Privacy Policy
Draft — pending review
This is a plain-language draft prepared for review. It describes how the platform actually works today, but it has not yet been reviewed by legal counsel and may change.
1. What we store
When you create an account we store your email address, a bcrypt hash of your password (never the password itself), and your public username. If you fill in the intake or settings, we also store your display name, bio, learning goals, weekly-hours preference, and experience level. As you learn, we record enrollments, lesson completions, quiz attempts and scores, XP, and streaks — that is the product.
2. What is public
Your profile page (/u/your-username) shows your username, display name, bio, learning goals, and progress statistics. Your email address is never shown publicly, and auto-generated usernames are neutral handles that don't reveal it. Community posts appear under your username.
3. Cookies
We use one session cookie to keep you signed in and a CSRF token to protect forms. There are no advertising or third-party analytics cookies. The visitor counter described below sets no cookie at all.
4. Visitor statistics
We count how many people read AIMaks from each country and publish the totals in the footer and on the audience page. Each page you open sends your browser's time zone to our server, which places the visit in a country from the address the request came from (looked up in a database on our own server — the address is not sent to anyone) or, failing that, from the time zone. To count you once per day we keep a hash of your address and browser that is re-salted every day, so it cannot recognise you tomorrow and cannot be turned back into an address. We store only that daily hash and the per-country totals — never your address, your time zone, or the pages you read.
5. Third parties
We don't sell or share your data with advertisers. When you run Python code inside a lesson, your browser downloads the Pyodide runtime from the jsDelivr CDN — like any CDN request, jsDelivr sees your IP address but receives none of your account data. The code you run executes in your own browser.
6. Export and deletion
Settings → Data lets you export everything we hold about you as JSON, and delete your account. Deletion is immediate and removes your profile, progress, and community posts.
7. Contact
Privacy questions or requests: [email protected]. See also the Terms of Service.