At a glance
Public learning, account-protected progress
This Privacy Policy explains how Hello Python (“Hello Python,” “we,” “us,” or “our”) handles information when you use hellopython.dev. Public lessons, problem statements, catalogs, and references can be read without an account. Saving code, attempts, progress, Activity, and Mock Rounds requires Google sign-in.
Account-scoped cloud sync
Signed-in learning records use an offline browser cache and synchronize to your Supabase-backed Hello Python account.
No ad tracking
We do not use third-party advertising or analytics, and we do not sell learner data.
Information We Handle
Information stored on your device
After sign-in, Hello Python keeps an account-scoped offline cache of editor drafts, submission events, structured test results, Wizard state, assistance history, Mock Round sessions, and sync status in IndexedDB. Manual Roadmap completion is stored under the same account scope. Theme, layout, and workspace-size preferences may remain device-local in localStorage without an account.
Information processed when you visit
Like most internet services, our hosting and security provider may process request metadata such as your IP address, browser and device information, requested URL, timestamps, referring page, and security signals needed to deliver and protect the site.
Google sign-in and account data
When you choose “Continue with Google,” Google authenticates you and Supabase manages the authentication session. We receive a Supabase account identifier and may receive the name, email address, and profile image associated with the Google account. We use these fields to create, display, secure, and support your Hello Python account.
Once signed in, Hello Python synchronizes account-owned learning state: drafts, submission-level code, completion and assistance attribution, attempt events, Skill Lab drafts, and Mock Round setup and sessions. We do not synchronize OAuth access or refresh tokens inside learning records, hidden tests, raw provider responses, or editor keystroke replay.
Support communications
If you email us, we receive the address and contents you provide so we can respond and keep an appropriate support or legal record.
Offline Cache and Browser Preferences
The signed-in offline cache is separated by account identifier. It lets a supported browser preserve queued changes during a temporary network failure and retry them when connectivity returns. Clearing browser data removes that device's cache and preferences, but already synchronized account records remain available from the service.
Do not rely on an unsynchronized browser draft as your only copy. Private browsing, storage denial, a closed tab, or a lost device can remove changes that have not reached the cloud. Signed-out learning mutations are not saved; pre-launch anonymous learning keys are removed rather than merged into an account.
Service Providers and External Sites
- Cloudflare delivers and protects the site and can process network and security metadata. See the Cloudflare Privacy Policy.
- Supabase provides Google-connected authentication and Postgres storage for account-scoped profiles, learning events, mutable learning state, and sync cursors. See the Supabase Privacy Policy.
- Google provides identity authentication. Your use of Google is also governed by the Google Privacy Policy.
Learning pages link to Python documentation and third-party coding resources. When you follow an external link, that site handles information under its own policy. Hello Python does not control those sites.
How We Use Information
We use information only as reasonably necessary to:
- deliver the site and browser coding workspaces;
- authenticate and secure the account required for saved learning activity;
- preserve, synchronize, restore, provide access to, and delete your account-owned learning state;
- protect the service, prevent abuse, and diagnose failures;
- respond to support, privacy, and legal requests; and
- comply with applicable law and enforce the Terms of Service.
Where data-protection law requires a legal basis, the basis depends on the context: performing the service you request, our legitimate interests in operating and securing it, your consent where required, or compliance with a legal obligation. We do not use solely automated decision-making that produces legal or similarly significant effects.
Retention, Security, and International Processing
Account profiles and synchronized learning records are retained while the account is active. Using “Delete my account” removes the Supabase Auth user and cascades deletion to the profile, learning events, learning states, and sync-device rows. Provider backups and security logs may age out on their normal protected schedules, and we may retain limited records when required for fraud prevention, dispute resolution, or law.
For account deletion abuse review, we retain a private audit containing only an opaque request ID, operation type, outcome, and timestamps—never email, code, learning payloads, tokens, or provider responses. Terminal audit records are retained for no more than 90 days unless a longer period is reasonably required for an active security or legal investigation. Support communications are retained only as long as reasonably necessary for the request and related obligations.
We use reasonable technical and organizational safeguards appropriate to the service, including scoped credentials, transport encryption, access controls, and least-privilege provider configuration. No storage or transmission method is completely secure, so we cannot promise absolute security.
Hello Python and its providers may process information in the United States and other countries. Where applicable law requires safeguards for an international transfer, we will rely on an approved transfer mechanism or another lawful basis.
Your Rights and Choices
Depending on where you live and whether the relevant law applies, you may have rights to request access, correction, deletion, restriction, portability, or an explanation of our processing; to object to certain processing; to withdraw consent; and to lodge a complaint with a data-protection authority. These rights are not absolute and may be subject to identity verification and lawful exceptions.
The Profile page lets you update a display name and permanently delete the account. You can also clear a device's local cache in browser settings. For account access, portability, or provider-held data requests, email support@hellopython.dev. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.
Do Not Track and Global Privacy Control
Because Hello Python does not sell personal information, run behavioral advertising, or use third-party analytics, browser Do Not Track and Global Privacy Control signals do not change the current site behavior. If future processing creates a legal obligation to honor an opt-out signal, we will update the service and this policy before that processing begins.
Children
Hello Python is a general-audience interview-preparation service and is not directed to children under 13. Children under 13 may not create an account or provide personal information through account or support features. If you believe a child provided personal information, a parent or guardian should contact us so we can investigate and delete it where required.
Changes to This Policy
We may update this policy as the product or law changes. We will change the date above and provide additional notice before a material change when required. Analytics, advertising, billing, or AI processing would require a specific review rather than a silent expansion of this policy.
Contact
Hello Python operates hellopython.dev. For privacy questions, account requests, or product support, email support@hellopython.dev.
Do not include passwords, OAuth tokens, private keys, or sensitive code in an email request.