Privacy Policy
Last updated: July 17, 2026
1. Overview
PyCodeIt ("we," "us," or "our") is a free Python and SQL technical interview preparation platform created by Ameer Abdullah, a Data Science and AI/ML graduate. We are committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have regarding your data.
This policy applies to all visitors and registered users of www.pycodeit.com and any related subdomains. By using our services, you acknowledge that you have read and understood this policy.
2. Information We Collect
2.1 Account Data
If you create an account, we collect and store the following information via our authentication provider, Supabase:
- Email address: Required for account creation, login, and account recovery.
- Username: A display name you choose, shown on leaderboards and in the community forum.
- Progress data: Challenge scores, XP points, streak counts, problems solved, and exercise history, used to power your personalized dashboard and leaderboard rankings.
- Account preferences: Dark/light mode settings and other UI preferences stored in your profile.
2.2 Usage and Analytics Data
We use Google Analytics 4 (GA4) to collect anonymized usage data, including pages visited, session duration, device type, browser, and geographic region. This data is aggregated and does not identify you personally. We use this data solely to understand how users interact with the platform and to improve the product.
2.3 API Keys (Local Storage Only)
If you enter a Groq API key to unlock AI-powered problem generation, that key is stored exclusively in your browser's local storage on your device. We do not transmit, store, log, or process your API key on our servers at any point. You can remove the key at any time by clearing your browser's local storage or using the settings panel within the platform.
2.4 Cookie Consent Preference
We store your cookie consent decision (accepted or declined) in your browser's local storage under the key pycodeit_cookie_consent. This is a functional preference, not a tracking cookie. It allows us to respect your advertising cookie preference across visits.
2.5 Community Content
If you post in our community forum, the content of your posts (text, code snippets, replies) is stored in our Supabase database and displayed publicly to other users. Do not include personal information in posts that you would not want visible to the public.
3. How We Use Your Information
- To create and manage your account and authenticate your login sessions.
- To track and display your learning progress, XP, streaks, and rankings.
- To operate the community forum and attribute posts to the correct user.
- To send transactional emails (e.g., password reset) via Supabase Auth. We do not send marketing emails unless you explicitly opt in.
- To understand aggregate platform usage via Google Analytics and improve our features.
- To display advertisements via Google AdSense (subject to your cookie consent).
- To comply with our legal obligations and enforce our Terms of Service.
4. Cookies and Advertising
4.1 Types of Cookies We Use
- Essential cookies: Used by Supabase authentication for session management. These are strictly necessary to provide the login service and cannot be disabled without breaking account functionality.
- Analytics cookies: Google Analytics 4 uses cookies (e.g., _ga, _gid) to distinguish users and measure session data. These are only set if you accept analytics cookies via our consent banner.
- Advertising cookies: Google AdSense uses cookies to serve personalized ads based on your interests and browsing history. These are only loaded after you explicitly accept advertising cookies via our consent banner.
4.2 Google AdSense
This website uses Google AdSense to display advertisements. Google AdSense is an advertising service operated by Google LLC. When advertising cookies are enabled, Google uses cookies to serve ads based on your prior visits to this website or other websites on the internet. Google's use of advertising cookies enables it and its partners to serve ads to users based on their interests.
You may opt out of personalized advertising at any time by visiting Google Ads Settings or by using the NAI opt-out tool. You can also manage or disable cookies through your browser settings. Note that disabling advertising cookies will not remove ads entirely; it means ads shown may be less relevant to your interests.
4.3 Consent Management
On your first visit to PyCodeIt, a cookie consent banner is displayed at the bottom of the screen. You can choose to "Accept All" (enables analytics and advertising cookies) or "Decline" (only essential session cookies are set). You can change your preference at any time by clearing your browser's local storage.
5. Third-Party Services
We use the following third-party services that may process your data:
- Supabase (supabase.com) - Authentication, database storage, and real-time subscriptions. Data is stored on servers in the United States.Privacy Policy
- Google Analytics 4 - Web analytics. Data is anonymized and aggregated.Privacy Policy
- Google AdSense - Advertising. Subject to your cookie consent.Privacy Policy
- Groq (groq.com) - AI inference API. Your API key and prompts are sent directly from your browser to Groq using your own credentials. We are not an intermediary and do not log these requests.Privacy Policy
- Vercel (vercel.com) - Web hosting and CDN. Server access logs may be retained for up to 30 days.Privacy Policy
6. Data Retention
We retain your account data (email, username, progress) for as long as your account is active or until you request deletion. Challenge submission history is retained to power streak and leaderboard features. Analytics data in Google Analytics is retained for 14 months by default.
If you delete your account, all associated personal data (email, username, progress records) will be permanently deleted from our Supabase database within 30 days. Community posts may be anonymized rather than deleted to preserve discussion thread integrity.
7. Your Rights (GDPR - EEA/UK Users)
If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): You may request deletion of your personal data. We will comply within 30 days except where retention is required by law.
- Right to Restrict Processing: You may request that we limit how we use your data in certain circumstances.
- Right to Data Portability: You may request your data in a machine-readable format for transfer to another service.
- Right to Object: You may object to processing of your personal data for direct marketing or on grounds relating to your particular situation.
- Right to Withdraw Consent: Where processing is based on your consent (e.g., advertising cookies), you may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us via our Contact page. We will respond within 30 days. We do not currently have a designated Data Protection Officer (DPO) as we are a small indie platform, but all privacy requests are handled directly by the platform creator.
8. California Privacy Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you over the past 12 months, including the categories of sources, business purposes, and third parties with whom data was shared.
- Right to Delete: You may request deletion of personal information we have collected about you, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell your personal information to third parties. However, Google AdSense's interest-based advertising may constitute a "sale" under the CCPA's broad definition. You can opt out via the cookie consent banner or Google Ads Settings.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To submit a CCPA request, please contact us via our Contact page with the subject line "CCPA Request."
9. Data Security
We take reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- All data transmission between your browser and our servers uses HTTPS/TLS encryption.
- Supabase enforces Row Level Security (RLS) policies ensuring users can only access their own data records.
- API keys are never transmitted to or stored on our servers.
- Access to our Supabase database is restricted to authorized administrators only.
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
10. Children's Privacy (COPPA)
PyCodeIt is not directed at children under the age of 13 in the United States (or under 16 in the EEA). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately via our Contact page and we will delete the data within 7 business days.
11. International Data Transfers
Our services are operated primarily from servers located in the United States (Supabase) and distributed via Vercel's global CDN. If you are accessing PyCodeIt from the EEA, UK, or other regions with data protection laws, your data may be transferred to and processed in countries with different data protection standards.
Where required by applicable law, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards (as provided by our service providers, including Supabase and Google) to ensure adequate protection for international transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make significant changes, we will update the "Last updated" date at the top of this page. Continued use of the service after changes are posted constitutes your acceptance of the updated policy. We encourage you to review this page periodically.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us:
- Email: richiethedigitalrich10@gmail.com
- Contact Form: pycodeit.com/contact
- Platform Creator: Ameer Abdullah, Data Science & AI/ML Graduate
We aim to respond to all privacy inquiries within 30 days.