privacy
Privacy policy
Last updated
1.Who we are
ByteMonk Academy runs this site, bytemonk.io, and the courses, practice tools and assessments on it. When this policy says “we”, it means ByteMonk Academy. The person responsible for how your data is handled can be reached through the contact page or at himalay@bytemonk.io.
The short version: we keep what the site needs to teach you and to bill you, we send it to a small number of providers who do specific jobs for us, we do not sell it, and we do not run advertising trackers.
2.What we collect
Your account. An email address and a password, or, if you sign in with Google or GitHub, the email address, name and profile picture that provider shares with us together with an identifier for your account there. We never see your Google or GitHub password. A display name you set is stored with your profile.
Your learning. Which lessons you have completed, your quiz attempts and scores, what you liked, and everything you submit to the practice tools: system-design whiteboards and written answers, the questions you ask during a practice session or to the tutor, and the solutions you submit to coding problems. This is what lets the site remember where you are and show you how you did.
Your purchases. Which plan you bought, when, the amount and currency, its status, and the reference numbers our payment providers give us for the payment or subscription. We never receive or store card numbers, UPI ids or bank details; those go to the provider directly (section 5).
What you write to us. Messages sent through the contact form, feedback submitted through the feedback page (with your email only if you chose to give it), and your email address if you subscribe to the newsletter.
Assessments. If you sit a timed assessment run with a university or an employer (a “campus drive”), we collect the name, roll or entry number and institute email you enter when you join, your submissions, and the verdicts and scores they receive.
Mock interviews. If you take part in a mock interview, the whiteboard from that session, the interviewer’s notes and the feedback written for you are stored so you can come back to them.
Technical records. Our servers keep short-lived logs that include your IP address and the pages requested, used to rate-limit forms and APIs and to investigate abuse. Page views are counted by an analytics tool configured not to identify you (section 6).
3.What we do not collect
- No advertising or cross-site tracking of any kind.
- No card, UPI or bank details. Payment pages belong to Razorpay or Stripe, not to us.
- No analytics cookies and nothing analytics-related stored in your browser (section 6).
- No location beyond what an IP address implies, and we do not look that up.
- No data bought from, or sold to, anyone.
4.How we use it
- To run the site: sign you in, remember your progress, grade your quizzes and problems, and show you your own work.
- To bill you and to know which courses your account may open.
- To send the emails the service needs: confirming your address, resetting your password, a receipt or a note about your access. The newsletter is separate and goes only to people who subscribed; every issue carries an unsubscribe link.
- To reply when you write to us.
- To run an assessment on behalf of the institution that organised it, and to give that institution the results (section 7).
- To keep the service working and safe: rate limits, abuse investigation, debugging.
- To improve the courses and the automated grading, using submissions in aggregate or with anything identifying removed.
5.AI grading and the tutor
The practice tools grade system-design answers, answer clarifying questions, and power the tutor with a large language model. When you use them, the answer or whiteboard you submit, your question, and the lesson context it relates to are sent to Anthropic, whose model produces the evaluation or reply. Coding submissions are compiled and run by Judge0, a code-execution service, against the problem’s tests.
Both are processors acting on our instructions under their commercial API terms, which do not allow them to use what we send to train their models. Please keep personal details, passwords and secrets out of whiteboards, code and tutor questions all the same: nothing in a practice session needs them.
The model’s verdicts are automated and can be wrong. They are practice feedback, not a judgement about you, and for assessments a person reviews before anything is reported (section 7).
7.Assessments and campus drives
A campus drive is an assessment we run for a university or an employer. The organiser sets who may sit it and what it is for. When you join with a code, you are telling us it is fine to give that organiser your name, the roll or entry number you enter, your email address, your submissions, the verdicts, your scores, and a record of when you started and finished. The organiser is responsible for what it does with them afterwards; ask them about their retention and their decisions.
Grading of coding problems in an assessment is automatic. The system-design problem is scored by the model and marked by a person before results are reported.
9.How long we keep it
- Account and learning data: for as long as your account exists.
- Purchase records: as long as accounting and tax rules require after the purchase, even if the account is later deleted.
- Assessment records: for the organiser’s process, and as our own record of the drive.
- Contact messages and feedback: until they are dealt with and for a reasonable time after, so a follow-up has its context.
- Newsletter address: until you unsubscribe.
- Server logs: briefly, on a rolling basis.
10.Your choices and rights
You can see and change your profile from your account page, and unsubscribe from the newsletter with the link in any issue or on the unsubscribe page.
For anything else, including a copy of what we hold about you, a correction, or deleting your account and its learning data, write to us through the contact page from the address on the account. We will confirm it is you and act on it without undue delay. Purchase records we are required to keep are the one exception to deletion. Depending on where you live, you may have further rights under local law and the right to complain to a data-protection authority; we would rather hear from you first.
11.Security
Everything travels over TLS. Passwords are hashed by our authentication provider and are never visible to us. Database access is restricted row by row so that one member cannot read another member’s data, and the keys that can bypass those rules live only on the server. Payment details never reach us at all.
No system is perfect. If you find a weakness, please tell us through the contact page before telling anyone else, and give us a chance to fix it.
12.Children
The site is for people who are at least 16, or the age at which someone in your country may agree to a service like this on their own. We do not knowingly keep data about anyone younger; if you believe we have, write to us and we will remove it.
13.Changes to this policy
When the site starts doing something new with your data, this page changes in the same release, and the date at the top moves. A change that matters to existing members is announced by email or on the site before it takes effect.
Read alongside the terms of service. Questions about either go through the contact page.