Privacy

A small site should collect very little.

This notice describes the account, progress, agent authorization, and Pro billing data used by the current FlyPython website.

Hosting and security delivery

FlyPython is delivered through a Cloudflare Worker and Cloudflare's network. When you request this site, Cloudflare processes information needed to deliver and secure the request, which may include IP addresses, traffic-routing data, and system configuration information, under its privacy policy.

This infrastructure processing is separate from optional website analytics. FlyPython does not claim a provider retention period or access level that has not been verified.

Website analytics

FlyPython's checked-in application source does not add a browser analytics script or analytics cookies. The server keeps anonymous daily counts of a few steps, including agent authorization, file fetches, first agent claims, and pricing-page views. These counters contain a day, event name, and count; they do not contain an IP address or user id.

Cloudflare Web Analytics is not part of the approved application configuration. A production browser canary checks for injected beacon code and failed resources after each deployment; the result of a past deployment does not establish the state of a future one.

Analytics collection has not been approved. Any future enablement requires one coordinated change that names the provider, collected fields, retention period, and opt-out behavior here and permits only the required endpoints in the site's Content Security Policy. Otherwise, Cloudflare's platform-level injection must remain disabled.

Newsletter subscription

FlyPython.com does not embed a newsletter subscription form. Newsletter links send you to the FlyPython newsletter hosted by Substack. Substack receives the information you submit and applies its own privacy policy and consent flow, published at substack.com/privacy.

Accounts and progress

Accounts are optional — all challenge content works without one. Signing in with Google or GitHub shares your provider identity and (when returned) a verified email; email sign-up stores a PBKDF2-SHA256 hash of your password, never the password itself. Sessions use a single HttpOnly cookie.

Agent authorization links (how your coding agent gets a token without your password): when your agent starts one, we store the request for 10 minutes with the agent's self-reported name, the requesting IP address, and the country derived from it — both are shown to you on the approval page so you can verify the request is yours. Approved requests mint a token that stores only its scopes and origin; the request row is deleted within 24 hours. Agent tokens can submit claim codes, read your claim secret, and — for subscribers — fetch Pro course files; nothing else. You can revoke them anytime on /account/agent. Separately we keep anonymous per-day counters of server-observable steps — authorization links, agent file fetches, first agent claims, and pricing-page visits (counts only — no identifiers, no IPs) to see whether the flow works.

Stored account data: email (if provided), display name, sign-in method links, challenge claim codes you submit (including which channel submitted each — browser session or your own agent token), derived points/badges, and your subscription state. Your display name and points appear on the public leaderboard once your email is verified; nothing else is public unless you opt in to a builder profile (/builders/<name>), which shows display name, points, and badges only and can be switched off anytime on /account. Account data is kept while your account exists. Deleting your account removes your sessions, sign-in links, claims, and the local subscription record; an active Stripe subscription is cancelled at the same time (Stripe retains its own records under its policy).

Pro subscription billing

Pro is a Stripe-billed subscription. Checkout and card data are processed entirely by Stripe under its privacy policy — no card numbers touch FlyPython systems. We store only your Stripe customer id, subscription id, status, and period end, used to show your plan state and open the customer portal. Stripe calculates tax at checkout.

Transactional email is sent via Cloudflare Email Service from our own domain; only your address and the message travel through it. Account email covers four kinds: email verification links, password resets, a one-line notice when your account earns a badge, and a notice when a new agent is authorized on your account (so an approval you do not recognize can be revoked immediately). We may also send product and marketing email, such as new-course announcements and platform updates — only to people who explicitly turned it on. Subscribing or paying never counts as consent: the signup form has an unchecked opt-in box, the switch lives in your account settings, and each product email carries a one-click unsubscribe link — unsubscribing never stops the account email above. Product email only ever goes to a verified address, and a record of which course announcement was already sent prevents duplicates. Stripe sends its own charge receipts — replies to a receipt reach us directly and are the channel for refund requests.

External resources

FlyPython's first-party playbooks and checklists are served on this site. Each playbook may cite official sources, and the secondary Official references section links to third-party documentation and project websites. FlyPython does not control those external sites' analytics, cookies, or privacy practices.

Contact

Until a private contact address is verified, non-sensitive privacy questions and content corrections can be filed in the companion public FlyPython resource tracker. The website repository itself is not an anonymous public issue channel. Include the affected page URL and a supporting source, and do not include personal or confidential information.

Last updated: September 16, 2026.