Privacy Policy — Learn Python
Effective date: 10 Haziran 2026 Last updated: 10 Haziran 2026
This Privacy Policy explains how Yetkin Berat Sönmez (Kodpath) ("we", "us", "the developer") collects, uses, stores and protects your personal data when you use the Learn Python mobile app (the "App") and this website.
The App is an educational app for learning the Python programming language. We process your data to provide the service, save your progress, and keep the App secure and stable. The App shows ads through Google AdMob (full-screen ads between lessons and, optionally, rewarded ads you choose to watch that grant in-app gems). The App also offers optional in-app purchases such as the "Super" subscription and gem packs; payments are processed by the Apple App Store or Google Play, and we never see your card/bank details. We do not use third-party analytics for advertising and do not sell your data. In regions where consent is required (EU/UK) and on iOS, we ask for your explicit consent for personalized advertising and tracking; the App works fully even without consent (you simply see non-personalized ads).
By using the service you accept the practices described in this policy.
1. Data Controller
For your processed personal data, the data controller under Türkiye's Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the EU General Data Protection Regulation ("GDPR") is:
- Data controller: Yetkin Berat Sönmez (Kodpath)
- Contact: contact@kodpath.com
- Address: —
- Website: https://kodpath.com/tr/learn-python
2. Summary
| Topic | Short explanation |
|---|---|
| What data? | Account (optional email), profile (name, photo), learning progress, purchase/subscription status, notification (push) token, limited technical/crash data |
| Why? | To provide the service, save progress, gamification/rankings, deliver purchases & subscriptions, security and debugging |
| Ads? | Yes — Google AdMob (full-screen between lessons + optional rewarded ads) |
| Tracking/personalization for ads? | Only with your consent (AdMob/UMP consent screen; ATT on iOS) |
| Purchases & subscription? | Yes — "Super" subscription and gem packs (via App Store / Google Play) |
| Payment card details? | We don't see them — payment is processed entirely by Apple/Google |
| Selling data? | No |
| Server location | European Union (Germany/Frankfurt) — Supabase infrastructure |
| Account deletion | Possible in-app with a single tap (Settings → Delete Account) |
3. Data We Collect
3.1. Account information
- Anonymous account: The first time you open the App, an anonymous account is created for you automatically, without an email or name. This lets us store your progress under an identifier tied to your device.
- Permanent account (optional): To keep your progress and access it from other devices, you can create a permanent account with an email address. In that case we process your email and the one-time verification codes/links used to sign you in. We do not store passwords (sign-in uses a code/link sent to your email).
- Sign in with Google or Apple (optional): You can also create or sign in to your permanent account with your Google or Apple account. When you use this method, the provider shares your email address (and name, if available) with us to verify your identity; we never see your password. With Sign in with Apple you can use Apple's "Hide My Email" option to share a relay address instead of your real email.
3.2. Profile information
- The display name (username) you choose.
- A profile photo you optionally upload. When you pick a photo we only access the image you select, not your whole gallery. The uploaded image is downsized and stored on our server.
3.3. Learning and usage data
For the App's core function we process the following progress data:
- Completed lessons, exercise attempts and correct/incorrect results,
- XP, streak, level, badges,
- In-app virtual values (gems, hearts, chests) and store/reward records,
- Daily quests and review (spaced repetition) records,
- Placement test and unit exam results,
- Arena/challenge submissions.
3.4. Social feature data
The App includes social features such as leaderboards and following friends:
- Users you follow / who follow you,
- Your score and position in the league and leaderboard.
Using social features is optional; see Section 5.
3.5. Device permissions
- Photos: Access is requested only when you want to upload a profile photo, so you can pick an image.
- Notifications: If you allow them, we may send you two kinds of notifications: (1) local notifications generated on your device (such as streak reminders and your daily goal), and (2) remote (push) notifications sent from our server (such as duel (1v1) invites). To send remote notifications we register your device's push notification token, which is a device identifier used solely to deliver notifications to you. You can turn off notification permission anytime in your device settings.
