Privacy Policy
How we collect, use, and protect your information
Privacy Policy
Last Updated: November 4, 2025
Introduction
Tesla Institute of MRI Technology ("we," "us," "our," or "Company") operates the TeslaMR Learn platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
1. Information We Collect
1.1 Personal Information You Provide
Account Information:
- Full name
- Email address
- Password (encrypted)
- Profile picture (optional)
- Phone number (optional)
- Date of birth
- Professional credentials or certifications
Educational Information:
- Institution or organization affiliation
- Cohort assignment
- Course enrollment data
- Learning goals and preferences
Payment Information:
- Billing name and address
- Payment method details (processed by third-party payment processors)
- Transaction history
Communications:
- Messages sent through the Service
- Support requests and correspondence
- Survey responses and feedback
1.2 Information Automatically Collected
Usage Data:
- Pages and content viewed
- Time spent on pages
- Videos watched and progress
- Quiz attempts and results
- Navigation paths through the Service
- Features used and interactions
Device and Technical Information:
- IP address
- Browser type and version
- Device type and identifiers
- Operating system
- Screen resolution
- Referral source
- Date and time of access
Cookies and Tracking Technologies:
- Session cookies for authentication
- Analytics cookies for usage tracking
- Preference cookies for user settings
- We use PostHog for analytics and session recording
1.3 Information from Third-Party Sources
Authentication Providers:
- If you sign in using third-party services (e.g., Google, Microsoft), we may receive:
- Name
- Email address
- Profile picture
- Authentication tokens
Educational Partners:
- ScanLab MR scanning practice data and performance metrics
- Cohort enrollment information from partner institutions
Payment Processors:
- Transaction confirmation and payment status
- We do not store full credit card numbers
2. How We Use Your Information
2.1 To Provide and Improve the Service
- Create and manage your account
- Authenticate your identity and maintain security
- Deliver educational content and course materials
- Track your learning progress and performance
- Administer quizzes and assessments
- Generate certificates and credentials
- Provide customer support
- Send service-related notifications
- Improve and optimize the Service
2.2 To Personalize Your Experience
- Customize content recommendations
- Remember your preferences and settings
- Provide cohort-specific information
- Display relevant learning materials
- Track streaks and achievements
2.3 To Communicate With You
- Send course updates and announcements
- Provide quiz results and feedback
- Share upcoming events and deadlines
- Respond to your inquiries and requests
- Send administrative messages
- Deliver marketing communications (with your consent)
2.4 For Analytics and Research
- Analyze usage patterns and trends
- Measure Service performance
- Conduct educational research
- Evaluate learning outcomes
- Generate aggregate statistics
- Improve educational methodologies
2.5 For Legal and Security Purposes
- Enforce our Terms of Service and EULA
- Detect and prevent fraud or abuse
- Protect against security threats
- Comply with legal obligations
- Respond to legal requests
- Protect our rights and property
3. How We Share Your Information
3.1 With Service Providers
We share information with third-party service providers who perform services on our behalf:
Infrastructure and Hosting:
- Supabase - Database, authentication, and backend services
- Render - Application hosting and deployment
Analytics and Monitoring:
- PostHog - Product analytics, session recording, and feature flags
- Analytics data may include user interactions, page views, and navigation patterns
Educational Partners:
- ScanLab MR - MRI scanning practice and performance data
- Google Calendar - Event scheduling and calendar integration
Payment Processing:
- QuickBooks - Invoicing and payment tracking
- Third-party payment processors for transaction processing
Communication Services:
- Email service providers for transactional and marketing emails
- SMS providers for text notifications (if applicable)
3.2 With Educational Institutions
If you are enrolled through a partner institution or organization:
- We may share your progress, quiz results, and completion status with your institution
- Your institution may have access to aggregate cohort performance data
- We share only information necessary for educational administration
3.3 With Other Users (Limited)
- Your name and profile picture may be visible to other users in your cohort
- Leaderboards or achievement displays (if you opt-in)
- Discussion forums or collaborative features (if applicable)
3.4 For Legal Reasons
We may disclose your information if required to do so by law or in response to:
- Court orders or subpoenas
- Government or regulatory requests
- Legal processes or investigations
- Protection of our rights, property, or safety
- Protection of the rights, property, or safety of others
3.5 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control of your information.
