Legal
Privacy notice
Last updated 2026-09-23.
Who this is
PNL Learn is operated by Proto Node Labs LLC. This page describes what we collect when you use the site, why, and how to have it removed.
What we collect
- Account details: username, email address and a one-way argon2 hash of your password (never the password itself).
- Course progress: enrollments, completed lessons and exercises, XP, level, streak, hints used, revealed solutions and review history.
- Anything you write in the code editor and playground, saved as drafts and snippets so you can pick up where you left off.
- Preferences: theme, editor font size, reduced motion, sound, timezone and daily goal.
- A session cookie and a matching database record (the browser you used, and when the session was created and last active), so you stay signed in.
- If you subscribe, your plan and subscription status, and the Stripe identifiers needed to manage it. We never see your full card number.
Cookies
We set one cookie, pnl_learn_session, to keep you signed in. It is HTTP-only (not readable by page scripts), marked secure in production, and lasts 30 days, renewed while you are active. We do not use advertising or tracking cookies.
We email you for account purposes only: password reset links and, if you opt in, course reminders. We use Resend to deliver these emails and do not use your email for marketing you have not asked for.
Certificates
A finished program issues a certificate as a signed digital credential (Open Badges 3.0). It identifies you by a salted, one-way hash of your email address rather than the email itself, so the credential can be verified without exposing your email to whoever holds it.
GitHub
If you use “Publish to GitHub,” you authorize that one push through GitHub's own sign-in. The access token it gives us is used once and is never stored, logged or sent to your browser.
What we do not do
We do not sell your data. We do not share it with third parties except the services that run the product on our behalf (our database host, Resend for email, Stripe for billing, and GitHub only when you ask us to publish to it), and only the data each of those needs to do its job.
Deleting your data
You can delete your account at any time from Settings. This permanently removes your user record and everything tied to it, including progress, sessions, achievements, snippets and subscription record, and cannot be undone. Certificates already issued for a completed program remain independently verifiable, since revoking one would falsify a credential a third party (an employer, for instance) may already be relying on; the certificate identifies you only by the salted email hash described above, never your email in clear text.
Changes
We will update the date at the top of this page whenever this notice changes.
Contact
Questions, or a request about your data: maverick@protonodelabs.com.