Skip to content
Log in

Privacy policy

Last updated: September 29, 2026

Productovi Learning (learning.productovi.com) is a free learning platform for product managers and marketers. It is run by PE Serhii Brukh, a private entrepreneur (FOP) registered in Ukraine ("we", "us"). This policy explains what personal data we collect, why, and what you can do about it. Questions and requests: sergeybruh@gmail.com.

1. What we collect

You can read every lesson without an account. When you log in, we store:

  • Account data: your email address, the name you give us (or the name from your Google profile), your avatar (an emoji or a photo you upload), your interface language and the ways you have logged in.
  • Learning data: your answers to exercises, scores, lesson progress, topic mastery and certificates.
  • AI usage records: when and how much AI feedback you used, so we can apply daily limits. These records contain token counts and costs, not your answers.
  • Technical data: our hosting providers keep standard server logs (IP address, browser, requested page) for security and troubleshooting.

We use Google Analytics and PostHog to understand how the site is used. Until you allow analytics in the cookie banner (or if you decline), they only receive cookieless usage pings such as pages viewed and approximate location, and nothing is stored in your browser. If you allow analytics, they may set cookies, and PostHog records sessions: how you move, scroll and click on our pages, with everything you type masked. If you are logged in, this data is linked to your internal account ID, never to your email or name.

2. Google sign-in

If you log in with Google, we ask Google only for your basic profile: a unique account ID, your email address, whether it is verified, and your name. We do not get your password or access to your Gmail, Drive, contacts or any other Google data.

We use this data only to create your account and log you in. We do not sell it, use it for advertising, or share it with anyone except the providers listed below that help us run the service. Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

3. Why we use your data

  • To provide the service you asked for: your account, saved progress, exercise feedback and certificates (performance of a contract).
  • To send you login links by email (performance of a contract).
  • To keep the service secure and within budget: rate limits, abuse prevention and AI usage limits (legitimate interest).
  • To understand how the site is used, only if you agree (consent).

We do not send marketing emails and we do not sell personal data.

4. AI feedback

For open-ended tasks, the text of your answer and the task are sent to our AI provider, DeepSeek, to generate feedback. We do not send your name or email with it. Please do not include personal or confidential information in your answers.

5. Who processes your data

We use a small number of providers who process data on our behalf:

  • Vercel (website hosting) and Render (API and database hosting).
  • Resend (sending login emails).
  • Google (sign-in with Google, and Google Analytics).
  • PostHog (product analytics and, if you allow it, session recordings).
  • DeepSeek (AI feedback, as described above).

Some of these providers are located outside Ukraine and the European Economic Area, including in the United States and China. Where required, transfers rely on the providers' contractual safeguards.

6. Certificates

When you complete a course, your certificate gets a public verification link. Anyone with the link can see the name on the certificate, the course, your average score and the date. The link is not listed anywhere; you decide whom to share it with.

7. Answers shown to other learners

When your answer to a written task or a case passes the AI check, other logged-in learners who have answered the same task can see it, so they can compare approaches. They see your name, your avatar, the text of the answer and, for cases, its score. They never see your email address or the AI feedback. Guests only see how many learners answered.

This is on by default, and a note under every answer box says so. You can turn it off for all your answers with "Show my answers to other learners" on your account page, or hide a single answer under its result. When you delete your account, your answers are deleted too. We rely on our legitimate interest in running a learning community; you can object at any time with these settings.

8. Cookies and local storage

  • pl_session: keeps you logged in (30 days). Required.
  • pl_oauth_state: protects Google sign-in (10 minutes). Required.
  • PL_LOCALE: remembers the language you picked. Required.
  • Browser storage for your theme and your cookie choice. Required.
  • Browser storage for what you enter in the RICE, ICE, cohort retention and TAM/SAM/SOM tools, so it is still there when you come back. It never leaves your browser, and "Start empty" clears it.
  • _ga cookies from Google Analytics, and ph_ cookies and browser storage from PostHog, only if you allow analytics.

You can change your analytics choice at any time with "Cookie settings" in the footer.

9. How long we keep data

We keep your account and learning data until you delete your account. Login links expire after 15 minutes. When you delete your account, your profile, answers, progress and certificates are deleted immediately; AI usage records stay only as anonymous cost statistics. Server logs are kept by our hosting providers for a limited period.

10. Your rights

You can view and change your name and avatar on your account page, and delete your account there at any time. You can also ask us for a copy of your data, to correct it, to restrict or object to its processing, or to delete it by writing to sergeybruh@gmail.com. We will reply within 30 days.

If you think we handle your data unlawfully, you can complain to the Ukrainian Parliament Commissioner for Human Rights or to the data protection authority in your country.

11. Children

The service is intended for people aged 16 and over. We do not knowingly collect data from younger children. If you believe a child has created an account, write to sergeybruh@gmail.com and we will delete it.

12. Changes

If we change this policy, we will update the date at the top. If the changes are significant, we will tell logged-in users on the site.