Privacy Policy

Effective date: February 21, 2026

OnFire Lab, LLC ("we," "us," or "OnFire Lab") operates LessonDebrief (lessondebrief.com). This policy explains what data we collect, why we collect it, how we use it, and your choices.

1. Information we collect

Account information

When you create an account we collect your name, email address, optional phone number, and role (CFI or student). We require a permanent email address; temporary or disposable email providers are not accepted at registration. Passwords are hashed with bcrypt and never stored in plain text. If you register as a CFI, we may periodically verify your instructor credentials; you agree to provide accurate, verifiable identification for this purpose.

Lesson and training data

CFIs enter lesson details including lesson type, tags, focus areas, debrief notes, and optional voice recordings. Voice recordings are sent to OpenAI for transcription and are also stored securely on AWS S3 for up to 90 days, after which they are automatically deleted. Lesson data is processed by automated agents (powered by Anthropic Claude and OpenAI) to generate study pack drafts. The resulting transcripts, study packs, and student prep checklists are stored in our database to provide the service.

Shared study packs

CFIs and students may each share a study pack via a private, unguessable link. Each role has an independent sharing toggle. Shared packs are read-only and display limited information: the pack content, the date it was sent, and the instructor's first name and last initial. Shared links are not indexed by search engines. Sharing can be revoked at any time, which immediately disables the link.

Bot protection

We use Cloudflare Turnstile on our signup form to prevent automated abuse. Turnstile may collect limited interaction data (such as browser type and session signals) to distinguish humans from bots. No personal data is shared with Cloudflare for this purpose beyond what is necessary for the challenge.

Usage data

We use Google Analytics and PostHog to collect usage statistics such as page views, session duration, device type, and product usage events (e.g. feature interactions, navigation patterns). PostHog may also record anonymized session replays to help us understand how users interact with the product. This data is used to improve LessonDebrief and cannot be used to identify you outside of our platform. You can opt out using a browser extension or ad blocker.

2. How we use your data

  • Provide and improve LessonDebrief (lesson logging, automated study pack generation, prep tracking)
  • Authenticate you and secure your account
  • Send transactional emails (account confirmation, password reset, invitations)
  • Understand how the product is used so we can make it better

We do not sell your personal data. We do not use your training data to train AI models. Your lesson and student data is only accessible to you and the CFI/student relationship you establish within the platform.

3. Third-party services

ServicePurposeData shared
OpenAIVoice transcriptionAudio recordings
Anthropic (Claude)Automated study pack generationLesson debrief text, tags, focus areas
StripePayment processing for subscriptionsEmail, name; card details handled entirely by Stripe
Cloudflare TurnstileBot protection on signupBrowser signals for challenge verification
Google AnalyticsAnonymous usage analyticsPage views, session data (no personal info)
PostHogProduct analytics, session replayPage views, feature usage events, anonymized session replays
DatadogApplication monitoring and error trackingServer-side logs and performance metrics (no personal info)
Amazon Web Services (AWS)Cloud hosting and log storageAll application data is hosted on AWS infrastructure

OpenAI processes data under their API data usage policy, which states that API inputs and outputs are not used to train their models. Anthropic processes data under their privacy policy; API inputs and outputs are not used to train their models. Stripe processes payment data under their privacy policy. Cloudflare processes Turnstile data under their privacy policy. PostHog processes analytics data under their privacy policy. Datadog processes monitoring data under their privacy policy. AWS processes data under their privacy notice. We do not store credit card numbers or payment card details on our servers.

4. Data retention

Your account and training data are retained as long as your account is active. Voice recordings are stored for up to 90 days after upload and then automatically deleted. If you delete your account, we will delete your personal data (including any stored recordings) within 30 days. Anonymized, aggregated analytics data may be retained indefinitely.

5. Data security

We use industry-standard measures to protect your data, including encrypted connections (TLS), httpOnly authentication cookies, bcrypt password hashing, and role-based access controls. CFIs can only access data for their own students, and students can only see packs sent to them. When a CFI sends an invite, their email address and optional phone number are visible to the recipient so the student can verify who the invite is from.

6. Your rights

You may:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Opt out of analytics by using a browser ad blocker

To exercise any of these rights, email us at support@lessondebrief.com.

7. Children's privacy

LessonDebrief is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

8. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the site. Your continued use of LessonDebrief after changes constitutes acceptance of the updated policy.

9. Contact us

OnFire Lab, LLC
Email: support@lessondebrief.com