Privacy Policy
Last updated
This policy covers PyLearn at pylearnapp.com — the marketing pages, the courses, the account behind them and the email we send you.
Who we are
PyLearn is run by one person, as a sole proprietor in the United States. We are the controller of the personal data described here, and the address below reaches us directly rather than a support desk.
support@pylearnapp.comWhat we collect
Only what an account needs to work. In full:
- Your account. Your name, your email address, a bcrypt hash of your password (never the password), the time zone your browser reports, and the seed that draws your avatar. Nothing here is optional — an account cannot exist without it.
- Your work. Which lessons you have started and finished, how many attempts each took, whether you revealed a hint or a solution, your quiz answers and scores, your project submissions, and the code currently in your editor for each lesson — saved so that closing the tab does not lose it.
- Your progress. XP, level, current and longest streak, badges, and a per-day count of lessons finished and XP earned, which is what draws the activity calendar.
- Certificates. When you finish a course we store the name to print on the certificate, the course title, the date and a serial number.
- Email preferences. Which notifications you want, and a record of what we sent and when, so that a reminder is not sent twice.
- Support messages. What you write in the support form or send to support@pylearnapp.com, and the address it came from.
- Billing records, if you subscribe. The customer or payer identifier your payment provider assigns you, and one row per payment: amount, currency, status, the provider’s receipt link and the date. Card numbers, bank details and billing addresses stay with Stripe or PayPal and are never sent to us.
- Server logs. Our host records requests in the ordinary way — IP address, time, path, user agent — as every web server does. We read them to debug and to spot abuse.
What we don't collect
There is no analytics package on this site. No Google Analytics, no session recorder, no A/B testing service, no third-party cookie, no fingerprinting. The fonts are served from our own domain rather than Google’s, and the Python runtime is served from our own domain rather than a CDN, so loading a lesson tells nobody but us that you did.
The one exception is advertising. PyLearn runs ads on Facebook, Instagram and Google, and if you allow it we load Meta’s pixel and Google’s conversion tag so that we can tell an ad led to a sign-up. Both are off until you say otherwise: the scripts are not on the page and no request reaches either company while the banner is unanswered or declined. Google’s tag is the advertising one, not Google Analytics — it reports that a conversion happened, and there is no analytics property behind it. What they store, and how to change your mind, is in the Cookie Policy.
We do not buy data about you, we do not enrich your email address against a data broker, and we do not sell, rent or share your personal information — including for cross-context behavioural advertising, the definition that matters under California law. There is no advertising on PyLearn to sell it for.
Why we're allowed to
If you are in the UK or the European Economic Area, the GDPR asks us to name a legal basis for each purpose:
- Performance of a contract — your account, your progress, your certificates, your subscription and the email that goes with them. You asked us to teach you Python; this is what that takes.
- Legitimate interests — keeping the service secure, preventing abuse of the free tier, debugging from server logs, and answering support. Our interest is running a working service; the data involved is minimal and none of it is used to profile you.
- Legal obligation — keeping payment records for tax and accounting.
- Consent — the optional notification emails, which you can turn off in your profile or by using the unsubscribe link in any of them.
Who else sees it
A short list, and it is the whole list. Each of these is a processor acting on our instructions, under a contract that limits them to what we ask for:
- Our hosting provider, which runs the servers and the database this site lives on, and relays our outbound email.
- Stripe and PayPal, if you subscribe. You give them your payment details directly; they tell us that a payment succeeded and who it was for. Each is a controller in its own right for the payment itself and has its own privacy policy.
- A third-party AI provider, when you use the AI tutor. Requests go to a routing service, which forwards them to whichever language-model provider is answering — see below.
Beyond that, we disclose personal data only if the law requires it, and we would tell you unless we were forbidden to. If the service were ever sold, you would be told before your data moved.
The AI tutor
The chat panel in a lesson is the one place where anything you write leaves your browser for a third party, and only when you send a message. What travels with the message is the course and lesson title, the lesson instructions, whatever is in your editor at that moment, and the earlier turns of that conversation.
It goes to a third-party routing service, which passes it to whichever language-model provider is answering at that moment. Your name, your email and your account identifier are not sent — the request carries no way of telling that provider who you are. We do not store the conversation: it lives in the page and is gone when you close the lesson. We will tell you the current provider if you ask.
If you would rather nothing left your machine at all, do not use the panel. Every lesson, every exercise and every test works without it.
How long we keep it
Your account and everything attached to it stays until you ask us to delete it. We keep it while the account exists because that is the product: a streak, a certificate and a half-finished lesson are only useful if they are still there when you come back.
- Sign-in sessions expire on their own, and signing out ends one immediately.
- Email-verification and password-reset tokens are single use and expire within hours.
- Payment records are kept for as long as tax law requires — generally seven years — even after an account is deleted. This is the one category we cannot erase on request, and the law is the reason.
- Server logs are rotated by our host and are not kept indefinitely.
Your rights
Wherever you are, you can ask us to show you what we hold, correct it, delete it, or send it to you in a portable form. Under the GDPR and UK GDPR you can also object to or restrict processing, and withdraw consent for the optional emails at any time. Under the California Consumer Privacy Act you have the rights to know, delete, correct, and to opt out of sale or sharing — there is nothing to opt out of, because we do neither — and we will not treat you differently for exercising any of them.
Some of this you can do yourself: your name, email and avatar are editable in your profile, and the notification settings are beside them. For anything else, write to support@pylearnapp.com from the address on your account and we will act within 30 days. Deletion needs no request: the danger zone on your profile does it at once, on the website and in the iOS app. It removes your profile, your progress, your submissions, your certificates and your notification history, and signs out every device; the payment records described above survive it, with nothing left linking them to you.
If you think we have handled your data badly, please tell us first — but you are entitled to complain to your data protection authority regardless. In the EEA that is your national supervisory authority, in the UK the Information Commissioner’s Office, and in the United States your state Attorney General’s office.
Children
PyLearn is not intended for children under 13, and we do not knowingly collect anything from them. If you are between 13 and 16 and live in the EEA, please have a parent or guardian agree on your behalf. If you believe a child has given us personal data, write to support@pylearnapp.com and we will delete the account.
International transfers
We operate from the United States and our servers are there, so using PyLearn from outside the US means your data is transferred to and stored in the US. Where we rely on processors that move data across borders, those transfers are covered by the European Commission’s Standard Contractual Clauses or an equivalent safeguard.
Security
Passwords are stored as bcrypt hashes and are never recoverable, not even by us — which is why a forgotten one is reset rather than sent. Traffic is encrypted with TLS. Sessions are held in signed, HTTP-only cookies. Payment credentials never reach our servers at all. The site sets a strict content security policy and a set of hardening headers, and the Python runtime is sandboxed inside a Web Worker.
No system is perfect. If a breach affects you we will tell you and the relevant authority without undue delay, and within 72 hours where the GDPR requires it. If you find a vulnerability, please write to support@pylearnapp.com rather than publishing it, and we will work with you.
Changes
When this policy changes the date at the top changes with it. If a change materially affects how we handle your data, we will email the address on your account before it takes effect rather than relying on you to re-read the page.