Privacy Policy — Learn Python
Effective date: June 10, 2026 Last updated: August 19, 2026
This Privacy Policy explains how Yetkin Berat Sönmez (Kodpath) ("we", "us", "the developer") collects, uses, stores and protects your personal data when you use the Learn Python mobile app (the "App") and this website.
The App is an educational app for learning the Python programming language. We process your data to provide the service, save your progress, and keep the App secure and stable. We use Google Analytics for Firebase to measure product usage and learning conversions. The App shows ads through Google AdMob (full-screen ads between lessons and, optionally, rewarded ads you choose to watch that grant in-app gems). The App also offers optional in-app purchases such as the "Super" subscription and gem packs; payments are processed by the Apple App Store or Google Play, and we never see your card/bank details. We do not sell your data. In regions where consent is required (EU/UK) and on iOS, we ask for your explicit consent for personalized advertising and tracking; the App continues to work without consent (non-personalized ads may still be shown).
By using the Service, you acknowledge that you have read this Privacy Policy. Where consent is required, we request it separately, and you may withdraw it through the controls described below.
1. Data Controller
For your processed personal data, the data controller under Türkiye's Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the EU General Data Protection Regulation ("GDPR") is:
- Data controller: Yetkin Berat Sönmez (Kodpath)
- Contact: contact@kodpath.com
- Website: https://kodpath.com/en/learn-python
2. Summary
| Topic | Short explanation |
|---|---|
| What data? | Account (optional email), profile (name, photo), learning progress, purchase/subscription status, notification (push) token, app-instance/installation and advertising IDs, approximate location derived from masked IP, session/screen/app-lifecycle data, learning-conversion and ad interactions, and limited technical/crash data |
| Why? | To provide the service, save progress, run gamification/rankings, deliver purchases & subscriptions, serve and measure ads, perform analytics, provide security, prevent fraud, and debug errors |
| Ads? | Yes — Google AdMob (full-screen between lessons + optional rewarded ads) |
| Tracking/personalization for ads? | Only with your consent (AdMob/UMP consent screen; ATT on iOS) |
| Purchases & subscription? | Yes — "Super" subscription and gem packs (via App Store / Google Play) |
| Payment card details? | We don't see them — payment is processed entirely by Apple/Google |
| Selling data? | No |
| Server location | Primary application data: European Union (Germany/Frankfurt) — Supabase infrastructure; some providers may process limited data in other countries |
| Account deletion | Possible in-app with a single tap (Settings → Delete Account) |
3. Data We Collect
3.1. Account information
- Anonymous account: The first time you open the App, an anonymous account is created for you automatically, without an email or name. This lets us store your progress under an identifier tied to your device.
- Permanent account (optional): To keep your progress and access it from other devices, you can create a permanent account with an email address. In that case we process your email and the one-time verification codes/links used to sign you in. We do not store passwords (sign-in uses a code/link sent to your email).
- Sign in with Google or Apple (optional): You can also create or sign in to your permanent account with your Google or Apple account. When you use this method, the provider shares your email address (and name, if available) with us to verify your identity; we never see your password. With Sign in with Apple you can use Apple's "Hide My Email" option to share a relay address instead of your real email.
3.2. Profile information
- The display name (username) you choose.
- A profile photo you optionally upload. When you pick a photo we only access the image you select, not your whole gallery. The uploaded image is downsized and stored on our server.
3.3. Learning and usage data
For the App's core function we process the following progress data:
- Completed lessons, exercise attempts and correct/incorrect results,
- XP, streak, level, badges,
- In-app virtual values (gems, hearts, chests) and store/reward records,
- Daily quests and review (spaced repetition) records,
- Placement test and unit exam results,
- Arena/challenge submissions,
- Content you bookmark and optional notes you add to it.
3.4. Social feature data
The App includes social features such as leaderboards and following friends:
- Users you follow / who follow you,
- Your score and position in the league and leaderboard,
- Duel invites, match results, answers and rating,
- Users you block and the reason/optional note in safety or moderation reports you submit,
- A briefly retained last-active timestamp used for the online-friends indicator.
During Duels, users can send only predefined emoji and quick-reaction messages to their opponent. These reactions are transmitted in real time through Supabase and are not retained as chat history. The App does not provide free-text chat.
Using social features is optional; see Section 5.
3.5. Device permissions
- Photos: Access is requested only when you want to upload a profile photo, so you can pick an image.
