Privacy
TRTD is built to know as little about you as possible. Fonts are self-hosted, video streams from our own CDN, and there are no third-party scripts, embeds, analytics services or ad pixels anywhere on the site.
Last updated 2026-08-04.
Who we are
Lidema Studios (Pty) Ltd (South Africa) is the responsible party and controller for everything described here, under POPIA, GDPR, UK GDPR.
- Information Officer
- Martin Kruger
- Contact
- privacy@theroadtodev.com
- EU representative
- Being appointed
- UK representative
- Being appointed
You must be 18 or older to hold an account. Reading the site does not require one.
Why there is no cookie banner
Banners exist to gather consent for tracking. We do not track. Everything stored on your device is strictly necessary for something you actively asked for, and the analytics that ride along carry no IP address, no user agent, no cross-site identifier and no profiling.
No identifier exists until there is something to keep. Reading a page — the home page, a Resource, the blog, the glossary, a roadmap, search, these legal pages — writes nothing to your device and creates no record of you. An identity is minted on your first write: opening a lesson, marking something complete, starting a quiz, running a challenge.
What this site stores on your device
The complete inventory. Nothing else is written, and none of it is readable by anyone but this site.
| Item | Mechanism | Purpose | Lifetime |
|---|---|---|---|
| Session | Cookie | Carries the anonymous or account identity that holds your progress | Session lifetime |
| Live editor drafts | localStorage | Keeps your own code across reloads, in lesson editors and in-progress challenges | Until you clear it |
| Code-block preference | localStorage | Your TypeScript/JavaScript and npm/pnpm/yarn choice | Until you clear it |
| Theme preference | localStorage | Light or dark | Until you clear it |
| Search source toggles | localStorage | Which search sources you have enabled | Until you clear it |
No third-party storage of any kind.
What we measure
Page views are counted first-party and in aggregate. Each row holds a redacted path, a timestamp, the origin of the referring site, the content item the page resolved to, and a two-letter country. Referrers are reduced to their origin so other people's search queries never reach us, query strings are dropped except a share marker, and certificate pages are excluded from measurement entirely.
Your country is resolved from your IP address in memory, at the moment of the request, and the address is then discarded. It is never written down, so there is nothing to purge and nothing to hand over.
What we don’t measure
- No session recording
- No heatmaps
- No A/B tests or experiments run on learners
- No cross-site tracking
- No ad pixels
- No device fingerprinting
- No profile view counts
- No IP address or user-agent storage
- No third-party analytics service
- No open or click tracking in any email we send
The AI lesson chat
When you use the lesson chat, your message and the lesson's own content are sent to Anthropic to generate a reply. Your identity is not. No user ID, no email, no username, no display name and no progress state leaves this site — the request is assembled on our server and carries the lesson and your message, nothing else.
We store no transcripts. The conversation lives in your browser for the session only. The daily message counter is a number and a date; it never contains anything you wrote.
Why we are allowed to hold what we hold
| What | Lawful basis |
|---|---|
| Accounts, sign-in, sessions | Contract — providing the service you asked for |
| Progress, quiz attempts, submissions, achievements | Contract — this is the service |
| Certificates and the public profile | Contract, plus your explicit opt-in |
| Transactional email | Contract |
| Page-view measurement | Legitimate interests — aggregate, no IP, no profiling |
| Rate limiting and abuse prevention | Legitimate interests — IP used, never stored |
| Error monitoring | Legitimate interests — self-hosted, no account identifiers |
| Moderation and suspension | Legitimate interests — protecting learners |
| Product-update email | Consent — the only consent-based processing here |
Who else touches your data
Everyone who processes personal data on our behalf. This table is generated from a file in our source repository, so it cannot fall out of date with what we actually run.
| Processor | Purpose | Where | Transfer basis |
|---|---|---|---|
| Hetzner | Application and database hosting | EU (Germany) | None needed |
| Bunny | Video streaming and asset CDN | EU (Slovenia) | None needed |
| Resend | Transactional email delivery | US | DPA + SCCs/DPF |
| Anthropic | AI lesson chat inference | US | DPA + SCCs/DPF |
| GitHub | OAuth identity, the TRTD App, project template repositories | US | DPA + SCCs/DPF |
| Cloudflare | DNS (gray-cloud) and encrypted off-host backup storage | US company | DPA + SCCs/DPF; R2 bucket set to EU jurisdiction restriction |
| Migadu | Inbound mail on the root domain | Switzerland | Adequacy decision — no SCCs needed |
Sign-in providers are not our processors. If you sign in with Google, Facebook (Meta), LinkedIn, Discord, they decide their own purposes for what they hold about you. We receive the provider, an account ID, your email and whether it is verified, and a name to seed your display name — nothing else. We never store the avatar image or URL.
Error monitoring is first-party. We run it on our own servers rather than sending errors to a third party, which removes a processor and a data transfer entirely. Reports carry a random per-browser-session identifier that exists nowhere else and cannot be resolved back to an account.
Donation links to GitHub Sponsors and Ko-fi are ordinary outbound links. There is no embed, no widget, and no data flows from us to them.
How long we keep it
| Data | Retention |
|---|---|
| Your learning record — completions, quiz attempts, submissions, achievements | For as long as your account exists. It is the service. |
| Anonymous identities and their data | 90 days from last activity |
| Page views with no account attached | 90 days |
| Page views attached to an account | 25 months |
| Daily aggregate page-view counts | Indefinitely — no identifiers of any kind |
| Web-server access logs | 14 days |
| Email send metadata (never the message body) | 180 days |
| Email delivery events | 90 days |
| Addresses that bounced or complained | Indefinitely — see below |
| Error reports | 90 days |
| Deletion log (a hash and a date) | 90 days |
| Database backups | 7 days on-host, 60 days off-host and encrypted |
| Record of a rights request | 3 years, for accountability |
Your rights, and how to use them
Export, deletion, correcting your display name and the visibility toggles all live in your settings and work immediately, without anyone reading a request. Export gives you a single JSON file of everything we hold about your account.
Anything else goes to privacy@theroadtodev.com. We answer within 30 days, there is no fee, and we verify who you are by your signed-in session or a link sent to the address on your account — never by asking for an ID document.
What deletion does and does not reach
Deleting your account removes your progress, attempts, achievements and submissions immediately, and your certificate links stop showing a certificate — they say it was withdrawn rather than breaking, so anyone holding one gets an honest answer instead of a dead link.
One thing survives, and we would rather say so than have you find out. If mail to your address ever hard-bounced or was reported as spam, we keep that address, that fact and its date — permanently. Nothing else, and for no purpose other than never mailing it again. Deleting it would let the same address be mailed afresh after a re-signup, which is the exact harm the record exists to prevent.
Off-host backups rotate on a 60-day cycle, so a copy taken before your deletion may hold your data until it rotates out. Those copies are encrypted, are never queried, and are never used to make any decision about anyone. If we ever restored one, deletions are replayed as a mandatory step rather than silently reversed.
Project repositories live in your GitHub account. They were never ours, and deleting your TRTD account does not touch them.
If something goes wrong
We assess any suspected breach within 24 hours. Where the law requires it we notify the relevant supervisory authorities within 72 hours, and under POPIA we notify the Information Regulator and affected people as soon as reasonably possible.
Attribution
- IP geolocation by DB-IP — https://db-ip.com