LECO
FRENIT
Data protection

Privacy notice

One page for both sides of LECO: this marketing site and the application. It says what is collected, what is public, who else receives it, where it is processed, and how to have your data corrected or erased. Whatever has not been decided yet is written as such, rather than replaced with a reassuring phrase.

Last updated : 2026-08-07

Who is responsible for your data

Registered name
Learning Connection SARL
Registered office
Yaoundé, Cameroun
Representative in the European Union (GDPR art. 27)
not published yet
Contact
learning.connection.leco@gmail.com

What this page covers

This notice covers both sides of LECO:

  • this marketing site, learning-connection.org;
  • the application, app.learning-connection.org, where you create an account, post questions and answers, and keep a profile.

One page, because it is the same controller, the same processors and the same rights. It is also this page the application points at when it links to its privacy notice. Where a rule holds for only one of the two, that is said.

A controller established outside the European Union

Learning Connection is a company registered in Cameroon, and it is from Cameroon that this site and the application are administered. We are not established in the European Union.

That takes nothing away from your rights. The GDPR applies to a controller established outside the Union as soon as it offers a service to people who are in it: that is its art. 3(2). LECO addresses a European audience, in French and in Italian; the regulation therefore covers this processing in full, and everything this page describes holds as though we were established in the Union.

It does change one thing materially: your data leaves the European Union in order to be processed. The section on transfers, at the foot of this page, says what covers that.

Our representative in the European Union

GDPR art. 27 requires a controller established outside the Union to designate, in writing, a representative in one of the member states where the people whose data it processes are located.

That designation has not been made yet. While the matching row at the top of this page names nobody, there is no representative to write to: use the contact address given in the same place, which stays open and which we answer ourselves. Once a representative is designated, their name and address will appear in that row, and you will be able to address them exactly as you would address us. A supervisory authority will be able to do the same. None of this replaces your right to go directly to the supervisory authority of your own country.

What we collect on this site

The form on this site asks for a name and an email address. It sends nothing itself: it opens a pre-filled message in your own mail program, and you are the one who sends it. Until you send it, nothing reaches us. This site sets no cookies and runs no analytics tool.

What the application collects

  • Your identity: name, email address, username, the date your address was verified. There is no password: you sign in through a single-use link valid for fifteen minutes.
  • Your profile: first name, last name, bio (up to 2000 characters), language, institution, department, academic level, year.
  • What you post: questions, answers, edit histories, messages in project spaces, comments, applications to join a project (motivation, skills, availability, message), proposals and outputs.
  • Your files: avatars and attachments, with their name, type, size and a checksum.
  • Technical data: your IP address and user agent, kept in the session registry and in the activity log. A recognised device is identified by a SHA-256 fingerprint computed over those same two things.
  • How you read: what the feed showed you, how long you stayed on each item, ten kinds of interaction, your topic and course affinities, and a 1024-dimension interest vector per person. Visitors who are not signed in are included, attached to an identifier derived from their session.

Registration is open to anyone and asks only for a name and an email address. No age is asked or checked, and no consent box is shown at sign-up: nothing below therefore rests on a consent we never asked you for.

Your contributions and your profile are public

Anyone can read your profile without an account and without signing in, as long as they have the link. It is the most surprising thing about LECO, and better read here than discovered.

Publicly reachable:

  • your profile: real first and last name, bio, avatar, institution, department, academic level and year, join date, number of public projects;
  • a 365-day activity calendar, day by day, attached to your name;
  • search, which indexes your username and your real name: searching your real name finds you;
  • every question and every answer, including the history of their edits, as well as the feed, proposals, projects, their updates, their outputs and their resources. Every question and every answer shows its author’s full name and avatar.

No setting makes a profile private. The only two visibility settings that exist are whether your academic interests appear on your public profile, and joining project by project. LECO is not built for contributing anonymously, and that is not planned.

In this same update we are adding a robots.txt file and a noindex tag: profiles will no longer be picked up by search engines. They stay readable by anyone who has the link.

The legal bases

  • Performing the service, GDPR art. 6(1)(b): your account, your profile, what you post, and the emails without which the service does not work.
  • Our legitimate interest, art. 6(1)(f): security and abuse prevention, feed ranking, operational measurement and error monitoring. You can object to it.
  • Your consent, art. 6(1)(a): the message you send us from this site, and the weekly digest, the only email you have to opt in to. It can be withdrawn at any time, and withdrawing it does not affect the lawfulness of what was done beforehand.

