Privacy policy
This explains what Pebble Labs collects about you, why, and who else touches it. The controller is [TO BE COMPLETED], [TO BE COMPLETED].
What we collect
From signing in
You sign in with a Google account, a GitHub account, or a single-use link we send to your email address. Google and GitHub give us your name, email address, and profile picture, and we store those along with an account record linking you to that identity. We never see your password for either.
If you sign in by email, we store your email address, a hash of the link’s secret rather than the secret itself, a hash of the value tying it to your browser, and the IP address the request came from. The IP is what stops someone requesting links for an address they do not own. A link expires in minutes and is spent on first use, and we delete the record once it is too old to count against those limits. You can change the email address on your account, and we confirm the new one the same way, with a code you type in rather than a link.
From paying
Stripe handles payment. Card details go to Stripe and never reach our servers. We store your Stripe customer reference, which plan you are on, whether the subscription is active, and when the current period ends. That is what the app checks to decide whether to let you deploy a paid lab.
From using the platform
- Which courses you enrolled in and which lessons you completed.
- Answers you submit to lab tasks and flag questions, how many attempts you made, and when you solved them. A correct answer is kept so the page can show it back to you later. Only you and an administrator can see it.
- Lab sessions: which lab, its status, the gateway address, when it was last active, and the credit ledger for labs that meter usage.
- A VPN identity: a certificate authority and certificates issued to you, plus a random hostname label used to route your VPN connection to your current lab gateway.
From lab infrastructure
Network flow records from your lab gateway tell us whether a lab is being used, so an idle one can be suspended instead of billing you for nothing. We look at whether traffic happened and how much, not at what was in it.
Labs that give a machine access to a hosted AI model produce invocation records used to meter usage. Those records carry token counts and the identity of the calling machine. Logging of prompts, completions, images, and embeddings is switched off at the source, so we do not receive what you asked the model or what it replied.
Why we hold it
To run your account and your labs, which is performance of our contract with you. To take payment and keep records of it, which the law requires. To keep the platform working and to investigate abuse, which is our legitimate interest in running a service that other customers can rely on.
We do not sell personal data, we do not share it with advertisers, and we do not use it to train models.
Who processes it for us
Running the platform means these companies handle some of your data:
- Google and GitHub, for sign-in.
- Resend, which delivers our sign-in links and account emails.
- Stripe, for payments and subscription billing.
- Vercel, which hosts the web application.
- Neon, which hosts the database.
- Amazon Web Services, which runs the lab environments, the VPN gateways, the provisioning system, file storage, and the DNS records that point your VPN at your gateway.
- Cloudflare, where course video is hosted.
Our infrastructure runs in the United States. If you are in the UK or the EEA, that means your data is transferred there.
How long we keep it
Account and progress data stays while your account is open. Lab machines and their contents are destroyed when a lab is torn down, which happens on request or automatically once a lab has been left long enough. Payment records are kept for as long as tax and accounting law requires, which is longer than your account may last. Close your account and we delete the rest, other than what we must keep.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, or object to us holding it. Write to [TO BE COMPLETED] and we will respond within 30 days. If you are in the UK or the EEA and you think we have handled this badly, you can complain to your data protection authority.
Two things are worth knowing before you ask for deletion. Deleting your account destroys your lab progress and your solved answers, and we cannot restore them. And we cannot delete payment records we are required to keep.
Cookies
We set a session cookie so you stay signed in. Signing in sets three short-lived ones alongside it: a token protecting the sign-in form against forgery, the page to return you to once you are through, and a random value tying your sign-in link to this browser, which is what stops the link working anywhere else. Changing your email address sets one more of that last kind, for the confirmation code. Those are the only cookies the application sets. There is no advertising or analytics tracking on the site.
Children
The service is for adults. Anyone under 18 needs a parent or guardian to accept the user agreement for them and to take responsibility for their use of it. If we learn that an account belongs to a child with no such arrangement, we close it and delete the data.
Changes
If this policy changes in a way that affects you, we will tell you by email or in the app, and the date at the bottom of this page will move.
Contact
Privacy questions go to [TO BE COMPLETED]. Anything else goes to pebblepwns@gmail.com.