Privacy policy
Effective date: 7 October 2026
This policy explains what personal data Curious Dev Learn (learn.vladtimchenko.dev) stores, why, where, and what you can do about it. It follows the EU General Data Protection Regulation (GDPR) and the Law of Ukraine “On Personal Data Protection”.
Who is responsible
Section titled “Who is responsible”Curious Dev Learn is a free, non-commercial project run by Vlad Timchenko, a private individual, who decides how your data is used (the controller).
Contact for anything about your data: learn@vladtimchenko.dev.
Reading needs no account
Section titled “Reading needs no account”You can read every lesson without signing in. While you read, the site keeps a few settings in your browser (see “Browser storage” below) and sends nothing to us that identifies you, apart from the technical data every web request carries (see “Server logs”).
What we store when you sign in
Section titled “What we store when you sign in”Your sign-in record. You sign in with Google or GitHub. We receive and keep the provider, your email address, your name and the address of your profile photo. We never see or store a password.
Your profile. The display name, username, certificate name and avatar you set, your language, whether your public profile is on, your student id, the sign-in methods you linked, your GitHub login and id (only if you linked GitHub), when you joined and when you last used the site.
Your progress. Which lessons you opened, which labs you passed or have not passed yet, and which lab key versions you unlocked.
Your lab runs. For each run: the URLs and repository links you entered, the result of every check, and what the check read from your service’s Google-signed identity token (Cloud Run service and revision, its service account, and the Google Cloud project id and number). The project id and number link that Google Cloud project to your account, so nobody else can pass labs with it. Runs are deleted automatically 365 days after they start.
Your certificates. The name on the certificate, the course, the dates, and which lab runs passed.
Reports and moderation. Reports you send about a public profile or certificate (the reason and an optional note), and moderation decisions about your names, your avatar, or reports about your pages. The person you report never learns who reported them. Every action an admin takes is recorded in an audit log, which is deleted after 2 years.
Limits. Timestamps of your recent lab runs, certificate requests, avatar uploads and reports, used to enforce rate limits. Old entries are removed as new ones arrive.
Statistics. Daily counts (sign-ups by provider and language, lab runs, passes, certificates). These are totals and contain no personal data.
Why we use it (lawful basis)
Section titled “Why we use it (lawful basis)”- To provide the service you signed up for (contract): your account, courses, lab checks, progress and certificates.
- To keep the platform secure and free of abuse (legitimate interest): name and avatar moderation, reports, rate limits, bot protection, server logs and the admin audit log.
We do not sell your data, show ads, or build marketing profiles.
Automatic moderation
Section titled “Automatic moderation”Names you set (display name, username, certificate name) are checked by Google Cloud Natural Language, and uploaded avatars by Google Cloud Vision SafeSearch. A name or picture that is clearly harmful is refused automatically; borderline cases go to a person for review. During the launch period every certificate name is reviewed by a person. If you think a refusal is wrong, write to learn@vladtimchenko.dev and a person will look at it.
Who processes your data for us
Section titled “Who processes your data for us”Google (Google Cloud and Firebase). All of the platform runs on Google’s infrastructure:
- Firebase Hosting serves the website.
- Firebase Authentication with Identity Platform handles sign-in.
- Cloud Run runs our API and the lab checker.
- Firestore stores the data described above.
- Cloud Storage stores avatars.
- Cloud Tasks and Eventarc run background jobs (lab runs, avatar processing, account deletion).
- Cloud Logging keeps server logs.
- Cloud Vision (SafeSearch) and Cloud Natural Language check avatars and names.
- App Check with reCAPTCHA Enterprise checks that requests to our API come from a real browser on our site. It loads only when you sign in or are signed in, and Google may store a cookie for this security check.
GitHub. If you sign in with GitHub, GitHub confirms who you are. If a lab asks for a repository, the lab checker reads that public repository (commits and files) through the GitHub API. If you choose your GitHub avatar, browsers load it from GitHub.
LinkedIn, only if you click “Add to LinkedIn” on your certificate: your browser opens LinkedIn with the certificate title, date, id and link.
Where your data is
Section titled “Where your data is”Firestore, Cloud Run, Cloud Storage, Cloud Tasks and Eventarc run in the
Google Cloud region europe-west1 (Belgium, EU). Firebase Hosting delivers
pages through Google’s worldwide network. Firebase Authentication data is
stored and processed as described in Google’s Firebase terms. Where Google or
GitHub process data outside the EU, their data processing terms apply.
Server logs
Section titled “Server logs”Our servers log technical data about requests (time, address requested, response status, browser type and IP address) for security and to fix errors. Logs that relate to your account carry a hashed user id, never your email or name. Logs are deleted after 30 days.
Browser storage, no tracking cookies
Section titled “Browser storage, no tracking cookies”We use no tracking or advertising cookies and no analytics. If that ever changes, we will ask for your consent first. The site keeps these items in your browser’s storage, and they never leave your device unless noted:
- Your theme choice (
cd.theme). - Before you sign in, the lessons you opened (
cd.reading.v1). When you sign in, they are added to your progress and removed from the browser. - A hint that this browser has a session (
cd.auth.v1,cd.auth.redirect), and which lessons were already recorded today (cd.recorded.v1). - The last URLs you entered in lab forms (
cd.lab.inputs.v1), so you do not have to type them again. - Your sign-in session, kept by Firebase Authentication in IndexedDB or local storage.
What is public
Section titled “What is public”Nothing is public unless you choose it:
- Public profile, off by default. When you turn it on, anyone with the
link to
/u/your-usernamesees your display name, username, avatar, the date you joined, your valid certificates and how many labs you passed per course. Never your email, student id, project ids or lab runs. Profile pages ask search engines not to index them. - Certificates. When you issue a certificate, its page shows the name on the certificate, the course, the date, the certificate id and the labs passed, to anyone with the link. We show you exactly how your name will appear before you issue it.
- Avatars. An approved avatar is stored as a publicly readable picture so the site can show it.
How long we keep it
Section titled “How long we keep it”- Your account data: until you delete your account.
- Lab runs: 365 days after the run started.
- Pictures uploaded but not processed: 1 day.
- Server logs: 30 days.
- Admin audit log: 2 years.
- Database recovery copies (point-in-time recovery): up to 7 days.
Your rights
Section titled “Your rights”You can, at any time:
- Export your data. Settings, “Your data”, “Download my data”: a JSON file with everything we hold about you (profile, progress, lab runs, certificates, project links, reports you sent, moderation items).
- Correct your data. Change your names and avatar in settings. A certificate name is locked once a certificate is issued; write to us to correct it.
- Delete your account. Settings, “Your data”, “Delete my account”. We delete your sign-in record, profile, progress, lab runs, project links, avatar files, public profile and the reports you sent. Your certificates are revoked and the name on them is erased; their pages then say the certificate is no longer available. Audit log entries keep only an internal user id, and server logs expire after 30 days.
- Object to or restrict processing, or ask anything else about your data: write to learn@vladtimchenko.dev. We answer within one month.
- Complain to a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, the data protection authority of your country.
You must be at least 16 years old to create an account.
Changes
Section titled “Changes”When this policy changes, we update it on this page and change the effective date at the top. For important changes we will also tell signed-in users on the site.