Legal
Privacy Policy
Pyroom is a free Python environment that runs in your browser. This policy explains, in plain language, what data Pyroom handles, why, where it is kept, for how long, and how you can see or delete it.
In brief
- Your code runs and stays in your browser. It leaves your device only when you choose to share a project, send a bug report, or save Classroom work to your own Google Drive.
- You do not need an account. There are no ads, and Pyroom never sells or rents your data.
- Usage statistics are sent only if you turn them on, and never contain your code, output, or error text.
- With Google Classroom, Pyroom keeps only IDs, an encrypted authorization, and the assignments teachers publish. Student work is saved in the student's own Google Drive.
- You can disconnect, turn things off, or ask us to delete your data at any time: [email protected].
Who we are
Pyroom (pyroom.app and play.pyroom.app) is provided by Mykhailo Smaha, an individual developer in Ukraine, who decides how the data described here is used. Contact: [email protected].
This policy covers the website, the Playground, project sharing, the newsletter, bug reports, usage statistics, and the Google Classroom integration.
What we collect and why
Playground on your device
Your code, files, project history, task text, and settings (language, theme, accessibility profile, editor options) are saved in your browser's storage on your device. They are not sent to Pyroom. Clearing your browser's site data for play.pyroom.app deletes them.
AI help and console translation
AI explanations and console translation run inside your browser. Your code and error messages are not sent anywhere. To start, your browser downloads the model files from Pyroom's model server or from Hugging Face; like any download, that host sees your IP address.
Usage statistics (only if you turn them on)
If you opt in, the Playground sends short events such as "code run", "example loaded", "setting changed", or the type of a Python error (for example NameError), with a random session ID, the app version, and the time. We store a one-way hash of your IP address and of your browser's user agent to stop abuse. Events never include your code, program output, or error text. You can turn statistics off at any time in Settings.
Shared projects
When you press Share, the project (its code and files), and the author and task names if you enter them, are stored so that anyone with the link can open it. You choose how long the link works (1 hour to 30 days, or without an end date). Do not share personal information in a shared project.
Newsletter
If you subscribe, we store your email address and language and send release news through Resend. We also record the IP address and browser of the subscribe and unsubscribe requests to prevent abuse; these are cleared after 30 days. Every email has an unsubscribe link.
Bug reports
A bug report contains what you write, an optional email address, your browser and screen details, and the language. It is stored and copied into a private issue in Pyroom's GitHub repository so it can be fixed. The IP address of the request is stored to limit spam and cleared after 30 days.
Google Classroom integration
Teachers and students can connect a Google account to use Pyroom with Google Classroom. Pyroom stores:
- Connection: your Google account ID, your role (teacher or student), the permissions you granted, and an encrypted Google authorization so Pyroom can act for you when you use it. A browser session lasts up to 14 days.
- Teachers' assignments: what a teacher publishes β title, instructions, starter files, and visible tests β with the course and coursework IDs and links, and the teacher's account ID.
- Students' work: code and test results are saved as a
.pyroomfile in the student's own Google Drive and on the device. Pyroom stores only a one-way hash of the student's account ID, the Drive file and revision IDs, revision numbers, and submission time and link β never the code itself. - Shown, not stored: names and photos, course names, due dates, and hand-in counts are read from Google when you open a page and are not saved.
Pyroom does not store your email address, your password, or student source code for the Classroom integration.
Classroom beta requests
While the Classroom integration is in beta, teachers can ask for access. The form collects the Google account email, name, school, country (optional), class size, account type, and an optional note. We use them only to add the account to the beta and to email the teacher about it. The request is stored and copied into a private GitHub issue; the IP address is kept only as a one-way hash for rate limiting.
Website delivery
Pyroom is hosted on Cloudflare, which processes your IP address, browser, and the pages you request to deliver and protect the site. The website loads fonts from Google Fonts, and the Playground loads the Python runtime from jsDelivr and pyodide.org; these services see your IP address. Pyroom does not use advertising or tracking cookies.
