Privacy policy
OpenREPL is a free, open-source service for running code in your browser. This page explains what data the service handles, why, and the choices you have.
What we collect and why
Code and files you work with
What you type in a terminal or run from the editor is sent to our servers so it can run in a sandboxed container. Files you create or upload are stored in your workspace (up to 50 MB).
- Guests: the workspace is deleted about 1 hour after your last visit.
- Signed-in users: your workspace is kept so it is there next time. Delete files from the Files panel whenever you like.
If the service runs on more than one server, your workspace may be copied between them so your files are there wherever your terminal runs.
Please don't paste passwords, keys or other secrets into the terminal, editor or Genie.
Account information
If you sign in, we use Google Firebase Authentication with Google, GitHub or email sign-in. We receive your name, email address, profile photo and a user ID, and keep them with your session so you stay signed in.
Cookies and browser storage
We set a signed session cookie that keeps you signed in and links you to your workspace, and a small counter cookie (Session-Counter) that tracks how many terminals you have open. Google Tag Manager and Google Analytics may set their own cookies (such as _ga) to recognise returning visitors. The page also saves a few preferences in your browser's local storage, such as the editor theme, whether the Files panel is open, and practice progress. If you're signed in, your practice questions and which ones you've finished are also saved with your account, so they follow you to other browsers.
Shared sessions
Share links work through Google Firebase Realtime Database. For a session, it holds the editor content, the language, the file tree and the terminal output, so that people with the link can follow along.
Code links
When you choose Share, then Create code link, a copy of the code in your editor (up to 64 KB) is stored on our server and you get a short link. Anyone who has the link can read that code. Code links are kept until we remove them, so don't create one for code that contains secrets. To prevent abuse we count how many links each IP address creates in a short time.
Genie, the AI helper
When you use Genie, your messages and the code in your editor are sent through our server to OpenAI to generate replies. Genie is optional; if you don't open it, nothing is sent to OpenAI.
Language requests and feedback
If you send a request or feedback, we store the name, email and message you enter so we can read and reply to it. Google reCAPTCHA checks the form for spam.
Server logs and usage statistics
Our servers log each request with your IP address, the page requested and the time, and the servers' own commands. We use the logs to run and secure the service. The people who run OpenREPL can read them in an administration dashboard, where keys, tokens, cookies and full email addresses are masked. Logs rotate and are kept for up to 30 days.
To see how the service is used, we keep daily totals of how many terminals were started and in which language. To count each visitor once a day, we use a keyed hash of your account or IP address that changes every day; it is used only for that count. These totals are kept for 60 days.
Analytics and third-party content
We use Google Tag Manager to load analytics tags (such as Google Analytics), which record pages visited, device and browser type. Fonts come from Google Fonts and some scripts from public CDNs (cdnjs, jsDelivr and unpkg). These providers receive your IP address when your browser loads their files.
Services we rely on
- Google (Firebase Authentication and Realtime Database, Tag Manager and Analytics, reCAPTCHA, Fonts): Google Privacy Policy
- OpenAI (Genie replies): OpenAI Privacy Policy
- GitHub (if you sign in with GitHub): GitHub Privacy Statement
We do not sell your personal information.
How long we keep data
- Guest workspaces: about 1 hour after your last visit.
- Account and session data, and signed-in workspaces: until you ask us to delete them.
- Code links: until we remove them. Ask us to delete one (see Contact).
- Server logs: up to 30 days. Daily usage totals: 60 days.
- Requests and feedback: until we have dealt with them.
Your choices
- Use OpenREPL as a guest without an account.
- Don't open Genie if you don't want your code sent to OpenAI.
- Block or clear cookies and site data in your browser. Signing in needs the session cookie.
- Ask us to delete your account data or workspace (see Contact).
Security
Each session runs in its own container with limits on memory and disk. No online service is perfectly secure, so avoid storing sensitive data in OpenREPL.
Children
OpenREPL is not directed at children under 13, and we do not knowingly collect their personal information.
Changes to this policy
We may update this page. The date at the top shows the latest version.
Contact
Questions or deletion requests: contact the maintainer through the OpenREPL project on GitHub, or use the request form at the bottom of the home page.