Plain-language policy
Privacy notice
Effective 3 September 2026
This notice explains the personal data QuickDevBase uses to provide accounts, per-technology learning progress, certificate assessments, optional AI lesson help, and optional public certificates of completion.
Data we process
- Your name and email address.
- A salted password hash—never your readable password.
- Login sessions, course progress, and completion timestamps.
- Certificate assessment questions, selected answers, scores, attempt times, and recorded exam-window warnings.
- If you choose to publish a certificate: your chosen public name, course, issue date, credential ID, and database verification code.
When you use Ask QuickDev, we also process a per-user daily request count. The temporary answer cache stores a one-way request hash and generated answer without your user ID.
Why we use it
We use this information to create and secure your account, restore your progress, enforce assessment rules, determine certificate eligibility, issue a completion record when requested, prevent abuse, and verify a certificate you voluntarily publish.
Public certificate choice
You can make the certificate private again at any time. The same link will stop working publicly until you choose to republish. Updating your account name also updates the name on your certificate.
Optional AI lesson help
Ask QuickDev is used only when you select an AI action, submit a question, or ask it to analyze an image. For lesson help, the open lesson, its official documentation link, and your question are sent to Google's Gemini API. When hybrid RAG is enabled, a topic question is embedded for semantic retrieval and the question plus the top server-owned curriculum excerpts are sent to Gemini to produce a grounded answer. For image matching, the uploaded PNG, JPEG, or WebP image is sent to Gemini to extract educational text before the same retrieval process. Local lexical retrieval remains the fallback when RAG is disabled or unavailable. QuickDevBase does not include your name, email, progress, password, or certificate in these requests. Do not upload or enter personal, confidential, or sensitive information.
Uploaded images and their extracted text are not retained after processing or placed in the answer cache by QuickDevBase. Identical lesson-guide requests may be answered from a temporary shared cache to reduce provider calls. Cached records expire automatically and are not linked to a user ID. Per-user daily counts are retained for abuse prevention and are deleted with the account.
Retention and deletion
Account data remains while your account is active. Expired sessions are removed automatically. You can permanently delete your account from Profile & privacy settings; this deletes the user, sessions, progress, assessment, and certificate records through database cascade rules.
Temporary AI cache entries expire automatically. Deleting your account also deletes its AI usage counts.
Security and service providers
QuickDevBase uses password hashing, random session tokens, HTTP-only cookies, parameterized database queries, security headers, access controls, bounded AI inputs and outputs, and usage limits. PostgreSQL and the deployment provider process data to operate the service. Google processes Ask QuickDev requests as the AI provider. Pages currently load typefaces from Google Fonts, so Google may receive ordinary network information such as an IP address.
Your choices
You may correct your name, unpublish your certificate, or delete your account from the application. For another privacy request, contact the deployed site operator. If this project is operated from the public repository, open a repository issue without posting passwords or other sensitive information.
