BLOCK of BYTES
  • Home
  • Skill Map
  • IDE
  • Sign in
Home Skill Map IDE Sign in

// PRIVACY

Privacy Policy

This notice explains what Block of Bytes collects, why it is used, and how you can control it.

Controller and contact

Block of Bytes is operated from Poland. For privacy questions or requests, contact BlockOfBytes@gmail.com.

What we collect

  • If you choose Google sign-in: your Google account subject, verified email, and basic profile metadata returned within the requested scopes.
  • Your account record, accepted Terms version and timestamp, and current email-marketing preference and the timestamps of its latest consent and withdrawal.
  • If you sign in: your current, furthest, and completed learning progress for each Block.
  • If you send feedback: your message, the page it concerns, your account ID if signed in, and whether you allowed a reply about that feedback.
  • Cookieless web and product analytics for selected public pages and courses, tutorial starts, the highest Byte reached, and tutorial completion.
  • Limited technical request, error, and security logs generated when you use the service. Depending on the event and hosting configuration, these may include your IP address, request date and time, requested URL, HTTP method and response status, browser user agent, referrer, and diagnostic information.

We use PostHog Cloud EU to process limited technical error reports, without request contents or account identifiers, to maintain service reliability. Browser analytics opt-out does not disable this server-side monitoring.

Why we use it

  • To provide the optional account, authenticate you, and synchronize learning progress as part of the service you request.
  • To operate and monitor the service, diagnose errors, maintain security, prevent abuse, investigate feedback, and improve the service based on our legitimate interests.
  • To send our own course, product, and promotional emails only when you have given optional consent.
  • To meet legal obligations and establish or defend legal claims where applicable.

Email updates and feedback replies

  • Marketing is off by default. You can turn it on or off immediately in account settings.

Product and web analytics

  • PostHog Cloud EU processes selected pageviews and product events for us, with data hosted in the EU and retained for up to one year.
  • For selected public pages, we send the public page or course path without its query string or fragment. We also send the referring website's hostname when available, not its full page address, and selected short campaign labels from tagged links (utm_source, utm_medium, utm_campaign, utm_content).
  • We collect limited browser, operating system, device type, and screen-size information to understand how the public pages are used. We do not track account, authentication, or settings pageviews.
  • We configure PostHog in cookieless mode, so it does not store analytics cookies or identifiers in your browser storage.
  • PostHog processes limited technical connection data, including your IP address and user agent, to generate a rotating analytics identifier. We do not link this identifier to your account.
  • We do not send PostHog your email, Google subject, Python code, terminal input, or terminal output.
  • We do not use PostHog identify, person profiles, session replay, surveys, automatic pageviews, or automatic interaction capture.
  • Campaign labels are not saved in browser storage. If you opt out, neither web nor product analytics is loaded for that browser on subsequent page loads.

In-browser Python runtime

The IDE runs Python locally in your browser using Pyodide. Required runtime and package files are delivered by jsDelivr, which may receive standard connection data such as your IP address and the requested file URLs. Your Python code, terminal input and output, and project files are not sent to jsDelivr by the runtime. See jsDelivr's Privacy Policy.

Browser storage

  • The tutorial uses namespaced local storage to remember anonymous or account-specific learning progress; the site also remembers your theme.
  • Signed-in progress is stored in our database. Python code and project files remain in your browser and are not synced to your account.
  • Django uses essential host-only cookies for CSRF protection and signed-in sessions.
  • If you opt out of web and product analytics, we store the bob_no_metrics preference cookie.

Providers and international transfers

We use service providers to operate Block of Bytes, including authentication, hosting, content delivery, product analytics, and email services. Some providers may process personal data outside the EEA. Where required, international transfers are protected using safeguards recognized under applicable data-protection law.

Retention

  • Account and progress data is kept while the account is active and then only as long as needed for deletion, security, or legal obligations.
  • Feedback and its account link are kept only while needed to investigate and improve the relevant page. Deleting an account removes its link from earlier feedback.
  • Marketing consent and withdrawal records may be retained as evidence of your choice for the period needed to handle legal claims.
  • PostHog pageviews and product events are retained for up to one year.

Your choices and rights

  • Email BlockOfBytes@gmail.com to request access, correction, export, deletion, restriction, or objection, or to withdraw consent.
  • You may complain to the Polish data-protection authority (UODO) or another competent supervisory authority.

What we do not do

We do not sell your data or share your email address for another company’s marketing.

Changes

We will update this page when our data practices materially change. The separate Terms of Service govern use of the service.