# Python Quest: how your work is handled

This document describes the public browser edition on Cloudflare static hosting (Pages or Workers Static Assets). It describes the app's behavior and the host's role separately.

Your Python code is checked inside your browser. The public edition has no accounts, passwords, access tokens, authentication cookies, or server endpoint that receives code for execution. There is therefore no public access-token lifetime to manage. Each learner has their own browser session.

By default, your code, drafts, learning progress, choices, and experiments stay in the current tab's memory. Reloading or closing the tab loses this temporary session. The first-visit screen explains this choice, and **Privacy & backups** remains available before you leave. Choosing a path, skipping a lesson, making a bookmark, or using the playground does not enable device saving.

- **Remember on this device** is optional. Enabling it saves lesson code and drafts, completion/attempt/lesson records, skipped and demonstrated skills, bookmarks, checkpoint results, review counts and their last-review time, separate review drafts, your current lesson, learning-path and editor preferences, and playground code, input, and trace preference. It uses this browser's `localStorage`, under the single key `pyquest-public-v1`. A later visit restores that saved choice. No tokens are stored there. Anyone using the same browser profile may be able to read this work; leave remembering off on a shared device.
- **Export backup** downloads readable JSON containing the same learning data. It is not encrypted; code and playground input can contain anything you typed. Keep it somewhere private. Generated execution traces and console output are not included in the backup. The app cannot delete copies you download, email, or put in cloud storage.
- **Import backup** reads a file on your device. It validates the file before asking to replace current work, and does not upload the contents or change your device-saving choice. Importing into a temporary session keeps it temporary; if remembering was already enabled, the restored work is saved under that existing choice. Backups are limited to 5 MiB; individual Python files to 50,000 bytes and playground input to 12,000 UTF-8 bytes.
- **Turn remembering off** removes the app's saved storage key while keeping your current tab's work. **Erase progress** also resets the current session, including preferences, bookmarks, reviews, and playground content. These actions leave other websites' data and downloaded files alone. If the browser blocks saving or deletion, the app displays a warning. A deletion warning means an older saved copy may remain; use your browser's site-data settings to remove it.

The current backup format is version 2. The app still accepts valid version 1 public backups and previously remembered browser data, preserving their code and completion records while adding defaults for new learning tools. The storage key keeps its older `v1` name so an upgrade can find your existing opt-in data. Migration does not create an account or grant new storage permission. Unsupported or invalid backups are rejected before replacement; an unreadable saved record is left intact while the tab starts a temporary session with a warning.

Python Quest includes no analytics, advertising, or automatic sharing of learner code with AI assistants. It does not request camera, microphone, or location access. Browser extensions, your editor, and services you deliberately use to share files have their own behavior.

Your browser still requests the website, Python runtime, and library files. On a Cloudflare-hosted deployment, Cloudflare receives normal connection information, such as IP address, request time, and requested asset paths. Different libraries require different asset downloads. These app requests do not include your puzzle source, backups, or learning progress. Cloudflare processes traffic and security information under its own [Privacy Policy](https://www.cloudflare.com/privacypolicy/), including the sections about end users and network data. This app cannot erase the provider's records and does not promise anonymous connections, zero host logs, or a particular retention period.

The deployment does not add visitor analytics, an application server, a database, or code-upload endpoints. Provider-level operational statistics and security processing can still occur. Cloudflare also supplies Network Error Logging headers, which supported browsers may use to report connection failures to Cloudflare. Optional hosting analytics or injected scripts must remain disabled to preserve this description. The site operator must check actual hosted responses and update this notice if those settings change. When using the local preview at `127.0.0.1`, requests go to the local preview server instead of Cloudflare.

Device saving belongs to one browser profile and website address. Local preview, a staging site, the final `workers.dev` address, and a later custom domain each have separate storage. Progress does not automatically move between them. Export a backup from the old address and import it at the new one if you want to continue there.

Public runtime files may remain in the browser's ordinary HTTP cache. They contain Python and course dependencies, not your code or progress. Clearing learning progress does not need to clear that public-file cache. Documentation links open other websites, which have their own privacy practices.

Execution uses a temporary virtual filesystem inside an isolated browser worker. A graded run receives only the current source and public test data; a playground run receives its current source and supplied input. Neither receives other saved lessons, bookmarks, or browser storage. File changes made by an exercise or experiment disappear after its run. Requests lessons use offline sample responses; FastAPI lessons use requests inside the Python process. Exercises cannot make real network requests through this sandbox. Optional traces show bounded snapshots of ordinary variables inside the current tab; they are not uploaded.

The editor's highlighting and indentation assistance run locally, without a third-party completion service. Choosing a `.py` file reads it on your device; the site cannot automatically watch later changes in Cursor or VS Code. **Download complete IDE project** downloads public starter material, test data, and a checker. The pack does not contain your browser work, saved progress, or authentication information. Use **Download .py** or a backup separately to keep your own code. If you execute a downloaded project in an editor, it runs with your computer's permissions and is outside the browser sandbox.

Keep your browser updated. Browser isolation and time limits reduce risk, but do not provide a strict memory quota or a guarantee against every browser or dependency defect. The current implementation details and release requirements are in [PUBLIC_RELEASE.md](PUBLIC_RELEASE.md).

The original personal game remains separate. Its `app.py` server binds to your own computer, uses a local control token, and keeps files on that computer. That token is not public account authentication. Personal puzzle files and existing progress are not copied into the public build or automatically migrated.

The site owner's Cloudflare account is also separate from learners. Publishing requires the owner to authenticate with Cloudflare; deployment-tool credentials stay outside the public build and must never be added to the site, a backup, or the source repository. Learners do not need a Cloudflare account. The owner's setup instructions are in `CLOUDFLARE_SETUP.md` in the source project.