- Notifications: If you allow them, we may send you two kinds of notifications: (1) local notifications generated on your device (such as streak reminders and your daily goal), and (2) remote (push) notifications sent from our server (such as duel (1v1) invites). To send remote notifications we register your device's push notification token, which is a device identifier used solely to deliver notifications to you. You can turn off notification permission anytime in your device settings.
3.6. Technical data and crash reports
To keep the App stable, we may use crash and error reporting only in store-distributed builds (Sentry). This may process technical data such as the app version, device model, OS version and error/stack trace information. To count affected users without sending an email address or name, a report may include your internal account identifier (UUID). This reporting is configured to minimize personal data (sensitive user data is not sent by default).
3.7. Advertising data (Google AdMob)
In store-distributed builds, the App shows ads via Google AdMob:
- Full-screen (interstitial) ads: between lessons/tasks, not in the middle of a lesson.
- Rewarded ads: shown only when you choose to tap "Watch an ad, earn gems"; they grant in-app gems (no real money).
For ad delivery, measurement, and fraud prevention, the AdMob SDK may automatically process and share with Google the device's IP address (which may be used to estimate approximate/general location), ad/product interactions such as app launches, taps, and video views, app and SDK diagnostic/performance information, and device/advertising identifiers such as the Android advertising ID and App Set ID. These transfers may also occur for non-personalized ads for delivery, measurement, and security. Personalized advertising and cross-app/user tracking occur only where the required consent has been given; you can manage your choice through AdMob's consent (UMP) screen and the App Tracking Transparency (ATT) prompt on iOS. Without consent, non-personalized ads may still be shown. Details: https://policies.google.com/privacy, https://support.google.com/admob/answer/6128543, and https://developers.google.com/admob/android/privacy/play-data-disclosure.
To measure the reliability of the ad flow and ensure rewards are granted correctly, we also keep limited first-party ad telemetry in our own infrastructure (Supabase): randomly generated installation, session, and attempt IDs; ad format and in-app placement; event outcome and time (such as offer, impression, click, reward, or error); elapsed time, limited error details, and, where available, ad-revenue value/currency. These records may be linked to the internal app user ID and are used to measure ad performance, diagnose technical issues, and prevent reward abuse or fraud. Associated records are deleted when the account is deleted.
We also record limited first-party shop-funnel events in Supabase, such as shop impressions and actions, product or source identifiers, and purchase-flow status (started, completed, cancelled, failed, or abandoned). These events may be linked to the internal user ID and are used to operate, secure, diagnose, and improve the shop and purchase experience.
3.8. Product analytics (Google Analytics for Firebase)
In store-distributed builds, we use Google Analytics for Firebase to understand how the App is used and how users progress through the learning journey, diagnose problems, improve features, and measure campaign/conversion performance.
Firebase Analytics automatically collects some of the following data:
- A randomly generated app-instance ID for each app instance/installation; device, operating-system, and app-version information; and, where available and permitted by platform/consent settings, advertising identifiers (Android Advertising ID; IDFA on iOS where ATT authorization is available, otherwise a vendor identifier where applicable),
- Approximate location derived by Google from a masked IP address at collection time. Google states that the IP address is discarded before it is logged or stored,
- Sessions, screen views, first open, and app-lifecycle data such as app opens, updates, and foreground/background transitions,
- Automatic in_app_purchase events for store purchases and subscriptions, which may include product ID, product name, price, and currency.
We also send the following custom events to measure learning and product conversions:
- Tutorial completion,
- Sign-up method (only email, google, or apple as a method value; the actual email address is not sent),
- Lesson start, first-lesson completion, lesson completion, unit completion, and course completion, with the relevant lesson, unit, course, and path identifiers,
- Path purchase, with the path identifier and in-app gem transaction details such as listed/paid gem amounts, discounts, credits, or funds used.
These custom Analytics events do not send your email address, name, internal user UUID, code you write, answer, or solution. Our Google Analytics property is linked to our Google Ads account, so Analytics data and events may be shared with Google Ads for campaign and conversion measurement. Use for personalized advertising is subject to applicable platform settings and, where required, your consent choices. Details about Firebase Analytics automatic collection: https://support.google.com/analytics/answer/11582702, https://support.google.com/analytics/answer/11593727, and https://policies.google.com/privacy.
3.9. Purchase and subscription data
The App offers optional in-app purchases: the "Super" subscription (an ad-free experience plus extra perks) and in-app gem packs.
