Privacy Policy
Last Updated: July 22, 2026
This Privacy Policy explains how CoGen, LLC collects, uses, discloses, and protects your personal information when you use Terraform Academy and Terraform Academy Max. By using our services, you consent to the practices described in this policy.
1. Introduction
CoGen, LLC ("Company," "we," "us," or "our") operates the Terraform Academy platform and Terraform Academy Max subscription service. We are committed to protecting your privacy and ensuring transparency about how we handle your personal information.
This Privacy Policy applies to all users of our websites, applications, and services, including visitors, registered users, and subscribers. It describes our practices regarding information collection, use, disclosure, and protection.
For purposes of applicable data protection laws, CoGen, LLC is the data controller responsible for your personal information.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide when using our services:
- Account Information: Email address, username, password (encrypted), and profile details when you create an account.
- Payment Information: Billing address and payment card details (processed securely by Stripe; we do not store complete card numbers).
- Communication Data: Messages, feedback, and support requests you send to us.
- User Content: Any content you submit through our platform, including profile information and game statistics.
2.2 Information Collected Automatically
When you access our services, we automatically collect certain information:
- Device Information: Device type, operating system, browser type and version, screen resolution, and unique device identifiers.
- Usage Information: Pages visited, features used, time spent on pages, click patterns, and navigation paths.
- Log Data: IP address, access times, referring URLs, and error logs.
- Game Data: Performance statistics, scores, rankings, and gameplay activity in Terraform Academy Max.
- Location Information: Approximate geographic location based on IP address.
2.3 Cookies and Similar Technologies
We use cookies, web beacons, and similar tracking technologies to collect information about your interactions with our services. See Section 7 for detailed information about our cookie practices and your choices.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing and Improving Services
- Providing AI-assisted features (TCv7 chat, AI Coach, provider analysis) — user inputs are processed by third-party AI providers as described in Section 6.6;
- Creating and managing your account;
- Processing subscriptions and payments;
- Delivering content, labs, quizzes, and gaming features;
- Maintaining leaderboards and competitive rankings;
- Personalizing your experience and recommendations;
- Analyzing usage patterns to improve our services;
- Developing new features and content.
3.2 Communications
- Sending transactional emails (account confirmations, receipts, subscription updates);
- Providing customer support;
- Sending service announcements and updates;
- Marketing communications (with your consent where required).
3.3 Security and Legal Compliance
- Detecting, preventing, and addressing fraud, abuse, and security issues;
- Enforcing our Terms of Service;
- Complying with legal obligations;
- Responding to legal requests and preventing harm.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions that require a legal basis for processing personal data, we rely on the following grounds:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and service delivery | Contract performance |
| Payment processing | Contract performance |
| Security and fraud prevention | Legitimate interests |
| Service improvement and analytics | Legitimate interests |
| Marketing communications | Consent |
| Non-essential cookies | Consent |
| Legal compliance | Legal obligation |
5. Data Sharing and Disclosure
We do not sell your personal information to third parties. We may share your information in the following circumstances:
5.1 Service Providers
We share data with third-party service providers who perform services on our behalf, subject to contractual obligations to protect your information. See Section 6 for details about our third-party processors.
5.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal requests, including:
- Court orders and subpoenas;
- Government or regulatory agency requests;
- Legal processes to protect our rights or the rights of others;
- Emergency situations involving potential threats to safety.
5.3 Business Transfers
If CoGen, LLC is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
5.4 Aggregated or De-identified Data
We may share aggregated or de-identified information that cannot reasonably be used to identify you for analytics, research, or other purposes.
6. Third Party Data Processors
We use the following third-party service providers to operate our services. These providers process personal data on our behalf and are contractually obligated to protect your information:
6.1 Stripe, Inc.
Purpose: Payment processing for subscriptions
Data Processed: Payment card information, billing address, email address, transaction details
Location: United States (with global infrastructure)
Privacy Policy: stripe.com/privacy
Stripe is PCI-DSS Level 1 certified. Payment card data is transmitted directly to Stripe's secure servers; we do not store complete card numbers.
