Privacy Policy

Last updated 27 July 2026

Magic Journey Sanctuary LLC, trading as Magic Post Op Academy, is the controller of the personal data described here. We collect as little as the platform can function on, we do not sell it, and we do not share it with advertisers.

1. What we collect

Account data. Your full name, your email address and a cryptographic hash of your password. We never store your password itself and cannot recover it.

Learning data. Which lessons you have marked complete, your quiz attempts and scores, and any certificate issued to you.

Purchase data. What you bought, the amount, the currency, the status and a reference from our payment provider. We do not receive or store your card number, expiry date or security code; those go directly to the payment provider.

Technical data. For each active session we store the IP address and browser user agent it was created from, so that suspicious access can be investigated and abuse rate-limited.

Correspondence. Anything you send us by email or WhatsApp.

We do not ask for and do not want health data about you or about your clients. Do not send us client records.

2. Why we use it, and on what basis

  • To deliver the course you bought. Basis: performance of our contract with you.
  • To issue and verify certificates. Basis: performance of our contract, and our legitimate interest in a credential that can be trusted.
  • To keep the platform secure and prevent abuse. Basis: our legitimate interest in protecting students and the service.
  • To send course updates and new material. Basis: your consent, given at signup and withdrawable at any time.
  • To meet tax and accounting obligations. Basis: legal obligation.

We do not use your data for automated decision-making that produces a legal or similarly significant effect on you.

3. Cookies

We set one cookie: a strictly necessary session cookie that keeps you signed in. It is httpOnly, so scripts in your browser cannot read it, and it is marked SameSite so it is not sent on cross-site requests. It expires 30 days after sign-in, or immediately when you sign out.

We run no advertising cookies, no cross-site tracking pixels and no third-party analytics that profile you. Because we set no non-essential cookies, there is no consent banner to click past.

Video lessons are embedded from YouTube using their no-cookie domain, or from Vimeo. A video player only loads when you open a lesson that has one, and at that point the provider may set its own cookies under its own policy.

4. Who we share it with

We share the minimum necessary with:

  • our payment provider, to take payment and to confirm it;
  • our email provider, to deliver account and reset messages;
  • our hosting provider, which stores the database on our behalf;
  • our accountants and, where we are legally obliged, public authorities.

Each acts under contract and may use the data only to provide their service to us. We never sell personal data, and we never share your address with another student or with a third party for their own marketing.

5. Public certificate verification

Certificates are verifiable by code at our public verification page. Entering a valid code discloses the holder’s name, the certificate type, the issue date and whether it is still valid. Nothing else is disclosed: not your email, not your purchases, not your quiz scores. Anyone who has your code already has your certificate in front of them.

6. How long we keep it

  • Account and learning data: for as long as your account is open, then deleted within 90 days of closure.
  • Certificate records: retained after account closure, because a credential that stops verifying is worthless to its holder. You may ask us to revoke and remove yours.
  • Purchase records: seven years, to meet tax and accounting obligations.
  • Session records: deleted at expiry, and immediately when you sign out.
  • Password reset tokens: one hour, and invalidated the moment they are used.

7. Your rights

Depending on where you live, you have the right to access the data we hold about you, to have inaccurate data corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent to marketing at any time. Residents of the EU and UK hold these rights under the GDPR; California residents hold comparable rights under the CCPA, including the right not to be discriminated against for exercising them.

To exercise any of these, write to contact@magicpostop.com. We respond within 30 days. If you are unhappy with our response you may complain to your local data protection authority.

8. Security

Passwords are stored as bcrypt hashes. Session and password-reset tokens are stored hashed, so a copy of our database would not let anyone sign in as you. Traffic is served over HTTPS. Access to the production database is restricted to the people who operate the service.

No system is perfect. If a breach ever affects your data we will notify you and the relevant authority without undue delay.

9. International transfers

We are based in the United States and our infrastructure is operated there and in the European Union. Where we transfer personal data out of the EU or UK we rely on the European Commission’s standard contractual clauses.

10. Children

This is a professional programme for adults. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, write to contact@magicpostop.com and we will delete it.

11. Contact

Magic Journey Sanctuary LLC
2708 Glenwood Rd, Brooklyn, NY 11210
contact@magicpostop.com