3.6. Technical data and crash reports
To keep the App stable, we may use crash and error reporting only in store-distributed builds (Sentry). This may process technical data such as the app version, device model, OS version and error/stack trace information. This reporting is configured to minimize personal data (sensitive user data is not sent by default).
3.7. Advertising data (Google AdMob)
In store-distributed builds, the App shows ads via Google AdMob:
- Full-screen (interstitial) ads: between lessons/tasks, not in the middle of a lesson.
- Rewarded ads: shown only when you choose to tap "Watch an ad, earn gems"; they grant in-app gems (no real money).
To serve ads and prevent fraud, AdMob may process information such as device and advertising identifiers (e.g. the ad ID), IP address, and coarse ad-interaction data. Personalized advertising and tracking happen only with your consent; you can manage your choice through AdMob's consent (UMP) screen and the App Tracking Transparency (ATT) prompt on iOS. Without consent you see non-personalized ads. AdMob is a data processor and handles data under its own privacy policy: https://policies.google.com/privacy and https://support.google.com/admob/answer/6128543.
3.8. Purchase and subscription data
The App offers optional in-app purchases: the "Super" subscription (an ad-free experience plus extra perks) and in-app gem packs.
- We do not process the payment. All purchases go through the Apple App Store or Google Play; we do not see or store your payment card/bank details.
- We receive limited information from the store to verify a purchase and restore your entitlement across devices, such as: product ID, transaction/subscription ID, purchase and validity/renewal dates, and subscription status (active/cancelled/expired).
- We process this data to grant you the correct perks, restore subscriptions, prevent abuse, and meet legal/accounting obligations.
- The subscription renews automatically; you manage and cancel it from your Apple/Google account settings (see the Terms of Use).
3.9. Data we do not collect
We do not collect:
- Precise location (GPS) data,
- Your full payment card number or bank details (payment is processed entirely by Apple/Google),
- Tracking for advertising or analytics without your consent,
- Continuous access to contacts, microphone or camera.
4. Purposes and Legal Bases for Processing
| Purpose | Data type | Legal basis (KVKK art.5 / GDPR art.6) |
|---|---|---|
| Creating your account and maintaining the session | Account/email | Formation/performance of a contract |
| Saving and showing your learning progress | Learning/usage | Performance of a contract; legitimate interest |
| Gamification, rankings and social features | Profile, progress, social | Consent / legitimate interest |
| Delivering and restoring purchases and subscriptions | Purchase/subscription status | Performance of a contract; legal obligation |
| Local and remote (push) notifications | Notification permission, push token | Consent |
| Showing ads (non-personalized) | Ad interaction, device/IP | Legitimate interest |
| Personalized advertising and tracking | Ad ID, device/IP | Consent (UMP/ATT) |
| Security, abuse prevention, debugging | Technical/crash data | Legitimate interest; legal obligation |
| Complying with legal obligations | Relevant data | Legal obligation |
For consent-based processing you may withdraw your consent at any time (see Section 8).
5. Information Shared With Other Users
When you use social features (leaderboards, leagues, following friends, viewing profiles), your display name, profile photo and certain statistics (e.g. XP, streak, badge count, leaderboard position) may be visible to other users.
- Anonymous accounts appear on leaderboards as "Anonymous"; no name is published.
- If you don't want to be visible to other users, you can choose to use the App without creating a permanent account, or remove your display name/photo.
Your email address is never shown to other users.