6.2 Supabase, Inc.
Purpose: Database hosting, user authentication, and backend services
Data Processed: Account information, subscription status, user content, application data
Location: Data centers in multiple regions; user data stored based on account configuration
Privacy Policy: supabase.com/privacy
Supabase provides encrypted data storage and secure authentication services compliant with industry standards.
6.3 Cloudflare, Inc.
Purpose: Content delivery network (CDN), DDoS protection, security services, and serverless computing
Data Processed: IP addresses, request headers, traffic data, cached content
Location: Global network of data centers
Privacy Policy: cloudflare.com/privacypolicy
Cloudflare provides security and performance services. They process traffic data to deliver content and protect against threats.
6.4 Google Analytics
Purpose: Website analytics and usage statistics
Data Processed: Device information, usage patterns, IP address (anonymized), page views
Location: United States
Privacy Policy: policies.google.com/privacy
You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
6.5 GitHub Pages
Purpose: Website hosting
Data Processed: IP addresses, request headers, access logs
Location: United States
Privacy Policy: GitHub Privacy Statement
6.6 OpenAI, LLC
Purpose: Powering AI-assisted features including TCv7 chat (HashiCorp Hub), AI Coach (labs & certifications), provider release analysis, and IaC debug assistance
Data Processed: User-submitted text inputs to AI features (chat messages, questions, prompts); system-generated context data (platform status, provider versions, incident data)
Location: United States
Privacy Policy: openai.com/policies/privacy-policy
AI feature inputs are transmitted to OpenAI via our backend API. We do not send account credentials, payment data, or subscription information to OpenAI. You should not include sensitive personal information, passwords, API keys, or confidential data in AI input fields. AI conversations are not stored persistently on our servers. See our AI Policy for full details on AI data handling.
6.7 Meta Platforms, Inc.
Purpose: Marketing analytics and advertising measurement via Meta Pixel
Data Processed: Page view events, conversion events, device information, IP address (hashed)
Location: United States
Privacy Policy: facebook.com/privacy/policy
You can opt out of Meta advertising at facebook.com/ads/preferences.
7. Cookies and Tracking Technologies
7.1 What Are Cookies
Cookies are small text files placed on your device when you visit a website. They help websites remember your preferences and understand how you interact with the site.
7.2 Types of Cookies We Use
| Category | Purpose | Required |
|---|---|---|
| Strictly Necessary | Essential for site functionality, authentication, and security | Yes |
| Functional | Remember preferences and settings | No |
| Analytics | Understand usage patterns and improve services | No |
| Performance | Monitor and optimize site performance | No |
7.3 Managing Cookies
You can control your cookie preferences through our Cookie Preferences page. You can also configure your browser to block or delete cookies, though this may affect site functionality.
Most browsers allow you to:
- View what cookies are stored and delete individual cookies;
- Block third-party cookies;
- Block all cookies;
- Delete all cookies when you close the browser.
7.4 Do Not Track
Some browsers include a "Do Not Track" (DNT) feature. We currently do not respond to DNT signals because there is no consistent industry standard for compliance. We will update this policy if a standard is established.
8. Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including:
- Account Information: Retained while your account is active and for a reasonable period afterward to comply with legal obligations.
- Transaction Records: Retained for at least 7 years for tax and legal compliance.
- Usage Data: Retained for up to 26 months for analytics purposes.
- Support Communications: Retained for up to 3 years after resolution.
- Game Statistics: Retained while your account is active; may be retained in aggregated form after account deletion.
When personal information is no longer needed, we securely delete or anonymize it. Anonymized data may be retained indefinitely for statistical purposes.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:
- Encryption of data in transit using TLS/SSL;
- Encryption of sensitive data at rest;
- Regular security assessments and vulnerability testing;
- Access controls limiting employee access to personal data;
- Secure coding practices and code review;
- Incident response procedures;
- Regular backups and disaster recovery planning.
Despite these measures, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security of your information.
10. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information, subject to legal obligations.
- Portability: Request a copy of your data in a structured, machine-readable format.
- Opt-out: Opt out of marketing communications at any time.
- Withdraw Consent: Where processing is based on consent, withdraw consent at any time.