3.6 With Your Consent
We may share your information with third parties when you give us explicit consent to do so.
3.7 Text Messaging Data Disclosure
Tesla Institute of MRI Technology, Inc. may disclose Personal Data and other information as follows:
Third Parties that Help Provide the Messaging Service: We will not share your opt-in to an SMS short code campaign with a third party for purposes unrelated to supporting you in connection with that campaign. We may share your Personal Data with third parties that help us provide the messaging service, including, but not limited to, platform providers, phone companies, and other vendors who assist us in the delivery of text messages.
Additional Disclosures: We may disclose the Personal Data to our affiliates or subsidiaries; however, if we do so, their use and disclosure of your Personal Data will be subject to this Policy.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
4. Cookies and Tracking Technologies
4.1 Types of Cookies We Use
Essential Cookies:
- Required for authentication and security
- Remember your login session
- Cannot be disabled without affecting functionality
Analytics Cookies:
- Track usage patterns and performance
- Provided by PostHog and other analytics services
- Help us improve the Service
Preference Cookies:
- Remember your settings and preferences
- Enhance user experience
- Optional but recommended
4.2 Third-Party Tracking
PostHog Analytics:
- Tracks user interactions and behavior
- May include session recordings
- Provides feature usage analytics
- Privacy-focused analytics platform
Social Media and Third-Party Services:
- May use cookies or tracking pixels
- Subject to their own privacy policies
4.3 Your Cookie Choices
You can control cookies through your browser settings:
- Block all cookies (may affect functionality)
- Delete cookies after each session
- Set preferences for specific websites
Note: Disabling essential cookies may prevent you from using the Service.
5. Data Security
5.1 Security Measures
We implement appropriate technical and organizational measures to protect your information:
Technical Safeguards:
- Encryption in transit (SSL/TLS)
- Encryption at rest for sensitive data
- Secure authentication protocols
- Regular security updates and patches
- Access controls and authentication
- Automated backups
Organizational Safeguards:
- Limited access to personal information
- Employee training on data protection
- Regular security audits
- Incident response procedures
5.2 Account Security
You are responsible for:
- Keeping your password confidential
- Using a strong, unique password
- Logging out after each session
- Notifying us of any unauthorized access
5.3 No Guarantee
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.
6. Data Retention
6.1 How Long We Keep Your Data
Active Accounts:
- We retain your information as long as your account is active
- Course progress and quiz results are retained indefinitely for educational records
Inactive Accounts:
- Accounts inactive for 2+ years may be archived or deleted
- We will provide notice before deletion when possible
Legal and Business Requirements:
- Some information may be retained longer to comply with legal obligations
- Financial records retained per applicable laws (typically 7 years)
- Aggregate analytics data may be retained indefinitely
6.2 Deletion of Data
When we delete your data:
- Personal information is permanently deleted or anonymized
- Backups may contain data for up to 90 days
- Some information may be retained in aggregate form for analytics
7. Your Privacy Rights
7.1 Access and Portability
You have the right to:
- Access your personal information
- Request a copy of your data in a portable format
- Review your learning progress and quiz history
7.2 Correction and Update
You have the right to:
- Correct inaccurate information
- Update your profile and preferences
- Modify your account settings
7.3 Deletion
You have the right to:
- Request deletion of your account
- Remove specific information (subject to legal retention requirements)
- Withdraw consent for certain data processing
7.4 Opt-Out Rights
You have the right to:
- Unsubscribe from marketing emails
- Opt-out of analytics tracking (may affect functionality)
- Disable non-essential cookies
- Request that we stop sharing data with certain third parties
7.5 Do Not Sell My Personal Information
We do not sell your personal information to third parties for monetary consideration. Under certain privacy laws (e.g., CCPA), sharing data with service providers may be considered a "sale." You can opt-out of such sharing by contacting us.