- We do not process the payment. All purchases go through the Apple App Store or Google Play; we do not see or store your payment card/bank details.
- We receive limited information from the store and our purchase-infrastructure provider RevenueCat to verify a purchase and restore your entitlement across devices, such as: app user ID, store purchase token/receipt, product and transaction/subscription IDs, purchase and validity/renewal dates, refund state, and subscription status (active/cancelled/expired). RevenueCat may also process limited technical data such as device type, operating system, and last-seen time to provide the service.
- We process this data to grant you the correct perks, restore subscriptions, prevent abuse, and meet legal/accounting obligations.
- The subscription renews automatically; you manage and cancel it from your Apple/Google account settings (see the Terms of Use).
3.10. Data we do not collect
We do not collect:
- Precise location (GPS) data (AdMob and Firebase Analytics may only derive approximate/general location from a masked IP address),
- Your full payment card number or bank details (payment is processed entirely by Apple/Google),
- Continuous access to contacts, microphone or camera.
We do not use personal data for personalized advertising or cross-app tracking where consent is legally required unless that consent has been obtained. Limited first-party operational measurement, diagnostics, security and fraud prevention, and non-personalized ad processing may still occur as described in this Policy.
4. Purposes and Legal Bases for Processing
| Purpose | Data type | Legal basis (KVKK art.5 / GDPR art.6) |
|---|---|---|
| Creating your account and maintaining the session | Account/email | Formation/performance of a contract |
| Saving and showing your learning progress | Learning/usage | Performance of a contract; legitimate interest |
| Gamification, rankings and social features | Profile, progress, social | Consent / legitimate interest |
| Delivering and restoring purchases and subscriptions | Purchase/subscription status | Performance of a contract; legal obligation |
| Local and remote (push) notifications | Notification permission, push token | Consent |
| Product analytics and learning/campaign conversion measurement | App-instance/ad IDs, approximate location, session/screen/lifecycle data, learning and purchase events | Legitimate interest; consent where legally required |
| Showing ads (non-personalized) | Ad interaction, device/IP | Legitimate interest |
| Personalized advertising and tracking | Ad ID, device/IP | Consent (UMP/ATT) |
| Security, abuse prevention, debugging | Technical/crash data | Legitimate interest; legal obligation |
| Complying with legal obligations | Relevant data | Legal obligation |
For consent-based processing you may withdraw your consent at any time (see Section 8).
5. Information Shared With Other Users
When you use social features (leaderboards, leagues, following friends, viewing profiles), your display name, profile photo and certain statistics (e.g. XP, streak, badge count, leaderboard position) may be visible to other users.
- Anonymous accounts are not published on global leaderboards or in user search.
- If you don't want to be visible to other users, you can use the App without creating a permanent account, or email us to request correction or removal of your profile data.
Your email address is never shown to other users.
6. Third-Party Service Providers (Data Processors)
To provide the service we rely on the following providers. Each provider processes data for the purpose described below and under its applicable privacy terms:
| Provider | Purpose | Notes |
|---|---|---|
| Supabase | Database, authentication, file (profile photo) storage | Data hosted in the EU (Germany/Frankfurt) region |
| Vercel | Hosting this website | IP and basic request logs may be processed on site access |
| Sentry | Crash and error reporting (store builds only) | Configured to minimize personal data |
| Google Analytics for Firebase | Measuring product usage, learning conversions, purchase events, and campaign performance | Processes app-instance/ad IDs, masked-IP-derived approximate location, session/screen/lifecycle data, and the custom events listed above; the Analytics property is linked to Google Ads |
| Google AdMob | Serving and measuring ads (full-screen + rewarded) and preventing ad fraud | Automatically processes/shares IP-derived approximate location, ad/device IDs, interactions, and diagnostics; personalization and tracking require the applicable consent (UMP/ATT) |
| Apple App Store / Google Play | Distributing the App and processing in-app purchase/subscription payments | The store handles payment; we only receive purchase/subscription status and never see your card details |
| RevenueCat | Validating store receipts, synchronizing subscription/entitlement status across devices, and relaying it to our server | Processes the app user ID, store purchase token/receipt, product/transaction/subscription status, and limited device technical data; it does not receive payment-card details |
| Google / Apple (Sign-In) | Authentication via the optional "Sign in with Google/Apple" | Applies only if you choose it; the provider shares your email/name with us. Apple supports "Hide My Email" |
| Expo (push notification service) | Delivering remote (push) notifications (e.g. duel invites) | The push token is routed via Apple (APNs) and Google (FCM) infrastructure |
| jsDelivr (CDN) | Downloading the Python engine (Pyodide) that runs code exercises | When you use the code-running feature, your IP may be sent to the CDN |
We do not sell your data to data brokers. Transfers to Google Analytics for Firebase and Google AdMob for measurement, ad delivery, and security occur within the scope described above; personalized advertising and tracking use the applicable consent controls. We may also share your data with authorities where legally required (e.g. a court order).
