Open the editor

Security and privacy

Private by design

ZipCourse builds your course on your computer. Your slides, videos, quiz answers and learner results never reach our server, so they can't leak from it.

Your content stays with you

The editor runs in your browser. Media and slides are kept in your browser's storage and in course files you save. Nothing is uploaded.

No learner data

Exported courses report to your LMS or learning record store only. ZipCourse never receives learner names, answers or scores.

No passwords to steal

You sign in with a six-digit code sent to your email. There's no password to reuse, phish or leak.

What our server does receive

  • Your email address, to sign you in and send receipts, and your email choices.
  • When you export: a random course ID, and fingerprints of the course and its parts. Each fingerprint is a one-way hash, scrambled with a secret kept in your course file, so it can't be turned back into your content or matched against other files.
  • Your devices: a label such as "Chrome on Windows" for each signed-in device, so you can see and sign them out in Account.
  • For fraud checks: the export log keeps a scrambled form of your IP address for 90 days.
  • Payments: Stripe handles them. We see what you bought and Stripe's payment references, never your card details.

The privacy notice lists every item, why we hold it and for how long.

How exported courses are protected

Each export includes a licence for that exact version of the course, signed by ZipCourse with an ECDSA P-256 key that never leaves our server. When a learner opens the course, the player checks the signature and the course's fingerprint in the learner's browser. It makes no call to ZipCourse, so courses keep working offline, behind firewalls, and for as long as your LMS hosts them.

If someone edits the course files or swaps a video after export, the fingerprint no longer matches and the player stops, reporting nothing to the LMS. That protects you as well as us: what learners see is exactly what you published.

Signing in

  • Codes work for 10 minutes and allow 5 tries. We store only a keyed hash of each code.
  • Your session is a random token in a secure, HttpOnly cookie, stored by us only as a hash. It lasts 30 days on each device.
  • Cloudflare Turnstile checks that a person, not a bot, is asking for a code or sending a message with the contact form.
  • Changing your sign-in email needs a code sent to the new address, signs out your other devices, and tells the old address.

How the service is built

  • ZipCourse runs on Cloudflare Workers, with account data in Cloudflare D1 and Durable Objects.
  • Every page is served over HTTPS only (HSTS), with a strict Content Security Policy. Website pages run one small script of our own, for the contact form, which loads Cloudflare Turnstile only when you reach the form. There are no analytics or tracking scripts.
  • Payments go through Stripe Checkout; Stripe's signed notices are checked, and every payment is confirmed with Stripe before credits are added.
  • Secrets such as the licence signing key are held as encrypted Cloudflare secrets, never in code.

Your controls

In the editor, open Account to download everything we hold about you as a file, change your sign-in email, sign out other devices, or delete your account.

Reporting a security problem

Email support@zipcourse.app with the details. We reply within one working day and won't take action against good-faith research. Our security.txt has the same contact.

Try it with your own slides

Free to build and preview. No account needed until you export.

Open the editor

Contact us

Questions, feedback, or a problem with an export? Send us a message and we'll reply within one working day.

Buying for a school, team or group? We offer discounted bulk credit packs for groups of people, and an education discount for recognised schools, colleges and universities. Choose one in the form and the credit pack you'd like.

You can also email support@zipcourse.app.

Bulk credits and education discount