Privacy Policy
Last updated: August 20, 2026
Introduction
LLM Primer is an educational website about machine learning and large language models. You can read the public curriculum without creating an account. This policy explains what information we process, why we use it, and what choices you have. In this policy, we means LLM Primer.
Information We Process
Website Delivery, Security, and Updates
- Update-list data: the email address you submit, signup source, subscription status, IP address, user agent, and creation and update times.
- Communications: your email address and any information you include when you contact us.
- Technical and security data: request information such as IP address, user agent, timestamps, response status, and security or rate-limit signals needed to deliver and protect the service.
We use Cloudflare Web Analytics for aggregate traffic and real-user performance measurements, including Core Web Vitals. Cloudflare states that Web Analytics does not collect or use visitors' personal data. It does not use cookies or local storage for these measurements.
If you opt in through the optional analytics notice, we also use Google Analytics to measure aggregate page visits. We configure it without advertising storage, advertising personalization, Google Signals, or account identifiers. We do not send notes, answers, or learning events to Google Analytics. The Google tag is not loaded before that choice.
Accounts and Sign-In
Signing in with Google or GitHub gives us a provider-specific account identifier and the identity fields made available through that sign-in. For Google, we request OpenID identity and email. For GitHub, we receive your public profile identifier, username, and any public email returned by GitHub. We do not request access to Gmail, GitHub repositories, or private GitHub email addresses. The temporary GitHub access token is revoked after the identity check.
Account records can also include your optional private account name, generated learning pseudonym and handle, assigned roles, subject-access entitlements, account creation and sign-in times, and active or revoked browser sessions. A session record includes the browser user agent; the authentication cookie contains a random session token rather than your email address.
Learning and Study Data
When you are signed in, we synchronize learning records across your devices. Depending on the feature you use, these records can include:
- opened, read, done, undone, and scheduled-review states for lessons;
- exercise status, a limited attempt count, and the latest checked text or selected choice;
- Browser Python run or completion status and settings you save in interactive diagrams;
- highlights, text anchors, colors, visibility settings, private notes, and related timestamps;
- study-session names, descriptions, status, chapter scope, activity, and completion times;
- an optional learning-challenge length, note, dates, status, and activity summary;
- private challenge check-ins about what you learned and what you plan to do next;
- bounded project-workspace files, immutable revision metadata, byte counts, and synchronization times; and
- records used to apply resets and keep changes consistent across devices.
Synchronized exercise records do not keep a complete history of every answer. Editable files in a project workspace can synchronize when the interface says they are synchronized. Ordinary lesson editors do not synchronize Python source code, program output, errors, tracebacks, plots, or temporary editor state. Some information remains in your browser as described on the Local Data page.
Public Reader Profiles
Reader profiles are private unless you publish them. A published profile can show your generated handle and avatar, display name, short introduction, and join month. Learning activity remains off unless you enable it separately. If enabled, the profile can show daily completion counts, totals, streaks, milestones, and your active challenge and its note. Challenge check-ins remain private. It does not show lesson names, answers, failed attempts, notes, sessions, email, or exact event times.
Reports and Editorial Access
A content report can include the page, selected quotation, category, message, status, resolution message, and timestamps. Reviewers may add private editorial notes and assignment or status history. Authorized administrators can see account identifiers, private account names, roles, and access entitlements where needed to operate the service.
Private Project Workspace Administration
Administrators can see project-storage metadata such as the owning account, project, file and revision counts, byte counts, and last update. This routine view does not open project files. An owner may inspect the current private files only for a specific safety, security, abuse, or support need after a recent sign-in and a written reason. A successful inspection records the owner, affected account, workspace, revision, reason, and time. The inspection log does not copy file content or private storage keys.
Learning Hall
The Learning Hall is optional. If you join it, your learning pseudonym, handle, active-day count, lessons completed, and exercises solved can appear publicly for the selected time period. Your private account name, provider username, and email address are not shown there. Leaving the Hall removes you from its public results; the underlying learning records remain part of your account unless you delete them or your account.