7. Where Data Is Stored and International Transfer
Primary application data, including account, progress, profile, social, and gameplay records, is hosted in Supabase’s European Union region in Frankfurt, Germany. Some third-party providers listed in Section 6 may process or store limited data in the United States or other countries. Where required, such transfers are handled using the applicable safeguards offered by those providers and under applicable data-protection law.
8. Your Rights
Under KVKK and GDPR you have the following rights regarding your personal data:
- To learn whether it is processed and to request access to your data,
- To request correction of incomplete/incorrect data,
- To request deletion or destruction of your data,
- To object to processing and to withdraw consent (where applicable),
- To receive a portable copy of your data (data portability),
- To lodge a complaint with the relevant supervisory authority (in Türkiye, the Personal Data Protection Authority).
To exercise these rights:
- You can permanently delete your account, associated app data, and RevenueCat customer profile in-app via Settings → Delete Account. Deletion is irreversible. The store's own transaction/billing records are outside this deletion flow. (An active subscription is not cancelled by deleting your account; cancel it via your App Store/Google Play account settings.)
- You can manage your display name in the in-app account settings and replace your profile photo from the Profile screen. Email us for other correction or removal requests.
- You can change your ad-personalization consent anytime via the AdMob consent (UMP) screen and, on iOS, the Tracking (ATT) setting in your device settings.
- For other requests, contact us at contact@kodpath.com; we respond within the period required by law.
9. Children's Privacy
The App is designed for users aged 18 and older and is not directed to children. People under 18 must not access or use the App or create an account, and must provide accurate and up-to-date information when asked about their age. We do not intend to knowingly collect personal data from anyone under 18. If we learn that a person under 18 has used the App or provided us with personal data, we take reasonable steps to disable the account and delete the associated personal data in accordance with applicable law. If you believe a person under 18 has provided us with data, please contact us at contact@kodpath.com.
10. Data Retention
We keep your personal data for as long as your account is active and as needed to provide the service. When you delete your account, your associated learning and profile data is permanently deleted from the system. Purchase/subscription and billing records may be retained for the period required by tax and accounting law. Firebase Analytics event data is retained under the data-retention settings configured in our Google Analytics property and Google's applicable retention rules; aggregated reports may remain for longer. Crash/error reports are kept for a limited time per the service provider's retention policy.
11. Security
We take reasonable technical and administrative measures to protect your data against unauthorized access, loss and misuse, including encryption in transit (HTTPS), row-level access control (row-level security) and server-side authorized access. Note that no method is 100% secure; absolute security cannot be guaranteed.
12. Cookies and Tracking
The mobile app uses the local storage necessary to keep your session open. Google Analytics for Firebase uses app-instance and, where applicable, advertising identifiers to measure sessions, screens, app lifecycle, and the events described above. Google AdMob may also use device/ad-identifier technologies to serve and (if you consented) personalize ads; you can manage your ad-personalization choice via the AdMob consent (UMP) screen and, on iOS, the Tracking (ATT) setting in device settings. This website uses only strictly necessary cookies: the Supabase session cookies that keep you signed in to the admin area, and a cookie that remembers your language preference. The website uses no advertising/analytics cookies or third-party tracking.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We announce material changes in the App or at https://kodpath.com/en/learn-python. The "Last updated" date shows the most current version. Where a material change requires your consent, we will request it separately before the relevant processing begins.
14. Contact
For any questions, requests or complaints about this policy or your personal data:
- Yetkin Berat Sönmez (Kodpath)
- Email: contact@kodpath.com
- Privacy requests: contact@kodpath.com
- Web: https://kodpath.com/en/learn-python
This document is for information only and does not constitute legal advice. Before publishing, we recommend consulting a legal professional regarding compliance with applicable law (KVKK, GDPR, etc.).