Privacy Policy
Last updated September 2026
What we collect
Most lessons can be read without an account, and we collect nothing at all in that case. An account is needed to run the exercises and to read the last few lessons of a course. Google is currently the only way to sign in; when you do, we receive the basic profile Google shares during OAuth — your name, email address, and profile picture — and store it so we can identify your account.
We also store your course progress — lessons completed, XP, badges, streak and the code you last wrote in each playground — against your account, so it is the same on every device you sign in on.
Cookies and analytics
Signing in sets a session cookie (via Auth.js) so we know you're logged in — it's essential to the site working and isn't used for tracking. We use Vercel Web Analytics to count page views and see which pages get used; it's cookieless and doesn't track you individually or across other sites.
Your Gemini API key
The in-browser coding playgrounds use a Gemini API key that you supply. We store it against your account so it is available wherever you sign in, and it is encrypted (AES-256-GCM) before it is written to our database — the encryption key is held in our server environment, never in the database alongside it.
Your key is only ever used to run your own requests. When you run a playground exercise, the key is used by your browser to call Google's Gemini API directly. When you use the PPTX Lab, generating a deck sends your key from our server to Google's Gemini API on your behalf — to research the topic, write the slides and generate images — including one small test image per image model to check what your key can do. Your key is never logged or shown back to anyone, and we never use it for anything else or share it. You can remove it at any time from the Settings page, which deletes it from our database.
How we use your data
Account data is used solely to operate Purrx: authenticating you and storing your course progress and settings. We do not sell your data or share it with third parties for advertising.
Where data is hosted
Purrx is hosted on Vercel, and account data is stored in MongoDB. Sign-in is handled by Google's OAuth service — we never see or store your Google password.
Deleting your data
The Settings page lets you reset your progress and remove your stored API key, both of which delete that data from our database. To request deletion of your whole account, contact us at the email below.
Changes to this policy
As Purrx adds features — like account-linked progress sync — this policy will be updated to reflect what data that feature stores and why.
Contact
Questions about this policy: parag.garg37@gmail.com