7.6 How to Exercise Your Rights
To exercise any of these rights, contact us at:
- Email: [email protected]
- Through your account settings
- Written request to our mailing address
We will respond to your request within 30 days (or as required by applicable law).
8. Children's Privacy
The Service is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18.
If you are under 18, you may only use the Service with the involvement and consent of a parent or legal guardian.
If we become aware that we have collected personal information from a child under 18 without parental consent, we will take steps to delete that information.
9. International Data Transfers
9.1 Data Storage Location
Your information is stored on servers located in the United States and may be processed in other countries where our service providers operate.
9.2 Cross-Border Transfers
By using the Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection laws.
9.3 Data Protection Standards
We ensure that all transfers comply with applicable data protection laws and implement appropriate safeguards, such as:
- Standard contractual clauses
- Privacy Shield certifications (where applicable)
- Other recognized transfer mechanisms
10. State-Specific Privacy Rights
10.1 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Right to Know:
- Categories of personal information collected
- Sources of personal information
- Purposes for collecting or selling personal information
- Categories of third parties with whom we share information
Right to Delete:
- Request deletion of personal information (subject to exceptions)
Right to Opt-Out:
- Opt-out of the "sale" of personal information
Right to Non-Discrimination:
- We will not discriminate against you for exercising your rights
Shine the Light:
- Request information about disclosure of personal information to third parties for direct marketing purposes
To exercise these rights, contact us at [email protected]
10.2 Virginia, Colorado, Connecticut, and Other State Residents
If you reside in Virginia, Colorado, Connecticut, or other states with comprehensive privacy laws, you may have additional rights including:
- Right to access your personal information
- Right to correct inaccurate information
- Right to delete personal information
- Right to data portability
- Right to opt-out of targeted advertising
- Right to opt-out of profiling
10.3 European Union and UK Residents (GDPR)
If you are in the EU or UK, you have rights under the General Data Protection Regulation (GDPR):
Legal Basis for Processing:
- Consent (where applicable)
- Performance of a contract
- Legitimate interests
- Compliance with legal obligations
Your Rights:
- Right to access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
Data Protection Officer: Contact our Data Protection Officer at [email protected]
11. Third-Party Services and Links
11.1 Third-Party Services
The Service integrates with third-party services, each with their own privacy policies:
- Supabase: https://supabase.com/privacy
- PostHog: https://posthog.com/privacy
- ScanLab MR: Contact ScanLab for their privacy policy
- Render: https://render.com/privacy
11.2 External Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
11.3 Social Media Features
The Service may include social media features (e.g., share buttons). These features may collect your IP address and set cookies. Your interactions with these features are governed by the privacy policy of the company providing them.
12. Changes to This Privacy Policy
12.1 Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
12.2 Notification
When we make material changes:
- We will update the "Last Updated" date at the top
- We will notify you via email or through the Service
- We may require you to accept the new policy before continuing to use the Service
12.3 Review
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Tesla Institute of MRI Technology
Email: [email protected]
Website: https://learn.teslamr.com
Mailing Address:
Tesla Institute of MRI Technology
11023 Bea Mar Court
Fairfax, Virginia 22030
United States
Response Time:
We will respond to privacy requests within 30 days (or as required by applicable law).
14. Effective Date
This Privacy Policy is effective as of November 4, 2025 and applies to all information collected by the Service.
Version: 1.0
15. Acknowledgment
BY USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR INFORMATION AS DESCRIBED HEREIN.
Appendix: Data We Collect Summary
| Category | Examples | Purpose | Legal Basis |
|---|---|---|---|
| Account Information | Name, email, password | Account creation and authentication | Contract performance |
| Educational Data | Course progress, quiz results | Provide educational services | Contract performance |
| Usage Data | Pages viewed, time spent | Improve Service, analytics | Legitimate interest |
| Device Information | IP address, browser type | Security, fraud prevention | Legitimate interest |
| Payment Information | Billing details, transactions | Process payments | Contract performance |
| Communications | Support emails, feedback | Customer support, improvements | Legitimate interest |
| Cookies | Session cookies, analytics | Authentication, analytics | Consent / Legitimate interest |
Last Reviewed: November 4, 2025