Privacy
An account stores your email and what you have learned. Your name and XP appear on the public leaderboard; nothing else about you does. The free pages carry ads, which set cookies of their own. Deleting your account deletes all of it, immediately.
Last updated 10 August 2026
What is stored
Every lesson, article and challenge is readable without an account, and we store nothing about you while you read one — the list below starts existing when you create an account. The one qualification is advertising: an ad on a free page can set a cookie of its own, which is covered in its own section further down and is asked about first in the EU and the UK.
Your account
- Your email address, so you can sign back in and so we can send the confirmation and password-reset emails.
- Your password, hashed, by Supabase Auth. It is never stored in a readable form and we cannot see it.
- Your name and profile picture, if you sign in with Google or GitHub — taken from that account so your profile is not blank. You can change the name afterwards.
- A handle, generated when you join, and the date you joined.
What you have learned
- Which lessons you have completed, and when.
- Your best score on each lesson quiz.
- Every XP award, with what earned it and when — this is the record the leaderboard and your dashboard are both counted from.
- Your current and longest streak, and the last day you were active.
- Which badges you have earned, and any certificates issued to you.
- For each challenge you submit: whether it passed and how many tests it passed. The code you wrote is not stored or sent anywhere — it is graded in your own browser and only the result is reported.
Your resume
If you use the resume maker, everything you type into it is saved to your account so it is there on your next visit and from another device. It is readable only by you. Before you sign in it is kept in your browser only.
Technical
- A session cookie once you sign in, which is what keeps you signed in. It is not used to track you.
- Server logs kept by our host, including IP address and browser version, for a short period. These are how outages get diagnosed.
- Anonymous page-view and page-speed measurements, so we know which lessons people read and whether the site is fast for real visitors. These are aggregated and are not tied to your account.
- Google Analytics, if enabled on this deployment. This sets cookies of its own, and it is shared with aniui.dev so a visit that starts there and continues here is counted once rather than twice.
- Advertising cookies, on the pages that carry ads. See the section below, which is the part worth reading properly.
Advertising
The courses, challenges, job board and resume maker are free, and advertising is part of what pays for them. Where enabled on this deployment, ads are served by Google AdSense on the free pages. They do not appear while you are sitting an exam, and they do not appear on your dashboard, your profile or your certificates.
This has consequences you should know about, because they involve companies other than us:
- Google, as a third-party vendor, uses cookies to serve ads on this site. Its use of advertising cookies lets it and its partners serve ads to you based on your visits here and to other sites.
- Third parties may place and read cookies in your browser, or use web beacons and your IP address to collect information, as a result of ads being served here. That is done by them, under their own policies, and not by us.
- We never hand over your email address, your resume, your quiz answers or anything else from your account to an advertiser. Nothing about you is sold. What the ad system sees is a browser loading a page, the same as it would from any site.
You can turn personalised advertising off for your Google account at My Ad Center, and opt out of personalisation by many other vendors at aboutads.info or Your Online Choices. You will still see ads; they simply stop being tailored to you. Google’s own account of what it collects is at How Google uses information from sites that use its services.
If you are in the EU, the UK or Switzerland, you are asked before any advertising or analytics cookie is set, and nothing beyond the sign-in cookie is set until you say yes. You can change that answer at any time from the link in the footer of every page.
What is public
The leaderboard is a public page, and being on it is the point of it, so these are visible to anyone: your display name, your handle, your XP totals, your streak length and the number of lessons you have completed.
A certificate is public to anyone holding its link, and shows your name, the course, the date and your average quiz score. Links are not listed anywhere and cannot be guessed from one another — but a link you share is a link you have made public, so treat it that way.
Your email address is never shown publicly, and neither is your resume, your individual quiz answers or your challenge results.
Who else processes it
- Supabase — the database and the sign-in system. Every item above other than the analytics lives there.
- Vercel — hosting, server logs, and the anonymous page-view and page-speed measurements.
- Google — advertising through AdSense and measurement through Google Analytics, both where enabled, and sign-in if you choose Google.
- GitHub — sign-in only, if you choose GitHub.
Nothing about you is sold. No advertiser is given anything from your account, and the advertising above is the only third party here that is not doing a job the site cannot function without.
Deleting your account
On your profile page there is a delete button. It is immediate and it is not a soft delete: your progress, XP history, quiz scores, badges, certificates and resume are removed with the account, in the same operation. We keep no copy, so we cannot restore it afterwards and cannot undo it if you change your mind.
Certificate links you have already shared stop working. Backups taken before the deletion age out on their own within 30 days.
Changing your mind about the rest
You can edit your display name and handle on your profile at any time. To ask for a copy of what is stored about you, or to correct something you cannot change yourself, email hi@anishl.dev.
Age
An account requires you to be 13 or older. If you are under 18, you need a parent or guardian’s permission before buying anything.
Changes
If what is collected changes, this page changes with it and the date at the top moves. Anish L operates this site; the terms of use cover the rest of the relationship.