No consent box is shown at sign-up. We therefore do not claim that your account rests on a consent you gave.

Feed ranking, and what it infers about you

The feed is not chronological. An interest model is built from what you open, what you linger on, and what you ignore, which counts as a negative signal. Signals lose half their weight every ninety days. Each person has their own interest vector, and several ranking variants are tested in parallel, with control groups. Visitors who are not signed in are ranked the same way.

This is profiling. It is not an automated decision producing legal effects or similarly significantly affecting you within the meaning of GDPR art. 22: ranking changes the order of what is shown, nothing else. You can ask the application why it is showing you what it shows you, through the ?explain=1 parameter on the feed request (GET /v1/feed?explain=1), and object to this processing at the contact address given above.

Who receives your data

We do not sell, rent or trade anything. Apart from the controller named above, only these companies receive data, each for a defined job:

  • Resend — sending email. Receives the recipient address and the full body of the message, sign-in links included. A US company.
  • Google Cloud — the whole application: server, database, logs, task queues and secrets. Johannesburg, in South Africa; the scheduler and the queues are in Belgium.
  • Google Gemini — computing semantic vectors. Receives the title and a 600-character excerpt of questions, answers and proposals, capped at 2000 characters. Global endpoint, with no regional control. Two limits are enforced by the code: the text sent carries no name and no identifier, and only content that is already public is sent, which is re-checked immediately before it leaves.
  • Upstash — the cache and the queues. Receives sessions and pending jobs, including email addresses while they are in transit. Cape Town, in South Africa.
  • Cloudflare — page rendering, the API edge, file storage, image resizing and the anti-bot check. That check receives your IP address.
  • Error monitoring — technical errors, their traces and the trail of actions that led to them. Received in Germany, inside the European Union.

Two edge services strip your IP address and your geolocation headers before the request reaches the application server.

What does not exist, and this is checkable in the code rather than promised: no third-party analytics tool, no advertising pixel, no social-network button or tracker, no browser fingerprinting. The content security policy allows only our own scripts and the one belonging to the anti-bot check.

Where your data physically sits

  • The database and the application server: South Africa.
  • The cache and the queues: South Africa.
  • The task scheduler: Belgium.
  • The files you upload and the export archives: with Cloudflare, with a location preference of Western Europe.
  • Page rendering: with Cloudflare, with no region pinned.
  • Computing semantic vectors: a global endpoint, with no region.

What that means legally is dealt with in the section on transfers, at the foot of this page.

Cookies and local storage

This marketing site sets no cookies.

The application sets three, all its own, all needed for it to work:

  • leco-session — the session identifier, set for a visitor who is not signed in too; 120 minutes, extended on each visit;
  • XSRF-TOKEN — protection against forged requests; 2 hours;
  • locale — the language of the interface; 1 year.

The application also keeps things in your browser: your display preferences; the draft of your onboarding, with first name, last name, institution, courses and topics; and your composition drafts, unpublished titles and bodies included. Session storage holds the page to send you back to after you sign in.

All of it is set by us, to make the service work, and none of it is there to follow you. That is why you are shown no consent banner: there is nothing to accept or refuse. Your browsing sessions are not recorded; only errors are.

Email and notification preferences

The application sends twenty-nine kinds of notification, by email and inside the application. A preference centre, in the settings, lets you set them category by category — forty-seven of them.

No email contains an unsubscribe link, and no unsubscribe header is sent: you change this in that preference centre, or by writing to us. Only the weekly digest has to be switched on; everything else is on by default.

These emails carry personal data: the sign-in alert includes your IP address, and a mention notification includes the real name of the person who mentioned you and a 180-character excerpt.

Our email templates contain no tracking pixel and no tracking parameters in their links. Recording opens and clicks is, however, an account-level option at our sending provider: we have not verified it, and we therefore do not claim that it is switched off.

Your rights

The GDPR gives you, over the data concerning you:

  • the right of access — to know whether we hold data about you and to obtain a copy of it (art. 15);
  • the right to rectification — to have inaccurate or incomplete data corrected (art. 16);
  • the right to erasure — to have your data deleted (art. 17);
  • the right to restriction of processing — to have its use frozen while a claim is examined (art. 18);
  • the right to data portability — to receive your data in a machine-readable format, or have it sent to another controller (art. 20);
  • the right to object — to object to processing based on legitimate interests, feed ranking included (art. 21);
  • the right not to be subject to an automated decision producing legal effects (art. 22). LECO makes none: the ranking described above is profiling, not a decision of that kind.

