Privacy Policy
This policy explains what personal data GetNerdo collects, why, who we share it with, and the choices and rights you have. We aim to say exactly what we do — no more and no less.
Operated by LumaByte (GetNerdo) · Effective 26 June 2026
This English text is the governing version. An Arabic translation is provided for convenience.
Pre-launch notice. GetNerdo is in public beta, operated by LumaByte as an online service within the European Union. Everything here describes the service as it is built today.
1.Who we are
GetNerdo is an agentic AI learning platform — a LumaByte project — operated by LumaByte as an online service from within the European Union. For the personal data described in this policy, LumaByte is the data controller.
Where GetNerdo is provided to you through your employer, school, university or another organisation (an “Organisation”), that Organisation is the controller of the learning data it directs us to process, and we act as its processor under a data processing agreement. In that case, the Organisation’s own privacy notice governs how it uses your data, and you should also refer to it.
For any privacy question, or to exercise your rights, contact us at privacy@getnerdo.com.
2.Scope & your relationship with us
This policy covers the GetNerdo website at https://getnerdo.com, the in-product tutor, agents, Lab, research and arena features, and our demo and waitlist forms. GetNerdo is currently offered as a public beta, primarily to businesses and educational institutions and following a demo request. Beta features may change, and we will keep this policy current as the product evolves.
3.Data we collect
We collect only the data we need to run the service. In practice that is:
Data you give us
- Account data — your email address and authentication credentials (managed by our identity provider; passwords are never stored in plaintext), and, if you sign in with single sign-on, the subject identifier your provider returns.
- Profile data — optional details you choose to add: display name, full name, avatar, bio, pronouns, country, timezone and social links. Some of these appear on your public profile page if you complete one.
- Learning content & inputs — the messages, questions, code, files, voice recordings and other content you submit to the tutor, agents, Lab, quizzes and research tools.
- Demo & waitlist data — the email address and any details you submit when requesting a demo or joining the waitlist.
- Organisation data — if you create or join an Organisation: membership, roles, teams, cohorts and invitations.
Data we generate as you use GetNerdo
- Learning records — quiz attempts, competency and mastery estimates, spaced- repetition state, roadmap progress, artifacts you build, certificates and similar progress data.
- Usage & metering data — feature usage and request counts we record to operate limits and (where applicable) billing.
- Consent & compliance records — a record of the terms and privacy versions you accepted, with the time, IP address and user agent, kept as proof of consent.
- Audit logs — for Organisation and security events, including IP address and user agent.
Data we receive automatically
- Technical data — IP address, device and browser information, and request logs, collected by our hosting and error-monitoring providers to deliver and secure the service.
- Essential cookies — a session cookie that keeps you signed in. See our Cookie Notice.
Payment data
When a paid plan applies, payments are handled by Stripe. We do not receive or store your full card number; we keep only billing metadata such as your plan, currency, subscription status and the Stripe customer reference.
Sensitive data
We do not seek special-category data (such as health, biometric or ethnicity data). The one exception is in the education context: where an Organisation enables minor protections, a student’s date of birth may be processed to confirm age and apply the right safeguards. Please do not submit special-category data into chats or the Lab unless it is necessary and you have a lawful basis to do so.
4.How we use data & the legal bases we rely on
Under the GDPR we must have a lawful basis for each use of your data. Ours are:
- To provide the service — create your account, run the tutor and agents, track your learning, and deliver features you request. Basis: performance of our contract with you (or our processing on an Organisation’s instructions).
- To bill and prevent fraud — manage subscriptions, seats and payments. Basis: contract, and our legitimate interest in being paid and preventing abuse.
- To secure and improve the service — monitor for abuse, debug errors, and improve reliability and quality. Basis: legitimate interests, balanced against your rights.
- Marketing and demo follow-up — to respond to a demo request and send product updates you ask for. Basis: consent, or legitimate interest for business contacts, which you can withdraw at any time.
- To meet legal obligations — tax, accounting, and responding to lawful requests. Basis: legal obligation.
We do not sell your personal data, and we do not use the private content you submit to train third-party foundation models. See the next section for exactly how AI providers handle your content.
5.How AI processes your content (EU AI Act transparency)
GetNerdo is an AI system. You are interacting with artificial intelligence — not a human tutor — and we tell you so plainly throughout the product, in line with the transparency duties of the EU AI Act.