Google user data
Pyroom asks only for the Google permissions it needs for the Classroom features you use:
| Permission | Who grants it | What Pyroom does with it |
|---|---|---|
openid | Teachers and students | Gets a stable ID for your Google account so Pyroom can keep you connected. The ID is stored; for students it is stored only as a one-way hash next to assignment work. |
https://www.googleapis.com/auth/userinfo.profile | Teachers and students | Shows your name and photo on the Classroom page so you can see which account is connected. Fetched each time; never stored. |
https://www.googleapis.com/auth/classroom.courses.readonly | Teachers (required); students (optional) | Lists your active courses so a teacher can choose where to publish an assignment and the dashboard can show course names. Read-only; shown live, not stored. |
https://www.googleapis.com/auth/classroom.coursework.students | Teachers | Creates the coding assignment as Classroom coursework and reads how many students handed it in. Pyroom stores the assignment it created; hand-in counts are shown live, not stored. |
https://www.googleapis.com/auth/classroom.coursework.me | Students | Reads the state of your own submission, attaches your project file and a review link, turns it in, and takes it back when you choose Unsubmit. |
https://www.googleapis.com/auth/drive.file | Teachers and students | Saves your project checkpoints as one file in your own Google Drive, and lets a teacher open a submitted file they select. Pyroom can reach only files it created or that you picked β not the rest of your Drive. |
Pyroom uses Google user data only to provide and improve these user-facing features. Pyroom does not:
- use Google user data for advertising, or sell it;
- transfer it to others, except as needed to provide these features, to comply with law, or as part of a merger or sale with the same protections;
- let people read it, unless you ask us to (for example for support), it is needed for security, or the law requires it;
- use it to train generalized artificial-intelligence or machine-learning models.
Pyroom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can remove Pyroom's access at any time with Disconnect on play.pyroom.app/classroom (this deletes Pyroom's stored authorization and revokes it at Google) or in your Google Account permissions.
How long we keep data
| Data | Kept for |
|---|---|
| Playground data in your browser | Until you clear it |
| Usage statistics | 12 months (request logs used against abuse: 30 days) |
| Shared projects | Until the link expires, as you chose; links without an end date until you ask us to delete them |
| Newsletter | Until you unsubscribe; afterwards only your email and the unsubscribe date, so we do not email you again, deleted on request |
| Bug reports | 24 months |
| Raw IP address and browser details (newsletter, bug reports) | 30 days, then cleared |
| Classroom connection | Until you disconnect; browser sessions up to 14 days |
| Classroom assignments and student work references | While the course uses them; deleted on request or 24 months after the last change |
| Student work files | In the student's Google Drive, controlled by the student and school |
| Classroom beta requests | Until the beta ends, or sooner on request |
Security
All traffic uses HTTPS. Google authorizations are encrypted (AES-GCM) before they are stored, browser session IDs are stored only as hashes, and student IDs are stored as one-way hashes next to assignment work. IP addresses used for statistics and rate limits are hashed. Only the provider can access Pyroom's database. No system is perfectly secure; if a breach affects you, we will tell you and the authorities as the law requires.
Your rights and choices
Wherever you live, you can ask us to:
- tell you what data we hold about you and give you a copy;
- correct it;
- delete it;
- stop using it for a purpose, or withdraw a consent you gave.
Write to [email protected] from the email or Google account concerned. We answer within 30 days. You can also act yourself: turn usage statistics off in Settings, unsubscribe from any newsletter email, choose Disconnect on the Classroom page, remove Pyroom in your Google Account permissions, or clear Pyroom's site data in your browser.
If you think we handle your data unlawfully, you can complain to the Ukrainian Parliament Commissioner for Human Rights or to the data protection authority where you live.
Students and children
The Playground works without an account and does not ask for age or identity. Students use the Classroom integration through their school's Google Classroom, under the school's authorization; the school's Google Workspace administrator decides whether Pyroom may be used. Pyroom collects only what is described above for students and does not show ads. Parents or schools who want a student's data deleted can write to [email protected].
Changes to this policy
When this policy changes, we update the effective date above. For important changes β for example new data or new Google permissions β we will also show a notice on the website and in the Classroom page before they apply. Earlier versions are available on request.
Contact
Mykhailo Smaha, Pyroom β [email protected]. This policy is governed by the law of Ukraine, including the Law of Ukraine "On Personal Data Protection".