Privacy Policy
Last updated: September 20, 2026
This policy explains what personal data Newbie on Rails collects, why we collect it, who can see it, and what control you have. We wrote it to be read, not skimmed past.
1. What we collect
Account
- Email address, username and a password. The password is stored only as a one-way hash, never in readable form.
- Optionally: display name, country and city.
- Two-factor authentication secret and recovery codes, so you can sign in and recover access.
- Your GitHub account identifier, if you sign in with GitHub.
Learning activity
- Courses you enrol in, lessons completed, quiz attempts, XP, badges, streaks, time spent online and when you were last active.
- Code you submit to challenges, and whether you revealed a solution.
- Bookmarks and private notes you write on lessons.
Things you write
- Comments you post on lessons, which other learners can read.
- If you contact us as a company: company, contact name, email, website and message.
Technical data
- A session cookie, and your IP address, which our servers and rate limiting process to keep the service available and secure.
2. Why we use it, and on what basis
- To run your account, track your progress and issue certificates. Basis: performing the service you asked for.
- To protect the service from abuse, for example rate limits and two-factor authentication. Basis: our legitimate interest in security.
- To share your progress with the partner that referred you, described in section 4. Basis: your consent. We ask the first time you arrive from a partner, you can say no and still use your account, and you can change your answer any time in Settings.
- To let hiring partners contact you about work. Basis: your consent, given by ticking a box in Settings, off by default.
3. What is public
Your profile page (newbieonrails.com/u/your-username) and the certificates you earn are public by default. They show your display name (or username), when you joined, your country if you set one, your streak, badges, completed courses and XP. Your city is never shown. Turn off "public profile" in Settings and both stop being visible to anyone but you.
Comments you post on lessons are visible to other signed-in learners. Your email address is never shown publicly.
4. Partners
Partners that send learners to us
Some partners, for example HireRubyDevs, can send their users to Newbie on Rails already signed in. When that happens we receive from the partner: their internal user id for you, your email address and, optionally, your name, country and city. We use the name, country and city only to fill in your profile when the account is first created. After that your profile is yours, and the partner cannot change it.
We need the partner's id for you, and your email, to create your account, so we receive those before you are asked anything. If an account with the same email already exists here, we do not link it automatically: you sign in once, and that is what connects your account to the partner.
Then we ask whether you agree to share your progress with that partner. It is a box you tick yourself, and it starts empty. If you agree, that partner, and only that partner, can retrieve information about you, including what you did here before you agreed, and only for accounts that came from it. The page where we ask says what that partner uses it for, when it has told us:
- Your email, username, name, GitHub identifier if you linked one, join date and last activity.
- Your XP, level, lessons and courses completed and current streak.
- Your certificates (code, course, level and date) and your activity events, such as lessons completed.
Partners cannot see learners who did not come through them, or who did not agree. We do not send partners your country, city, notes, comments or code.
If you do not agree, nothing about you is shared and your account works the same. We keep the partner's id for you only so that signing in from their site takes you to your account instead of creating a second one. You can agree or withdraw at any time in Settings. After you withdraw, the partner stops seeing you, but we cannot recall what it already received.
Hiring partners and your consent
In Settings you can choose to be contactable by hiring partners. It is off by default. If you turn it on, we may give partners with a hiring plan your name, username, email, the courses you completed with their level and date, and your profile link, so they can contact you about work. Turn it off at any time. We stop including you from then on, but we cannot recall what a partner already received.
Sponsors
Partners and sponsors appear on the site as logos and links. That does not involve any of your data.
5. Service providers
We use a hosting provider for our servers and Cloudflare for DNS, traffic protection, and off-site backups. GitHub processes your sign-in if you choose GitHub. To load some code editor and diagram tools and fonts, your browser fetches files from public CDNs (jsDelivr, jspm.io and Bunny Fonts), which can see your IP address when it does. We do not sell your data and do not use it for advertising.
Our servers are located in the United States, so your data is stored and processed there, outside Brazil. The other providers above may also process data in other countries. By using the service from Brazil, your data is transferred internationally under the same protections described in this policy.
6. Cookies and browser storage
We use one session cookie, which is strictly necessary: it keeps you signed in and remembers your language. We store a few interface preferences, such as collapsed sections, in your browser, and a service worker caches pages for faster loading. We do not use advertising or tracking cookies.
7. How long we keep it
We keep your data while your account exists. When we delete an account we remove your personal data, apart from what we must keep by law. Backups are overwritten on a rolling schedule and are kept for a limited time.
8. Your rights
Under Brazil's LGPD, and the GDPR where it applies, you can ask us to:
- confirm that we process your data and give you a copy;
- correct data that is wrong or incomplete;
- delete your account and data;
- tell you which partners we have shared your data with;
- export your data, object to processing, or withdraw consent you gave.
You can edit your profile, hide it, and turn partner sharing and partner contact off yourself in Settings. For everything else, including account deletion, use the contact below. We reply within 15 days. You may also complain to the Brazilian data protection authority (ANPD), or to your local one.
9. Security
We use HTTPS, store passwords only as hashes, require two-factor authentication, rate-limit sign-in and other sensitive actions, and run submitted code in an isolated sandbox. No system is perfectly secure, so if we learn of a breach that affects you we will tell you and the authorities as the law requires.
10. Children
Newbie on Rails is not directed at children under 13. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes
If we change this policy in a way that matters to you, for example by sharing data with someone new, we will say so on the site before it takes effect. The date at the top always shows the latest version.
Contact and data requests
Newbie on Rails is responsible for the data described in this policy. For any request about your data, write to:
[email protected]