Learner accounts
An account stores your name, email address, optional Google profile image, role, sign-in method, and secure session records. Password accounts store only a salted password hash, never the original password. Google sign-in stores Google's stable account identifier but does not store Google access or refresh tokens. A random session token is placed in an HTTP-only, same-site cookie so the server can recognize your signed-in requests.
Learning data
Signed-in lesson completions, project milestone status, and private project notes are stored in the SovranCode database. Guest lesson progress remains in local storage on that browser. Code entered into HTML playgrounds stays inside a sandboxed browser preview and is not submitted to SovranCode.
Optional Google Analytics
Google Analytics measurement ID G-T432QDQJHJ loads only after you choose Allow analytics. It helps measure page usage and navigation patterns; IP anonymization is requested. Declining does not limit courses, accounts, progress, or projects. Your choice is stored locally and can be reset by clearing site data.
Security
We use salted password hashing, Google OpenID Connect validation, opaque database sessions, same-site cookies, authorization on every private mutation, rate limits on repeated sign-in failures, validation, and separation between public content and account data. No online service can guarantee absolute security, so important incidents will be investigated and communicated responsibly.
Your choices
You can read every free course without an account, decline analytics, clear guest progress through browser settings, and sign out at any time. Account export and deletion are not self-service yet; contact us to request access, correction, or deletion.
Contact
Questions or account-data requests can be sent through the contact page.