Skip to content

Cookie Policy

Last updated

What PyLearn stores in your browser, and why. The short answer is a sign-in cookie, two cookies that protect it, and three values that never leave your machine.

The cookies

All three are set by us, on this domain, and all of them exist to make signing in work. Under the ePrivacy rules they are strictly necessary, which is why we do not ask permission for them — without them there is no account, and without an account there is no course.

CookieWhat it doesHow long
authjs.session-token__Secure-authjs.session-token over HTTPSKeeps you signed in. Holds a signed token identifying your session — not your password.Expires on its own, and is cleared when you sign out.
authjs.csrf-token__Host-authjs.csrf-token over HTTPSProves a sign-in or sign-out request came from this site rather than someone else's page.Session cookie — gone when you close the browser.
authjs.callback-url__Secure-authjs.callback-url over HTTPSRemembers the page you were heading to so that signing in returns you to it.Session cookie — gone when you close the browser.

Each is marked HttpOnly where it can be, restricted to this site with SameSite, and sent only over HTTPS in production.

Kept in your browser

These are not cookies. They live in your browser’s own storage, are written only as a direct result of something you did on the page — choosing a setting, or typing in the playground — and are never sent to our servers:

  • theme — Light, dark or follow-your-system, so the site does not flash the wrong one.
  • pylearn:font-size — The text size you chose, applied before the page paints.
  • pylearn:playground-draft — Whatever you last typed in the playground, so a reload — or a trip through the signup form — does not lose it. Kept for that tab only, cleared when you close it, and never transmitted.

The Python runtime is also cached by your browser after its first download, the same way any large file on any site is. That is the browser’s own cache doing its job, and clearing it simply means the next lesson downloads the runtime again.

The advertising cookies

PyLearn advertises on Facebook and Instagram, Google. To know whether that is worth doing we need to see that an ad led to a sign-up rather than guess, and the only mechanism either platform offers for it is their tag — a small script that gives your browser a random id, stores it in a cookie on this domain, and reports a handful of events back. What each one stores is below.

Which way round that works depends on where you are, because the law does. In the UK, the EEA and Switzerland nothing loads until you press Allow — until then the scripts are not on the page at all and no request reaches either company. Everywhere else, including the United States, they load and you are told plainly, with the off switch in the same notice: US privacy law gives you the right to stop it rather than the right to be asked first. Either way the decision sticks, it is remembered in your browser and never sent to us, and turning it off is one click on this page at any time.

CookieWhat it doesHow long
_fbpset by Meta's pixel, first-partyGives this browser a random id so Meta can tell that an ad it showed led to a sign-up here. Not read by us.Three months, and cleared when you withdraw consent.
_fbcset by Meta's pixel, first-partyRecords that you arrived from a particular Facebook or Instagram ad, so that a later sign-up can be attributed to it. Only ever written if you clicked an ad.Three months, and cleared when you withdraw consent.
_gcl_auset by Google's advertising tag, first-partyGives this browser a random id so Google can tell that an ad it showed led to a sign-up here. Not read by us.Three months, and cleared when you withdraw consent.
_gcl_awset by Google's advertising tag, first-partyRecords that you arrived from a particular Google search ad, so that a later sign-up can be attributed to it. Only ever written if you clicked an ad.Three months, and cleared when you withdraw consent.
_gcl_dcset by Google's advertising tag, first-partyThe same as the one above, for a Google display ad rather than a search ad. Only ever written if you clicked an ad.Three months, and cleared when you withdraw consent.

What we send is the fact of a page view and, if you buy, that a purchase happened and what it was worth. Not your name, not your email, not your code. What Meta and Google each do with that afterwards is governed by their policies rather than ours.

Third-party cookies

None, in the sense that matters: nothing on this site sets a cookie on someone else’s domain. The tags above are Meta and Google’s own scripts, but every cookie they write is first-party, on pylearnapp.com.

If you go through checkout, Stripe or PayPal set their own cookies on their own pages — that happens on their domain, under their policies, and is how card payments are made safely everywhere.

Turning them off

Every browser lets you block or delete cookies, and you are welcome to. Blocking the three above signs you out and keeps you signed out; the marketing pages, the pricing page and this one will still read perfectly well.

More

What we do with the data behind the session is in the Privacy Policy. Anything unclear here, write to support@pylearnapp.com and we will explain — or fix the page.