. We remain accountable for it under the Data Privacy Act wherever it goes. Each provider is engaged under a written agreement that requires a comparable level of protection, restricts what they may do with your information, and requires them to help us honour your rights.
10. How long we keep it
| What | How long | | --- | --- | | Account and profile | While your account is open, then 12 months, then deleted or anonymised | | Purchases, receipts and refunds | 10 years, because Philippine tax rules require it | | Learning record: progress, quiz results, completions | While your account is open, then 12 months | | Certificates | Kept indefinitely, so a credential you have handed to an employer keeps verifying. If you close your account you may ask us to withdraw the credential instead | | Build conversations and prompts | 24 months from the last activity on that course | | Tutor conversations | 24 months from the last activity | | Screenshots you attach | 12 months | | Your workspace and its contents | While your enrolment is active, then reclaimed after 90 days unused, on notice | | Billing messages | 3 years from resolution | | Professor applications | 24 months from the decision | | Error reports and session recordings | 90 days, then deleted by our provider |
Where a period is shorter than a legal obligation we are under, the obligation wins, and we keep only what that obligation needs.
11. Your rights, and how to use them
Under the Data Privacy Act you have the right to:
- be informed about how your information is processed, which is what this document is
for;
- access what we hold about you, and be told where we got it and who we share it with;
- correct anything inaccurate;
- object to processing, including any processing based on our legitimate interests;
- have information erased or blocked where it is unlawful, unnecessary, outdated, or was
given on consent you have since withdrawn;
- data portability, meaning you can receive the information you gave us in a usable
electronic format;
- be indemnified for damage caused by inaccurate, unlawful or unauthorised use of your
information;
- complain to the National Privacy Commission;
- and, if you have died or are incapacitated, your heirs may exercise these rights.
How to exercise them. Email privacy@apexhuman.ai. Tell us what you want, and enough for us to identify your account. We will reply within 15 working days, and if the request is complex we will say so and tell you how much longer we need.
There is no self-service delete button in the Platform today, so closing an account and erasing information is done by request. Two things you should know before you ask:
- some information we must keep, meaning purchase records for tax, and enough to show that a
refund or a suspension was properly handled;
- deleting your learning record ends your access to courses you bought, and we cannot restore
it afterwards.
You can change your name and password yourself on your account page, and withdraw marketing permission there or by email.
12. If you are under 18
You may hold an account from age 13, and if you are under 18 a parent or guardian must consent and hold the account with you. Under the Data Privacy Act, consent for a minor's information is given by the parent or guardian.
How we ask. Signing up requires a tick box confirming that the person signing up is at least 13, and that a parent or legal guardian has read the Terms and agrees where that person is under 18. It is a declaration rather than a check. We do not verify anyone's age, and we would rather say so here than imply a check we do not run.
The AI features and a minor. A parent or guardian who consents to the account is consenting to the AI tutor and the build agent too, because they are the course rather than an extra. Our AI provider places additional requirements on a product that under-18s use, and section 6 sets out exactly what reaches that provider and what never does.
A parent or guardian may, at privacy@apexhuman.ai, ask to see what we hold about their child, correct it, or have it deleted and the account closed.
We do not knowingly collect information from anyone under 13. If you believe a child under 13 has an account, please tell us and we will close it and delete what we hold about them.
13. How we protect it
Everything travels over encrypted connections. Passwords are hashed by our authentication provider and never seen by us. Paid video is served through signed links that expire, so a copied link stops working. Private files, meaning slide decks and your screenshots, are readable only through short-lived signed links after we have checked the file is yours. Session recordings are masked in your browser before they are sent. Credentials are stripped out of stored prompts, and our error reports are configured to exclude cookies, authorisation headers, request bodies, database values, AI prompts and in-memory variables. Access to student information is restricted by role and enforced server-side.
No system is perfectly secure, and we will not claim otherwise.
14. If something goes wrong
If a breach occurs that is likely to put you at serious risk, we will notify the National Privacy Commission within 72 hours of learning about it, and tell you what happened, what it means for you, and what to do, as required by the Data Privacy Act.
15. Changes to this policy
We will update this document when what we do changes. For a material change we will tell you by email and in the Platform before it takes effect. The date at the top always shows the current version, and previous versions are available on request.
16. Complaints
Please come to our Data Protection Officer first, at privacy@apexhuman.ai. We would much rather fix it than have you escalate.
If you are not satisfied, you may complain to the National Privacy Commission, whose contact details and complaint process are published at privacy.gov.ph.