- When you use the tutor, agents, Lab, voice or research features, the content you submit is sent to the AI providers listed in Who we share data with so they can generate a response, transcribe speech, or create embeddings for retrieval.
- AI output can be wrong, incomplete or outdated. It is educational assistance, not professional, legal, medical or financial advice, and you should verify anything you rely on. Where the tutor draws on live web search or our learning library, we try to show citations so you can check the source.
- We instruct our AI providers, by contract, to process your content only to provide the service to us and not to train their general models on it. Provider terms can change; we keep the sub-processor register below current.
- Voice recordings are sent for transcription and are not retained by us beyond what is needed to return the transcript and run the feature you asked for.
6.Automated decisions & profiling
GetNerdo estimates your skills and adapts what it teaches — for example, mastery scores, spaced-repetition scheduling and roadmap recommendations. This is profiling in the GDPR sense, used to personalise your learning.
We do not use it to make decisions that produce legal or similarly significant effects about you without human involvement. Certificates and competency records are informational and learner-controlled. Where an Organisation uses GetNerdo data as an input to a decision about you (for instance grading or course access), that decision is the Organisation’s and is subject to its own policies and human review. You can ask us, or the Organisation, for an explanation of how a result was produced.
8.International transfers
We are established in the EU and prefer EU/EEA processing where practical. Some providers listed above process data in the United States or other countries. For those transfers we rely on the European Commission’s Standard Contractual Clauses, an applicable adequacy decision, or equivalent safeguards. You can request a copy of the relevant safeguard by emailing privacy@getnerdo.com.
9.How long we keep data
- Account, profile and learning data — kept while your account is active. When you delete your account, we delete or anonymise this data, except where we must keep limited records (see below).
- Consent and audit records — kept for the period needed to evidence consent and for security; Organisation audit logs are kept according to the Organisation’s retention setting and then automatically swept.
- Billing records — retained as long as required by tax and accounting law (typically several years).
- Data-subject request records — kept to demonstrate that we handled requests properly, even after an account is erased.
10.Your rights
If the GDPR applies to you, you have the right to:
- access a copy of your personal data;
- correct inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing, including direct marketing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting prior processing.
To exercise any of these, email privacy@getnerdo.com. We respond within one month, as required by Article 12(3) GDPR. If GetNerdo was provided to you by an Organisation, please direct requests to that Organisation, which we will assist as its processor.
You also have the right to lodge a complaint with a data protection supervisory authority — in particular your local data protection authority in the EU/EEA country where you live or work. You can find the full list of authorities on the European Data Protection Board’s website.
12.Students, minors & education
You must be at least 18 years old to create a personal GetNerdo account. We do not knowingly collect data from children for self-service accounts.
GetNerdo is also offered to colleges, universities and other educational institutions. Where a learner under 18 is given access through such an institution, that institution is responsible for having the legal authority and any required parental or guardian consent, and acts as the controller for that student’s data. For those learners we apply additional protections — limits on disclosure, a parental-consent record, and FERPA-equivalent handling of student records — configured by the institution. If you believe a minor has created a personal account without authorisation, contact privacy@getnerdo.com and we will remove it.
13.Regional notices — Saudi Arabia & UAE
GetNerdo serves learners and Organisations across the GCC. Where the Saudi Personal Data Protection Law (PDPL) or the UAE Federal Personal Data Protection Law applies, the descriptions in this policy of the data we process, our purposes, sharing, retention and your rights are intended to satisfy those laws as well. Residents of those countries have rights of access, correction and deletion equivalent to those above and can exercise them through the same contact address. Cross-border transfers are made using the safeguards described in International transfers.
14.Security
We protect data with encryption in transit, row-level access controls in our database, hashed secrets and tokens, scoped service credentials, and audit logging. No system is perfectly secure, but we work to limit what we collect, who can access it, and how long we keep it. If a personal-data breach affects you, we will notify you and the relevant authority as required by law.
15.Changes to this policy
We will update this policy as GetNerdo evolves. When changes are material, we will notify you in-product or by email and, where the law requires, ask you to accept the new version. The current version is privacy-2026-06-26, effective 26 June 2026.
16.How to contact us
Privacy questions and data-subject requests: privacy@getnerdo.com. General enquiries: hello@getnerdo.com. GetNerdo is operated online from within the European Union by LumaByte; the quickest way to reach us is by email.