Privacy policy
Last updated 10 August 2026
Draft. This policy describes how Sikhaku is designed to handle data, but it has not yet been reviewed by a qualified lawyer and will be finalised before launch.
This explains what Sikhaku, a Lacspace company collects, why, and what control you have. We have tried to write it in plain language rather than legal fog.
1. What we collect
- Account details — your phone number, and your email if you give one. Phone is our primary identifier because email signup measurably costs conversions here.
- Purchases — which courses you bought, when, and what you paid. We never see or store your wallet, banking or card credentials; payment happens on their systems.
- Learning activity — which lessons you watched and how far you got, so progress syncs across devices and creators can see where their course loses people.
- Device and technical data — device type, app version, and error reports, used to fix crashes and playback problems.
- Creator KYC — if you publish courses, we collect identity and bank or wallet details, because paying you legally requires it.
2. Why we collect it
To run the service: give you access to what you bought, sync your progress, issue invoices, pay creators, prevent fraud, and answer support requests. We do not sell your data, and we do not run third-party advertising on Sikhaku.
3. What creators can see about you
This is the part most people want to know, so it is stated plainly: a creator learns your identity only after you buy one of their courses.
- Before you buy, a creator cannot see you at all — not even that you viewed their page.
- After you buy, they see your name, the course you bought, when you bought it, and your progress through that course.
- They never see your phone number, your payment details, or anything you bought from a different creator.
This boundary is enforced in the system itself, not by policy alone: a creator’s access is scoped to their own enrolments at the database layer.
4. Who else sees it
We share data only with the services required to operate:
- Payment providers — the wallet, bank or card network you choose at checkout, to process the payment
- Our video provider — to deliver and protect lessons
- SMS and email providers — to send verification codes and receipts
- Error and analytics tooling — to find and fix faults
- Authorities — where we are legally required to, and no further
5. How long we keep it
Account and purchase records are kept while your account is open, and for as long afterwards as tax law requires us to retain invoices. Learning activity is deleted with your account. Verification codes are deleted within minutes.
6. Your rights
You can ask us to:
- Give you a copy of your data
- Correct anything wrong
- Delete your account and personal data, subject to invoice retention requirements
- Stop sending you notifications or marketing email
Email support@sikhaku.com. We respond within 30 days.
7. Security
Everything travels over TLS. Refresh tokens and verification codes are stored hashed, never in plaintext. Access to production data is limited to the people who need it, and payment credentials never reach our servers at all.
No system is perfectly secure. If a breach affects you, we will tell you what happened and what to do about it rather than quietly hoping you do not notice.