Legal

Privacy Policy

Draft — pending review

This is a plain-language draft prepared for review. It describes how the platform actually works today, but it has not yet been reviewed by legal counsel and may change.

1. What we store

When you create an account we store your email address, a bcrypt hash of your password (never the password itself), and your public username. If you fill in the intake or settings, we also store your display name, bio, learning goals, weekly-hours preference, and experience level. As you learn, we record enrollments, lesson completions, quiz attempts and scores, XP, and streaks — that is the product.

2. What is public

Your profile page (/u/your-username) shows your username, display name, bio, learning goals, and progress statistics. Your email address is never shown publicly, and auto-generated usernames are neutral handles that don't reveal it. Community posts appear under your username.

3. Cookies

We use one session cookie to keep you signed in and a CSRF token to protect forms. There are no advertising or third-party analytics cookies.

4. Third parties

We don't sell or share your data with advertisers. When you run Python code inside a lesson, your browser downloads the Pyodide runtime from the jsDelivr CDN — like any CDN request, jsDelivr sees your IP address but receives none of your account data. The code you run executes in your own browser.

5. Export and deletion

Settings → Data lets you export everything we hold about you as JSON, and delete your account. Deletion is immediate and removes your profile, progress, and community posts.

6. Contact

Privacy questions or requests: [email protected]. See also the Terms of Service.