← Policies

Security policy

How your account and your data are protected, and how to report a hole.

Sign-in. No passwords: one-time email links, GitHub or Google. Sessions are cookies your browser keeps, and signing out ends them. Because your email account is the key, protect it with two-factor authentication.

Your data in transit and at rest. The site is HTTPS only. The database is managed Postgres with row-level security on every table, so a query can only reach rows it is allowed to.

Your AI keys. If you add your own AI key, it is encrypted before it is stored and is never sent to your browser. It is used only for requests you make.

Rate limits. Every write is rate limited, which is what keeps a script from filling the site.

Reporting a vulnerability

Mail the support address on the privacy page with what you found and how to reproduce it. Please do not test on other members' accounts, do not run load or denial-of-service tests, and give us a reasonable chance to fix it before telling the world. We will credit you if you would like.

DevLearn is run by one student developer on free infrastructure. There is no bounty programme, and there is no security theatre either: you will get a straight answer.

More in policies

Did this miss what you needed? Ask us and we will answer.