Legal

Privacy policy

What we collect when you apply to Co/Op, why we collect it, who it goes to, and how to get it back or get it deleted. Last updated: [date pending review].

Who we are

Co/Op is the education house of Co/Unity. This site, learn.counity.xyz, is where you apply to Chapter 1, Community Leadership 2.0. Co/Unity decides what happens to the information described here, which makes us the controller of it.

Co/Unity, [company registration details], [registered address]. Questions about this policy, or any request under it, go to [contact email].

The short version

  • Two forms on this site collect personal data. Nothing else does.
  • We use what you send to review your application, plan the cohort, and (once you graduate) introduce you to work through the Co/Unity network.
  • It is stored in a Postgres database hosted by Railway. Only our server-side code can reach it.
  • We do not sell it, we do not advertise to you, and there is no third-party ad tracking on this site.
  • You can ask for a copy of it, or ask us to delete it, at any time.

What we collect

Only what you type into a form, plus the small amount of context described at the end of this section. There is no account, no profile, and no tracking pixel.

Everyone who applies for a seat

  • Full name and email address. Required.
  • Discord username, city and timezone. Optional. Timezone and city tell us what session times work for the cohort.
  • Current role: community manager, moderator, founder, marketing, or other.
  • Communities you run or moderate, including any links you choose to paste in. Optional.
  • Your niche: gaming, AI, DeFi and trading, NFTs, creator and social, SaaS, consumer, nonprofit, or other.
  • Time in community roles: under a year, 1 to 3, 3 to 5, or 5 plus.
  • Your answer to what you want to be able to do six weeks from now. Required, and the part we read first.
  • How you heard about us and a partner code, if you have one. Both optional.
  • Two checkbox answers: whether you want to be considered for a scholarship, and whether you want to be told when Chapter 2 is revealed.
  • The fact that you agreed to this policy when you submitted the form.

Scholarship applicants, in addition

  • Links to communities, servers, or content you have worked on, with your role in each.
  • Five written answers: what you want to be able to do after six weeks, a community you changed, a community you admire, the hardest moderation situation you have handled, and a community where you felt you belonged. These run to a few hundred words each, so write them knowing a person on our team will read them.
  • Four commitment answers: half the live sessions, two to three hours a week, submissions 24 hours before each workshop, and whether you could cover the balance of a partial seat.
  • Anything else you want to add, and a link to a public post if you take the spotlight option. Both optional.

Recorded alongside your answers

  • The chapter and season you applied to, and the dates your record was created and last updated.
  • Its status in our review: queued, invited, enrolled, or declined. For scholarships we also store the decision, when it was made, and who made it.
  • Campaign parameters from the link you arrived on (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and the referring website, if you came from one. These are held in your browser's session storage while you move from the landing page to the form, then saved with your application.
  • Your IP address is passed to Cloudflare with the spam-check token so it can score the submission. We do not store it in our database.

What we do not collect

No payment details. There is no checkout on this site while applications are open, so nothing takes a card number. No advertising cookies, no tracking pixels, no fingerprint scripts. We do not buy data about you from anyone else, and we do not enrich what you send us with third-party profiles.

One gap we have not closed yet: [whether application answers are ever read with AI tooling, and if so which]

Why we use it, and the legal basis

Four purposes, and nothing outside them.

  • Reviewing your application and replying to you. Deciding who gets a seat, deciding scholarships, and sending you the confirmation and the checkout link when dates lock. The basis is the steps you asked us to take before we enter into a contract, together with the agreement you gave on the form.
  • Cohort planning. Timezone, role, niche, tenure, and your six-week answer tell us when to run live sessions, how to build breakout rooms, and what to weight in the curriculum. The basis is our legitimate interest in running the program well.
  • The Co/Unity talent network. Graduates join the network, and when a role opens in a graduate's niche, certified graduates are where we look first. The basis is our legitimate interest, and yours, in that introduction. If you do not want to be in the network, tell us and you are out of it, without affecting your seat.
  • Knowing which channels work. The campaign parameters tell us where applicants come from, in aggregate. The basis is our legitimate interest in not wasting the marketing budget.

If you ticked the Chapter 2 box, we will email you once about it. That one is consent, and you can withdraw it in a line of email or from the link in the message.

Where we rely on a legitimate interest, we have weighed it against your rights, and you can object to any of it. See your rights below.

Who sees it

The Co/Unity people who review applications and plan cohorts, and the following providers, each doing one job for us. There is nobody else on this list.

  • Railway hosts the Postgres database your application is stored in.
  • Vercel hosts this site. Vercel Analytics counts page views without cookies and without identifying you.
  • Resend sends your confirmation email and the notification to our team. That notification carries your name, email, role, niche, your six-week answer, whether you asked about a scholarship, your partner code, and the campaign source.
  • Cloudflare runs the Turnstile spam check, which receives a challenge token and your IP address.

We do not sell your data, share it with advertisers, or hand it to anyone for their own marketing. If we are ever legally required to disclose something, we will tell you unless we are barred from doing so.

These providers may process data outside the country you live in, including in the United States. Where data leaves the UK or the European Economic Area we rely on the transfer terms in our agreement with each provider. [international transfer mechanism]

How long we keep it

Your application stays with us while the season you applied to is planned and run, and for [retention period] after it, so we can plan the next season, answer questions about your certification, and make the network introductions the program promises.

Applying again in the same season updates your existing record rather than creating a second one, so there is one row per person per season, not a pile of drafts.

Ask us to delete it and we will, unless we have to keep a record for accounting or legal reasons, in which case we keep the minimum and tell you what it is.

Your rights

If you are in the EU or the UK, data protection law gives you the rights below. We handle these requests the same way for everyone who applies, wherever you live.

  • Access. Ask for a copy of everything we hold about you.
  • Correction. Tell us anything that is wrong and we will fix it.
  • Deletion. Ask us to erase your record.
  • Portability. Ask for your answers in a machine-readable file you can take elsewhere.
  • Objection. Object to anything we do on the basis of a legitimate interest, including cohort planning and the network.
  • Restriction. Ask us to hold your record and stop using it while a question about it is settled.
  • Withdrawing consent. Take back the Chapter 2 opt-in at any time. It does not affect anything we did before you withdrew it.

Email [contact email] from the address you applied with, tell us which of these you want, and we will come back to you within one month. It is free. If we cannot do what you asked, we will tell you why.

If you are not happy with how we handled it, you can complain to the data protection authority where you live or work.

Cookies, storage, and analytics

This site sets no advertising cookies and runs no third-party ad tracking. Vercel Analytics measures traffic in a privacy-friendly way, without cookies and without building a profile of you.

One thing is stored in your browser: the campaign parameters and referrer from the link you arrived on, kept in session storage so the attribution survives the click from the landing page to the form. It clears when you close the tab, and blocking site data costs you nothing on this site.

How it is protected

There is no public database surface. The connection string lives on the server and never reaches your browser, nothing public can query the tables, and the site is served over HTTPS. Access to submissions is limited to the Co/Unity people who review them.

No system is perfectly secure, and we will not pretend otherwise. If something happens that affects your data, we will tell you and tell you what we did about it.

Age

Co/Op is built for people already working in community roles. It is not aimed at children, and we do not knowingly collect information from anyone under [minimum age]. If you think a younger person has applied, email us and we will remove the record.

Changes to this policy

When the forms change, this page changes with them. The date at the top always tells you when it was last touched, and anything material gets flagged to people already in the queue.

Contact

[contact email]. One person reads that inbox, so say what you need plainly and you will get a plain answer back.

Read the termsBack to Chapter 1