Skip to content
BytePatterns

Effective 5 October 2026

Privacy Policy

BytePatterns (bytepatterns.com) is a free learning site. This page says exactly what we store about you, why, and how to make it go away. It is written by the people who wrote the code, and it is short because there is not much to tell.

The short version

  • You can use every lesson and problem without an account.
  • Our visitor counting uses no cookie, no third-party script and stores no IP address.
  • We only hold your email address if you typed it in — to sign in, or to get the newsletter — and you can delete it yourself.
  • If you buy Premium or an AWS exam pack, Lemon Squeezy takes the payment; your card details never reach us.
  • The mobile app collects no data at all.
  • We do not sell, rent or share personal data with advertisers.

1. Site analytics

We count readers with our own first-party code. Each event (a page view, a lesson started, a quiz finished) is one row containing the event name, the page path without any query string, a small set of non-personal values such as a lesson id or a score, the referring site if there was one, campaign parameters from the link you arrived through, your country code as reported by our hosting provider, and a timestamp.

Instead of an identifier, each row carries a hash built from the current UTC date, your IP address, your browser's user-agent string and a server secret. The IP address is used to compute the hash inside the request and is then discarded; it is never stored or logged. Because the date is part of the hash, the value changes for everyone at midnight, so it can tell how many people visited today and cannot follow one person from one day to the next.

The user-agent string itself is never stored. If it says the request comes from an automated client such as a search crawler, the row is marked with the single word "bot", so that crawlers can be left out of the reader count. When a newsletter sign-up stores nothing, we record only why (for example "not a valid address"), never the address that was typed.

Signing in, creating an account, earning a certificate, starting a checkout and completing a purchase are counted by our server, not by your browser. Those rows carry no visitor hash, so they cannot be joined to what you read; they hold the plan or module and, if you arrived through a campaign link, its campaign labels — never your email address or a price. The labels travel with your sign-in or checkout request, are kept beside the sign-in link or the checkout until it is used, and are then deleted. No cookie is involved.

Analytics writes no cookie and no persistent identifier to your browser. If your browser sends a Do Not Track or Global Privacy Control signal, no analytics row is written at all.

2. Progress on your device

Which lessons you completed, your quiz results and your practice progress are stored in your own browser's local storage. They never leave your device unless you sign in and choose to sync them. Clearing your browser data removes them.

3. Accounts

An account is optional. If you create one, we store your email address, the time you signed up, and the progress you chose to sync. There is no password: signing in sends a one-time link to your email address, and the link expires after a single use.

While you are signed in, a cookie named bp_session keeps you signed in. It is a signed session token and it is marked HttpOnly. A companion cookie, bp_signed_in, holds only the value 1 so that pages can show the right header link without asking the server. Once Premium is on sale, a signed-in reader also gets bp_access, a signed HttpOnly note of whether the account has Premium, which decides which lessons a page shows, and bp_access_fresh, which lasts 30 seconds and stops a page from re-checking that note twice in a row. These are the only cookies this site sets; all of them belong to a signed-in session, none is used for analytics, and signing out removes them.

You can delete your account at any time from your account page. Deleting it removes your email address, every progress row and every certificate attached to it immediately.

If you ask for a module certificate, we store the name you type for it, the module and the date. That name, never your email address, is shown on the certificate and on its public verification page, which anyone with the link can open and which asks search engines not to index it. Deleting your account deletes the certificate and its link stops working.

AWS practice exams. Without an account, your answers and results on the AWS certification practice exams and practice sets stay in your browser's local storage, like the rest of your progress. If you are signed in, each one you finish is also stored on your account, so that it appears on your other devices: the certification, which practice exam or set it was and the exam version, when you started and finished it, how long it took, your score overall and per exam domain, whether the time ran out, the options you picked for each question and the questions you flagged. From those we also keep, per question, how many times you answered it wrong, whether your latest answer was right and whether you flagged it. Results you finished in this browser before signing in are copied to your account when you sign in, unless another account has already synced on this browser. An exam you have started but not finished stays in this browser only. We keep your latest 200 attempts per certification and drop older ones; deleting your account deletes all of it.

4. Payments

Premium is not on sale yet; until it is, the parts of this section about Premium do not happen.

Premium is sold through Lemon Squeezy, our merchant of record. When you start a checkout we send Lemon Squeezy your account's email address, so the form is filled in for you, and two random internal ids (your account's and the checkout's), so the payment can be matched back to your account. You then pay on Lemon Squeezy's own checkout page. Your card, billing address and tax details go to Lemon Squeezy and never reach our servers; it handles them under its own privacy policy, and it keeps the receipts and invoices a seller is required to keep.

