This policy explains what personal data Code-Along (“we”, “us”), operated by Syed Abu Bakar, collects, why we collect it, and what rights you have over it. It should be read alongside our Terms of Service.
The data controller is Syed Abu Bakar, 8187 Muhammad bin Abdullah bin Al-Zubair, Al-Khalidiyah, Madinah, Saudi Arabia. You can reach us about anything in this policy at syed216645@gmail.com.
1. What we collect
Information you give us
- Account details — your name and email address, provided when you register.
- Your password — stored only as a salted bcrypt hash. We never store, log, or have access to your password in readable form. If you sign in with Google you have no password with us at all.
- Consent record — the date and time you accepted these policies at sign-up, kept as evidence that consent was given.
Signing in with Google
Signing in with Google is optional. If you choose it, we ask Google only for the openid, email and profile scopes. From those we receive and store your email address, your display name, and the stable identifier Google assigns to your account (its sub value), which we keep solely so we can recognise you on future sign-ins even if you later change your email address. We do not read, post to, or otherwise access anything else in your Google account, and we never receive your Google password.
Signing in with Google for the first time creates a Code-Along account and records your acceptance of our Terms and this Policy at that moment. Google’s own handling of the sign-in is governed by Google’s privacy policy. You can remove the link at any time by deleting your account.
Information generated by your use of the Service
- Learning progress — which notebooks you have started and completed, and when.
- Notebook content — every project currently runs entirely inside your own browser. The code you write and the output it produces stay in your browser’s own storage and are never transmitted to or stored on our servers. If we later offer projects that run on our servers, we will update this policy before doing so.
- Technical data — standard server logs, which may include your IP address, browser type, and the pages you request. These are retained for 30 days and are used only to operate and secure the Service.
What we do not collect
We do not collect payment details, government identifiers, or special-category data (such as health or biometric information). We do not currently offer paid plans, and we do not use analytics or tracking of any kind. If either changes, we will update this policy first.
2. Why we use it, and our legal basis
- To provide the Service — authenticating you and saving your progress. Legal basis: performance of a contract.
- To keep the Service secure — detecting abuse and protecting our infrastructure. Legal basis: legitimate interests.
- To meet legal obligations — including retaining the consent record described above. Legal basis: legal obligation.
- To contact you about your account — for example, email verification, password resets, and security notices. Legal basis: performance of a contract.
We do not sell or share your personal data, and we do not use it for advertising or automated decision-making that produces legal effects.
3. Cookies and browser storage
We use browser storage only for what the Service needs to function:
- Authentication cookie — when you sign in, a session token is stored in a cookie named
ml_token. It is markedhttpOnly, which means JavaScript running on the page cannot read it, andSecure, which means it is only ever sent over an encrypted connection. It is not stored in your browser’s local storage. It expires automatically, and signing out removes it. - Sign-in handshake (Google only) — if you sign in with Google, a short-lived cookie holds the security values that protect the handshake against tampering. It is discarded once sign-in completes and is not used for anything else.
- Notebook state — because projects run in your browser, your notebook work is saved by that in-browser environment into your browser’s own storage so you do not lose progress between visits. It never reaches us.
We do not use advertising, analytics, or third-party tracking cookies.
4. Who we share it with
We share personal data only with service providers who help us operate the platform, and only as needed to do so. These currently include Amazon Web Services (hosting and database), Resend (email delivery), Google (sign-in). They process data on our instructions under written agreements.
We may also disclose data where required by law, or to protect our rights, users, or the security of the Service. If we are ever involved in a merger or acquisition, we will notify you before your data becomes subject to a different privacy policy.
5. International transfers
Your data is stored on servers in Paris, France, and a managed database in Paris, France. Where data is transferred outside your country, we rely on appropriate safeguards such as Standard Contractual Clauses.
6. How long we keep it
We keep your account data for as long as your account is active. If you delete your account, we delete your personal data and learning progress from our live systems immediately, and from backups within 30 days, except where we are required to retain certain records (such as consent logs) for longer to meet legal obligations.
7. How we protect it
Passwords are hashed with bcrypt. The authentication cookie is httpOnly and Secure, so it cannot be read by scripts on the page. Access to production systems is restricted to authorised personnel, and data is transmitted over encrypted connections. No system is perfectly secure, but we work to protect your data using measures appropriate to the risk, and we will notify you and any relevant regulator of a personal data breach where the law requires it.
8. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct inaccurate data, delete your data, restrict or object to how we use it, request it in a portable format, and withdraw consent where we rely on it.
You can delete your account yourself, at any time, from your Account page. That permanently removes your profile and all of your learning progress, and it cannot be undone.
To exercise any other right, or if you would rather we handled the deletion for you, contact syed216645@gmail.com. We will respond within the period required by law — generally one month under the UK/EU GDPR. If you are in the UK, EEA, or Switzerland and are unhappy with our response, you may complain to your local data protection authority.
9. Children
The Service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact syed216645@gmail.com and we will delete it.
10. Changes to this policy
We may update this policy from time to time. If the changes are material, we will notify you before they take effect. The “last updated” date at the top of this page always reflects the current version.
11. Contact
For any question about this policy or your personal data, contact syed216645@gmail.com, or write to 8187 Muhammad bin Abdullah bin Al-Zubair, Al-Khalidiyah, Madinah, Saudi Arabia.