How We Use Information
- To provide sign-in, accounts, and cross-device synchronization.
- To show your progress, notes, study sessions, and public profile or Hall activity that you choose to share.
- To receive and resolve content reports.
- To send updates that you request and respond to messages.
- To operate, secure, diagnose, and improve the service.
- With your optional analytics choice, to measure aggregate page visits.
- To enforce access permissions and prevent abuse.
We do not sell or rent personal information, use it for third-party advertising, or share it with third parties for their own marketing.
Legal Bases Where Applicable
Where the law requires a legal basis, we rely on your request or consent for update subscriptions, optional Google Analytics, optional public Hall participation, and other choices you make. Account and synchronization data is processed to provide the service you request. Technical and security data is processed for the legitimate interests of operating, protecting, and diagnosing the service, subject to your rights under applicable law.
Service Providers and Data Location
Cloudflare delivers the website and provides Workers, D1 database storage, private R2 object storage, rate limiting, security services, and Web Analytics. Google processes optional Analytics measurement when you allow it and processes Google sign-in requests; GitHub processes GitHub sign-in requests. These providers may process information in countries other than your own, subject to their safeguards and applicable law.
Cloudflare D1 chooses a database location when a database is created unless a jurisdiction restriction is configured. Requests can also be processed through Cloudflare's global network. We do not promise that account data will remain in your country.
Retention and Deletion
- Update-list records are kept while the subscription is active or until deletion is requested.
- Account, profile, learning, annotation, report, study-session, role, entitlement, and project-workspace records are normally kept while the account is active.
- Project-workspace inspection records can remain after the workspace or account is deleted when needed for security, abuse prevention, or dispute resolution. They contain identifiers, reason, revision, and time, not the inspected files.
- Authentication sessions expire after 30 days. Revoked session records and short-lived synchronization records may remain for security, replay protection, and reliable synchronization.
- We routinely remove the limited operational logs we store after 30 days. Cloudflare may retain its own infrastructure records under its policies and service configuration.
- Correspondence is kept as long as needed to answer the request and maintain necessary legal or operational records.
You can export or delete your account from the Account page. Account deletion removes account-linked learning records from the active database, except information that must be kept for legal, security, or dispute-resolution reasons. It does not unsubscribe an independently requested update-list subscription.
Security
We use safeguards including encrypted connections, secure cookie settings, hashed session secrets, access controls, rate limits, and restricted infrastructure access. No online service can guarantee complete security. Do not place passwords, authentication codes, payment details, private keys, or other sensitive information in notes, reports, project files, or messages.
Your Rights and Choices
Depending on applicable law, you may have the right to:
- access, correct, or receive a copy of your personal information;
- request deletion or restriction of processing;
- object to processing in applicable circumstances;
- withdraw consent and unsubscribe from updates; and
- complain to the relevant data-protection authority.
Account export and deletion controls are available on the Account page. You can change optional analytics consent on the Cookie Policy. You can leave the Learning Hall without deleting your account. For other requests, contact us; we may need to verify that the request concerns you.
Children's Privacy
Public lessons can be read without an account. Accounts are not intended for children under 13. Some countries set a higher age for independent consent. We do not currently provide a process for verifying parental or guardian consent. Do not create an account if the law where you live requires that verification. If you believe a child provided personal information without the required permission, contact us so that we can review and delete it.
Cookies and Local Storage
We use cookies for sign-in security and browser storage for learning progress, notes, interface preferences, synchronization queues, and an optional analytics preference. Cloudflare Web Analytics does not use cookies or local storage for its measurements. Google Analytics can use cookies only after you explicitly allow it. Read the Cookie Policy and Local Data page for details and controls.
Changes to This Policy
We may update this policy as the service changes. The date above shows the latest revision. If a change requires consent, we will ask for it rather than treating continued browsing as consent.
Contact Us
For privacy questions, requests, deletion, or update-list withdrawal, email contact@llmprimer.com.