Privacy policy

What we collect and why

Code and files you work with

What you type in a terminal or run from the editor is sent to our servers so it can run in a sandboxed container. Files you create or upload are stored in your workspace (up to 50 MB).

If the service runs on more than one server, your workspace may be copied between them so your files are there wherever your terminal runs.

Please don't paste passwords, keys or other secrets into the terminal, editor or Genie.

Account information

If you sign in, we use Google Firebase Authentication with Google, GitHub or email sign-in. We receive your name, email address, profile photo and a user ID, and keep them with your session so you stay signed in.

Cookies and browser storage

We set a signed session cookie that keeps you signed in and links you to your workspace, and a small counter cookie (Session-Counter) that tracks how many terminals you have open. Google Tag Manager and Google Analytics may set their own cookies (such as _ga) to recognise returning visitors. The page also saves a few preferences in your browser's local storage, such as the editor theme, whether the Files panel is open, and practice progress. If you're signed in, your practice questions and which ones you've finished are also saved with your account, so they follow you to other browsers.

Shared sessions

Share links work through Google Firebase Realtime Database. For a session, it holds the editor content, the language, the file tree and the terminal output, so that people with the link can follow along.

Code links

When you choose Share, then Create code link, a copy of the code in your editor (up to 64 KB) is stored on our server and you get a short link. Anyone who has the link can read that code. Code links are kept until we remove them, so don't create one for code that contains secrets. To prevent abuse we count how many links each IP address creates in a short time.

Genie, the AI helper

When you use Genie, your messages and the code in your editor are sent through our server to OpenAI to generate replies. Genie is optional; if you don't open it, nothing is sent to OpenAI.

Language requests and feedback

If you send a request or feedback, we store the name, email and message you enter so we can read and reply to it. Google reCAPTCHA checks the form for spam.

Server logs and usage statistics

Our servers log each request with your IP address, the page requested and the time, and the servers' own commands. We use the logs to run and secure the service. The people who run OpenREPL can read them in an administration dashboard, where keys, tokens, cookies and full email addresses are masked. Logs rotate and are kept for up to 30 days.

To see how the service is used, we keep daily totals of how many terminals were started and in which language. To count each visitor once a day, we use a keyed hash of your account or IP address that changes every day; it is used only for that count. These totals are kept for 60 days.

Analytics and third-party content

We use Google Tag Manager to load analytics tags (such as Google Analytics), which record pages visited, device and browser type. Fonts come from Google Fonts and some scripts from public CDNs (cdnjs, jsDelivr and unpkg). These providers receive your IP address when your browser loads their files.

Services we rely on

We do not sell your personal information.

How long we keep data

Your choices

Security

Each session runs in its own container with limits on memory and disk. No online service is perfectly secure, so avoid storing sensitive data in OpenREPL.

Children

OpenREPL is not directed at children under 13, and we do not knowingly collect their personal information.

Changes to this policy

We may update this page. The date at the top shows the latest version.

Contact

Questions or deletion requests: contact the maintainer through the OpenREPL project on GitHub, or use the request form at the bottom of the home page.