This policy explains what qa.cafe processes when you browse the site, create an account, learn, use a code execution allowance, buy membership, contact us, or join the newsletter.
1. Who is responsible
qa.cafe operates this website and is responsible for the personal information it processes for the service. Email contact@qa.cafe for a privacy question or request.
2. Information you provide
qa.cafe processes information that you submit directly.
- Account information, including your Google account identifier, email address, display name, roles, and security state. Administrator accounts also have a password hash.
- Learning information, including your selected path, enrollments, lesson completion, plan usage, and certificates.
- Messages and form information that you send to qa.cafe, including your name, email address, selected topic, and message.
- Your email address when you join the Quality Signal newsletter.
- Questions, selected lesson text, and current playground code that you choose to submit to an AI lesson helper.
3. Information processed during use
The application and hosting environment can process request data needed for delivery, security, diagnostics, and abuse prevention. This data can include an IP address, request time, browser information, route, response status, and diagnostic records.
qa.cafe uses Simple Analytics and can use Plausible for aggregate website measurement. These services state that they do not set analytics cookies or create persistent visitor profiles. You can disable these scripts on the cookie settings page.
4. Membership and payment information
When you start paid checkout, qa.cafe sends your account email, display name, and a purchase reference to Dodo Payments.
qa.cafe uses Dodo Payments as the Merchant of Record for paid memberships. Dodo Payments will act as an independent data controller for checkout, payment processing, fraud prevention, regulatory checks, transaction taxes, refunds, and disputes.
qa.cafe receives limited order and subscription information needed to activate a plan, reconcile access, provide support, and keep financial records. qa.cafe will not receive a complete payment-card number or card security code.
Read the Dodo Payments privacy policy for its processing details.
5. Code practice data
SQL, Python, JavaScript, and TypeScript practice source, runtime state, files, output, and exercise results stay in temporary runtime memory. qa.cafe does not save that practice data. This data is removed when the relevant runtime ends or the page closes.
Before a code run, qa.cafe records the execution time and updates the account's monthly usage count. The quota request does not include source code, files, output, or an exercise result.
If you ask an AI lesson helper to review current playground code, that separate request sends the code to qa.cafe and the configured AI provider. The AI disclosure appears before you submit the request.
6. How qa.cafe uses information
- Provide accounts, courses, progress, certificates, support, and other requested features.
- Apply AI and code execution allowances.
- Deliver member benefits and reconcile subscription status.
- Secure the service, prevent fraud and abuse, diagnose failures, and protect users.
- Respond to contact messages, membership support, and privacy requests.
- Send the Quality Signal when you request it.
- Measure aggregate use and improve public content.
- Meet legal, accounting, tax-support, and dispute obligations.
- Enforce the terms of service.
7. Legal bases
Where law requires a legal basis, qa.cafe uses the basis that fits the activity. These bases can include performing a contract, taking requested steps before a contract, legitimate interests, consent, and legal obligations.
Contract steps support account access, membership delivery, and payment support. Legitimate interests include security, reliability, quota enforcement, fraud prevention, and proportionate product improvement. Consent supports optional analytics and newsletter activity where required.
8. Service providers and disclosures
qa.cafe can give limited information to providers that support authentication, hosting, databases, email, analytics, security, and AI features. These providers include Google for sign-in, OpenAI for requested AI assistance, and Simple Analytics or Plausible for enabled aggregate analytics.
Dodo Payments processes buyer and transaction information as the Merchant of Record. It can use payment, fraud, compliance, tax, and infrastructure providers described in its privacy information.
qa.cafe can also disclose information when law requires it, when necessary to protect legal rights, or during a business reorganization. qa.cafe does not sell personal information or use it for behavioral advertising.
9. Public certificates
Certificate verification is public to anyone with the cryptographically random verification link. A verification page shows the recipient name, course, revision, issue date, and validity status. Search engines are instructed not to index these pages.
Issued certificate snapshots can remain separate from an account record to preserve credential integrity. Later account or course edits do not rewrite an issued certificate.
10. Retention
qa.cafe keeps information only while it supports the stated purpose, a legal duty, security, dispute handling, or credential integrity. Retention periods differ by record type.
- Account, learning, and current allowance records normally remain while the account is active.
- Contact messages and diagnostic records remain only as long as operationally necessary.
- Newsletter addresses remain until removal is requested or the list is retired.
- Certificate records can remain after account deletion to support public verification.
11. Your rights
Applicable law can give you rights to access, correct, delete, restrict, or receive personal information. You can also object to some processing, withdraw consent, or complain to a supervisory authority.
Email contact@qa.cafe for a request. qa.cafe can ask for information needed to verify your identity and protect the account.
12. Security and international processing
qa.cafe uses access controls, encrypted transport, protected authentication cookies, and other reasonable safeguards. No online service can guarantee absolute security.
Some providers can process data outside your country. Where required, qa.cafe uses suitable contractual or legal safeguards for that transfer.
13. Children
qa.cafe is designed for professional and adult learning. It is not directed to children under 16.
14. Changes and contact
qa.cafe can update this policy when the service or law changes. The version and date identify the current policy.
Email contact@qa.cafe or use the contact page.