Sign-in. No passwords: one-time email links, GitHub or Google. Sessions are cookies your browser keeps, and signing out ends them. Because your email account is the key, protect it with two-factor authentication.
Your data in transit and at rest. The site is HTTPS only. The database is managed Postgres with row-level security on every table, so a query can only reach rows it is allowed to.
Your AI keys. If you add your own AI key, it is encrypted before it is stored and is never sent to your browser. It is used only for requests you make.
Rate limits. Every write is rate limited, which is what keeps a script from filling the site.
Reporting a vulnerability
Mail the support address on the privacy page with what you found and how to reproduce it. Please do not test on other members' accounts, do not run load or denial-of-service tests, and give us a reasonable chance to fix it before telling the world. We will credit you if you would like.
DevLearn is run by one student developer on free infrastructure. There is no bounty programme, and there is no security theatre either: you will get a straight answer.