Privacy Policy — SCORMBridge
Last updated: August 2026
The Full Policy Lives on scormbridge.app
SCORMBridge is a hosted platform operated by lost end found Ltd (trading as SCORMBridge). Because it runs accounts, billing and a learner-tracking proxy — rather than being an offline app — its privacy policy is longer than the ones for our Mac apps, and it is maintained alongside the product itself:
- Privacy Policy: scormbridge.app/privacy
- Terms of Service: scormbridge.app/terms
- Data Processing Addendum: scormbridge.app/dpa
Those pages are the authoritative versions. What follows is a plain-language summary.
The Short Version
- Two roles. For the website, demo requests and portal accounts (publisher staff, client admins and members) we are the data controller. For the data that flows through the SCORM proxy when a learner launches a licensed course, we are a data processor acting on the instructions of the client organisation that runs the LMS, under the DPA.
- Account data — name, email, a salted password hash, role, organisation, preferences, sign-in security data (session tokens, IP and browser per sign-in), invitations, and Stripe billing references. Card details never touch our systems — they are entered on Stripe-hosted pages.
- Learner data (as processor) — the learner id/name the LMS passes to the course, a per-launch session id, the launching LMS hostname, browser user agent, time of launch, and the SCORM values the course reports back (completion, success, score, time,
suspend_data). IP addresses are used transiently for rate limiting and are not stored against launch records. - Course content is stored privately and served only to licensed learners through signed, short-lived links.
- Analytics are self-hosted (Umami), cookieless, and never identify signed-in users by name or email. No advertising or third-party tracking networks.
Where Data Lives
The platform runs on Cloudflare. Databases, course content and profile pictures are stored in Cloudflare's Western Europe region. Payments are handled by Stripe. Where data leaves the UK/EEA it does so under the UK IDTA/Addendum or EU Standard Contractual Clauses built into our providers' terms.
Retention (Headlines)
- Portal accounts — until you delete your account or an organisation admin removes you.
- Learner launch and tracking data — for the life of the licence, then deleted within 12 months of the client relationship ending (or within 30 days of a verified deletion request from the client organisation).
- Billing records — 6 years after the tax year they relate to (UK requirement).
The full retention table is in the canonical policy.
Your Rights
Under UK and EU data-protection law you can ask for a copy of your personal data, have it corrected or deleted, restrict or object to processing, and receive it in a portable format. If you are a learner, the organisation operating your LMS is the controller for your learning records — contact them first and we will help them respond.
Contact Information
- Email: support@scormbridge.app (subject "Privacy")
- Company: lost end found Ltd, trading as SCORMBridge
- Registration: Company Registration No. 15713779
- Location: Registered in England and Wales
You can also complain to the Information Commissioner's Office (ico.org.uk) — we would appreciate the chance to address your concern first.