~//privacy

Privacy Policy

Last updated: September 21, 2026

hackweb.dev is a free, community-driven learning platform. This policy explains what personal data we collect, why we collect it, and the choices you have. It applies tohackweb.dev and the API at api.hackweb.dev.

1. Information we collect

We keep data collection to the minimum needed to run the site:

  • Account data. When you sign in with GitHub, we receive your GitHub user ID, username, display name, avatar URL, and the email address GitHub makes available through the OAuth user:email scope. We never see your GitHub password.
  • Content you create. Lessons, corrections, suggestions, profile details and any other material you submit, along with the time you submitted it.
  • Progress and preferences. Tutorial progress, quiz results, streaks and theme/language preferences. Most of this is stored in your browser's localStorageand, when you are signed in, synced to your account.
  • Technical data. Your IP address is processed transiently for rate limiting, abuse prevention and security. We do not use it to build advertising profiles.

2. Cookies and local storage

We use a single essential cookie, __Secure-better-auth.session_token, to keep you signed in. It is Secure, HttpOnly, and SameSite=Lax, scoped to .hackweb.dev. We do not set advertising or third-party tracking cookies. Browser localStorage is used for functional data such as your theme, language and locally-saved progress.

3. How we use your information

  • To authenticate you and maintain your session.
  • To save and display your progress, contributions and profile.
  • To operate, secure and debug the service, including rate limiting and abuse prevention.
  • To respond to support requests and send essential service notices.

We do not sell your personal data, and we do not use it for targeted advertising.

4. Legal bases (EEA/UK)

Where the GDPR applies, we rely on:

  • Contract — to provide the account and features you signed up for.
  • Legitimate interests — to keep the service secure, prevent abuse and improve it.
  • Consent — where we ask for it, for example for optional communications.

5. Service providers

We share data only with providers that help us run the service:

  • Cloudflare — hosting, CDN, and the D1 database that stores your account and content.
  • GitHub — OAuth sign-in.

If paid plans launch, payments will be processed by a third-party merchant of record (for example Paddle). We would not receive or store your full card details. This policy will be updated before any such feature goes live.

6. Data retention

We retain account and contribution data for as long as your account exists or as needed to operate the service. You can ask us to delete your account and associated personal data at any time; we will do so unless we are required to keep certain records by law. Anonymized or aggregated data may be kept indefinitely.

7. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. To exercise any of these, contact us using the details below. You also have the right to complain to your local data protection authority.

8. Security

We use HTTPS everywhere, secure and HTTP-only session cookies, and access controls on our systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. Children

The service is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the "Last updated" date above, and significant changes will be announced on the site.

11. Contact

For any privacy question or request, open an issue atgithub.com/Mo-Ibra/HackWeb.