What we store is the plan you bought (Lifetime or Yearly), when it started, the order number, and, if it happens, that it was refunded or ended and when. For a checkout you start, we keep the plan, when you started it and whether it was completed. We do not store the amount you paid, anything about your card or a copy of your receipt.

Lemon Squeezy tells us about an order with a signed message from its server. We keep a fingerprint of that message (a hash), its type and the order number, so that the same message can never be applied twice; the message itself, which contains your email address, is not kept. If an order arrives for an email address that has no account here, an account is created for that address so the plan has somewhere to live; you can sign in with it and delete it like any other.

A started checkout and a completed purchase are counted as described in section 1: the row holds the plan and, if you arrived through a campaign link, its campaign labels — never your email address, a price or an amount. The labels are kept beside the checkout only until the order is confirmed and are then deleted.

Deleting your account deletes your plan record, your checkouts and any campaign labels waiting beside them. The order fingerprints and the note that an order was refunded are kept, because they are what stops an old message from granting access again; they hold an order number but no name, email address or amount. Lemon Squeezy keeps its own record of the order.

AWS exam packs are sold through Lemon Squeezy in the same way, and what this section says about the checkout, the order messages and the order fingerprints applies to them too. For a pack we store which pack it is, when you got it, the order number and, if it happens, that it was refunded and when; a checkout for a pack is kept like a checkout for a plan, with the pack in place of the plan. A started checkout and a completed purchase of a pack are counted as section 1 describes, with the pack's id in place of the plan and never a price. Deleting your account deletes your pack records with the rest.

5. Email and the newsletter

If you subscribe, we store your email address, the time you subscribed, and which form on the site you used. Newsletter emails are sent from our own domain and every one carries a one-click unsubscribe link and the standard unsubscribe headers. Unsubscribing adds your address to a suppression list so that it can never be mailed again, which is why that entry is kept.

We send the emails you asked for: sign-in links and, if you subscribed, the newsletter. Nothing else.

6. The mobile app

The BytePatterns app for Android and iOS collects no data. It has no account or sign-in, no analytics, no crash reporting, no advertising and no tracking, and it makes no network request of its own: every lesson, problem and animation is bundled inside the app. This is what the app declares in the App Store and on Google Play: no data collected, no tracking.

Your progress in the app (completed lessons, solved problems and the solutions you opened) is saved only on your device and is never sent anywhere. Settings → Reset clears it.

The app reaches the internet only when you tap a link to bytepatterns.com. The link opens in your device's browser, which the app cannot read, and from there this website's own rules above apply — including the campaign label some of those links carry, which tells us a visit came from the app and nothing about who you are. The app asks for no permissions on iOS; on Android it uses only the standard internet permission, for opening those links, and vibration, for answer feedback. There are no purchases in the app.

7. Where the data lives

The site runs on Cloudflare (hosting, database and email routing) and sends email through Amazon Web Services. Both act as processors on our behalf and see only what is needed to deliver a request or a message. There are no advertising networks, no social-media pixels and no third-party analytics scripts on this site. Payments are handled by Lemon Squeezy, as section 4 describes.

Our videos and posts on YouTube, TikTok and Instagram are governed by those platforms' own privacy policies; this policy covers bytepatterns.com only.

8. Retention

  • Analytics rows: kept as aggregate history; they contain no personal identifier.
  • Account data, including your plan and checkouts: until you delete the account.
  • Practice exam attempts on an account: the latest 200 per certification, until you delete the account.
  • Campaign labels on a checkout: until the order is confirmed or the account is deleted.
  • Order fingerprints and refund notes: kept; they hold an order number but no name, email address or amount.
  • Newsletter address: until you unsubscribe; the suppression entry is kept afterwards.
  • Sign-in links: single use, and expired shortly after they are sent.

9. Your rights

You can access, correct, export or delete what we hold about you. Account deletion and unsubscribing are self-service; for anything else, or if you are in a jurisdiction that grants you further rights (such as the GDPR or the CCPA), email hello@bytepatterns.com and we will answer within 30 days. This site is not directed at children under 13, and we do not knowingly collect data from them.

10. Changes

If this policy changes, the date at the top changes with it and the new text applies from that date. We do not change what we collect without changing this page.