6. Third-Party Service Providers (Data Processors)
To provide the service we rely on the following trusted providers. They process data only on our behalf and in line with this policy:
| Provider | Purpose | Notes |
|---|---|---|
| Supabase | Database, authentication, file (profile photo) storage | Data hosted in the EU (Germany/Frankfurt) region |
| Vercel | Hosting this website | IP and basic request logs may be processed on site access |
| Sentry | Crash and error reporting (store builds only) | Configured to minimize personal data |
| Google AdMob | Serving ads (full-screen + rewarded) and preventing ad fraud | Processes ad/device identifiers and IP; personalization only with consent (UMP/ATT) |
| Apple App Store / Google Play | Distributing the App and processing in-app purchase/subscription payments | The store handles payment; we only receive purchase/subscription status and never see your card details |
| Google / Apple (Sign-In) | Authentication via the optional "Sign in with Google/Apple" | Applies only if you choose it; the provider shares your email/name with us. Apple supports "Hide My Email" |
| Expo (push notification service) | Delivering remote (push) notifications (e.g. duel invites) | The push token is routed via Apple (APNs) and Google (FCM) infrastructure |
| jsDelivr (CDN) | Downloading the Python engine (Pyodide) that runs code exercises | When you use the code-running feature, your IP may be sent to the CDN |
We do not sell your data to data brokers. For ad serving, data is processed with Google AdMob only within the scope described above and subject to your (consent) preference. We may also share your data with authorities where legally required (e.g. a court order).
7. Where Data Is Stored and International Transfer
Your personal data is stored on servers in the European Union (Germany/Frankfurt) region via Supabase infrastructure. When you access from Türkiye, your data may be processed on these servers abroad. Third-party providers are chosen from organizations that provide safeguards compliant with applicable law.
8. Your Rights
Under KVKK and GDPR you have the following rights regarding your personal data:
- To learn whether it is processed and to request access to your data,
- To request correction of incomplete/incorrect data,
- To request deletion or destruction of your data,
- To object to processing and to withdraw consent (where applicable),
- To receive a portable copy of your data (data portability),
- To lodge a complaint with the relevant supervisory authority (in Türkiye, the Personal Data Protection Authority).
To exercise these rights:
- You can permanently delete your account and all progress data in-app via Settings → Delete Account. Deletion is irreversible. (An active subscription is not cancelled by deleting your account; cancel it via your App Store/Google Play account settings.)
- You can update or remove your display name and profile photo via Settings.
- You can change your ad-personalization consent anytime via the AdMob consent (UMP) screen and, on iOS, the Tracking (ATT) setting in your device settings.
- For other requests, contact us at contact@kodpath.com; we respond within the period required by law.
9. Children's Privacy
The App is a general-audience educational app. You must be at least 13 years old to use it. We do not knowingly collect personal data from children under this age. If we learn that a child under the applicable age limit has provided us data without parental/guardian consent, we delete it. If you believe your child has provided us data, please contact us at contact@kodpath.com.
10. Data Retention
We keep your personal data for as long as your account is active and as needed to provide the service. When you delete your account, your associated learning and profile data is permanently deleted from the system. Purchase/subscription and billing records may be retained for the period required by tax and accounting law. Crash/error reports are kept for a limited time per the service provider's retention policy.
11. Security
We take reasonable technical and administrative measures to protect your data against unauthorized access, loss and misuse, including encryption in transit (HTTPS), row-level access control (row-level security) and server-side authorized access. Note that no method is 100% secure; absolute security cannot be guaranteed.
12. Cookies and Tracking
The mobile app uses the local storage necessary to keep your session open. In addition, Google AdMob may use device/ad-identifier technologies to serve and (if you consented) personalize ads; you can manage your ad-personalization choice via the AdMob consent (UMP) screen and, on iOS, the Tracking (ATT) setting in device settings. This website uses only strictly necessary cookies: the Supabase session cookies that keep you signed in to the admin area, and a cookie that remembers your language preference. The website uses no advertising/analytics cookies or third-party tracking.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We announce material changes in the App or at https://kodpath.com/tr/learn-python. The "Last updated" date shows the most current version. Continuing to use the service after changes means you accept the updated policy.
14. Contact
For any questions, requests or complaints about this policy or your personal data:
- Yetkin Berat Sönmez (Kodpath)
- Email: contact@kodpath.com
- Privacy requests: contact@kodpath.com
- Web: https://kodpath.com/tr/learn-python
This document is for information only and does not constitute legal advice. Before publishing, we recommend consulting a legal professional regarding compliance with applicable law (KVKK, GDPR, etc.).