Privacy Policy
Draft — pending review
This is a plain-language draft prepared for review. It describes how the platform actually works today, but it has not yet been reviewed by legal counsel and may change.
1. What we store
When you create an account we store your email address, a bcrypt hash of your password (never the password itself), and your public username. If you fill in the intake or settings, we also store your display name, bio, learning goals, weekly-hours preference, and experience level. As you learn, we record enrollments, lesson completions, quiz attempts and scores, XP, and streaks — that is the product.
2. What is public
Your profile page (/u/your-username) shows your username, display name, bio, learning goals, and progress statistics. Your email address is never shown publicly, and auto-generated usernames are neutral handles that don't reveal it. Community posts appear under your username.
3. Cookies
We use one session cookie to keep you signed in and a CSRF token to protect forms. There are no advertising or third-party analytics cookies.
4. Third parties
We don't sell or share your data with advertisers. When you run Python code inside a lesson, your browser downloads the Pyodide runtime from the jsDelivr CDN — like any CDN request, jsDelivr sees your IP address but receives none of your account data. The code you run executes in your own browser.
5. Export and deletion
Settings → Data lets you export everything we hold about you as JSON, and delete your account. Deletion is immediate and removes your profile, progress, and community posts.
6. Contact
Privacy questions or requests: [email protected]. See also the Terms of Service.