Lrnon

Privacy

Version 0.3 · public preview · last updated 2026-08-24

The short version

Using this site without an account collects no personal data at all. No cookies, no analytics, no trackers, no third-party scripts. Signing in (optional, for cross-device sync) adds your email address and your learning progress to our database — nothing more.

Where your progress lives

By default, your lessons, XP, streaks, badges, and flashcard schedule are stored in your browser's local storage, on your device. We can't see them. Clearing your browser data deletes them; that is entirely in your hands. "Make available offline" stores lesson copies in your browser's cache the same way.

Accounts and sign-in (optional)

Signing in — via Google, GitHub, or an emailed sign-in link — lets your progress follow you across devices. Nothing about this is required to use the site.

If you sign in, we store: your email address, your display name (if you choose to set one), and your learning progress (lessons completed, XP/coin events, streak data). Your existing local progress merges in automatically the first time you sign in; nothing is lost or overwritten.

We don't store passwords — sign-in works entirely through your chosen provider (Google/GitHub) or a one-time emailed link, so there's no password of ours to leak. Your data is protected by database-level row-level security: only you (and, for support purposes, project administrators) can read your account's data — no one else, including other signed-in learners, can see it. Progress can only be written through a single, restricted server-side function; there is no direct write path into your XP or progress records.

We never sell your data or share it with advertisers, and there are no ad networks or third-party trackers on this site. Want your data exported or deleted? Open an issue on the project repository (see Contact below) and we'll handle it directly.

Age — learning is open to everyone

There is no minimum age to learn here. Lrnon is education, and education should not be gated by age. Lessons, quizzes, XP, streaks, badges and the daily review are open to anyone, in any region, subject to whatever local law applies where you are.

The most important thing to understand is that learning anonymously involves no personal data at all. Without an account we hold nothing about you: your progress is in your own browser's storage, we cannot see it, and there is nothing to consent to because there is nothing being processed. That is the default, and for a young learner it is the whole experience — an account only adds cross-device sync.

If you are under 18 and want an account, or to volunteer

Signing in, or volunteering, means we process personal data — an email address at minimum. Where the person is a child, the law requires consent from a parent or guardian first. India's DPDP Act treats everyone under 18 as a child and requires verifiable parental consent; the GDPR sets a lower floor (13–16 depending on the country) and the US COPPA rule covers under-13s. Which one applies depends on where you live, so we apply whichever is stricter for you.

How it works, in practice:

  1. Tell us you are under 18, and give us a parent or guardian's email — not theirs to be published, only to be asked.
  2. We email them directly, explaining exactly what you would be doing and what we would hold.
  3. They reply to confirm. A reply from the guardian's own address is the consent record — not a checkbox you tick on their behalf.
  4. Only then does the account or the volunteer task go ahead.

We record the guardian's confirmation, its date and the policy version in force. That record is visible only to project administrators, never published, and deleted when the account is closed or the task ends. A guardian can withdraw consent at any time by emailing us, and we act on it immediately — no reason required and no persuasion attempted.

While consent is pending we hold only what is needed to ask for it. If it never arrives, we delete that too. For volunteers under 18 we also never publish your name or contact details, even with consent.

Your rights over your data

If you have an account you can, at any time:

Administrative records of role changes are kept for accountability and cannot be edited by anyone, including us. Deleting your account unlinks you from those records rather than rewriting them, so the history stays honest without staying personal.

Hosting

The site is served by a content delivery network, which processes IP addresses transiently to deliver pages and protect against abuse, as all web hosting does. We run no server-side logging of our own beyond what's described above.

Contact

Questions or concerns: open an issue on the project repository — everything about this project happens in the open.