How those rights are exercised today

Plainly: the application has no button that deletes your account, and none that downloads your data. Deleting your own account is refused by the code, and export exists only on the administration side.

Everything therefore goes through a written request to the contact address given above. An administrator handles it by hand, after verifying your identity. We undertake to answer within thirty days; the GDPR gives us one month, extendable by two where the request is complex, in which case we tell you before the deadline. You will not be asked for identity documents beyond what is strictly necessary.

What erasure actually does

Erasure anonymises your account; it does not delete everything, and you are entitled to know where the line falls.

Genuinely deleted: your sign-in tokens, your passkeys, the files you uploaded, your feed reading data and your affinities. Emptied: your email address, your bio, your institution, your department, your level and your year. Your first name becomes the word Deleted, your display name becomes Deleted user, and your username is replaced with a technical identifier.

What you wrote stays. Questions, answers, edits, messages: all of it is kept and re-attributed to Deleted user. That is a choice, not an oversight — an answer pulled out would leave a discussion nobody could follow afterwards.

Three known residues, which we would rather write here: the activity log keeps a record of former name and email changes, and the 365-day clean-up its configuration announces is in fact never scheduled; your row in the search index probably survives anonymisation; measurement rows attached only to an anonymous identifier are left untouched. Write to us if you want them dealt with: like the rest, it is done by hand.

How long we keep what

Some data is pruned automatically: feed reading measurements after ninety days, semantic affinities after twenty-one days, export archives after six to twenty-four hours, download links after five minutes.

For account data, no period is set. The service configuration says so itself: the values in place are operational ones and the retention policy is still to be decided. We would rather write that than announce a figure nothing enforces. In the meantime your account data is kept for as long as the account exists, and erased when you ask.

The message you send us from this site arrives in our mailbox. Ask us to delete it and it is deleted.

Health data, and data about other people

LECO is a place for students to help each other, not a clinical record. You must not post patient data, identifiable clinical images, or health information about anybody else. The composition screen reminds you of this, moderation has a reason set aside for the case, and content of that kind is taken down.

We ask you for no special-category data within the meaning of GDPR art. 9, and we ask you not to entrust any to the service — neither about yourself nor about anyone else.

Complaining to a supervisory authority

If our answer does not satisfy you, you may lodge a complaint with the supervisory authority of your country of residence, of your place of work, or of the place of the alleged infringement. In France that is the Commission nationale de l’informatique et des libertés (cnil.fr); in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it). The European Data Protection Board publishes the full list of national authorities.

Transfers outside the European Union

The controller is established in Cameroon. The application itself runs in South Africa: the database, the application server and the cache are all hosted there. Your data therefore leaves the European Union as soon as you use LECO, and this is not a corner case of the processing: it is how it ordinarily works.

Neither Cameroon nor South Africa is covered by an adequacy decision of the European Commission. Other recipients add destinations of their own: the United States for sending email, and a global endpoint with no regional control for computing semantic vectors. Such a transfer is lawful only where one of the safeguards in chapter V of the GDPR — its arts. 44 to 49 — is in place, and this page has to say which one applies.

The safeguard that will cover these transfers has not been settled yet. The choice between the European Commission’s standard contractual clauses and the explicit consent provided for by GDPR art. 49(1)(a) is still being made, and we would rather write that here than announce a basis that is not in place. In the meantime you can write to the contact address given above, or to our representative in the European Union, to find out where that decision stands — and, if the answer matters to you, wait for it before opening an account.

Technical error monitoring

This site and the application report their technical errors to Sentry (Functional Software, Inc.). When a page breaks, a report is sent: the error message, the call stack, the address of the page, the trail of actions that led there, and your IP address and user agent, which any server receives simply because you connected to it. Reports from the application are received in Germany, inside the European Union.

Only errors trigger a capture: your browsing sessions are not recorded. That processing rests on our legitimate interest (GDPR art. 6(1)(f)) in keeping the service working; on this site, the SDK’s automatic personal-data option is switched off. You can object to it at any time, at the contact address given above.

← Back to the home pageLegal notice