To exercise these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law.
11. GDPR Rights (European Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
11.1 Additional Rights
- Right to Object: Object to processing based on legitimate interests.
- Right to Restriction: Request restriction of processing in certain circumstances.
- Right to Lodge a Complaint: File a complaint with your local data protection authority.
- Right Not to be Subject to Automated Decisions: Not be subject to decisions based solely on automated processing that produce legal or significant effects.
11.2 Data Protection Authority
You have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities can be found at edpb.europa.eu.
11.3 Data Transfers
When we transfer personal data outside the EEA, we use appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, or rely on adequacy decisions.
12. CCPA Rights (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights:
12.1 Right to Know
You have the right to request that we disclose:
- Categories of personal information we have collected;
- Sources from which personal information was collected;
- Business purposes for collecting personal information;
- Categories of third parties with whom we share personal information;
- Specific pieces of personal information we have collected about you.
12.2 Right to Delete
You have the right to request deletion of personal information we have collected, subject to certain exceptions.
12.3 Right to Non-Discrimination
We will not discriminate against you for exercising your CCPA rights.
12.4 We Do Not Sell Personal Information
CoGen, LLC does not sell personal information as defined under the CCPA.
12.5 Authorized Agents
You may designate an authorized agent to make requests on your behalf. The agent must provide proof of authorization.
13. International Data Transfers
CoGen, LLC is based in the United States. If you access our services from outside the United States, your information will be transferred to and processed in the United States and other countries where our service providers operate.
These countries may have data protection laws that differ from your jurisdiction. By using our services, you consent to the transfer of your information to these countries.
For transfers from the EEA, UK, or Switzerland, we implement appropriate safeguards including:
- Standard Contractual Clauses approved by the European Commission;
- Adequacy decisions by the European Commission;
- Binding corporate rules where applicable;
- Certifications and codes of conduct with enforceable commitments.
14. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
If we become aware that we have collected personal information from a child under 18 without parental consent, we will take steps to delete that information promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy;
- Provide notice through our services or by email for significant changes;
- Where required by law, obtain your consent to the changes.
We encourage you to review this Privacy Policy periodically. Your continued use of the services after any changes indicates your acceptance of the updated policy.
16. Third-Party Trademarks
Terraform Academy is an independent educational platform and is not affiliated with, endorsed by, or sponsored by any of the companies whose products, certifications, or technologies are referenced in our educational content. All third-party trademarks, service marks, logos, and brand names referenced in our services are the property of their respective owners, including but not limited to:
- HashiCorp, Inc. — "HashiCorp," "Terraform," and related marks are registered trademarks of HashiCorp, Inc.
- Amazon Web Services, Inc. — "AWS," "Amazon Web Services," and all AWS service names and logos are trademarks of Amazon.com, Inc. or its affiliates.
- Google LLC — "Google Cloud," "GCP," and all Google Cloud service names and logos are trademarks of Google LLC.
- Microsoft Corporation — "Microsoft Azure," "Azure," and all Azure service names and logos are trademarks of Microsoft Corporation. "GitHub" and the GitHub logo are trademarks of GitHub, Inc., a Microsoft subsidiary.
- The Linux Foundation — "Kubernetes," the Kubernetes logo, and CNCF certification marks are trademarks of The Linux Foundation.
- Docker, Inc. — "Docker" and the Docker logo are trademarks of Docker, Inc.
- OpenTofu — "OpenTofu" and the OpenTofu logo are trademarks of the OpenTofu project under the Linux Foundation.
Reference to any third-party products, services, or trademarks is for educational and descriptive purposes only and does not imply any affiliation with or endorsement by those trademark holders. CoGen, LLC makes no claim to ownership of any third-party trademarks referenced herein.
For the full trademark attribution and third-party brand disclaimer applicable to our educational content, please refer to Section 9.5 of our Terms of Service.
17. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
CoGen, LLC
Data Protection Inquiries
Email: [email protected]
Website: www.terraformacademy.app
For general support: [email protected]
We will respond to your inquiry within 30 days, or sooner if required by applicable law.