Privacy Policy
Last updated: 20 April 2026
1. Who We Are
Be Bitwise is a computing and cybersecurity education platform operated by Be Bitwise Limited, a company incorporated in England and Wales (company number 17165156) with its registered office at 66 Paul Street, London, England, United Kingdom, EC2A 4NA. References to “we”, “us”, or “our” throughout this policy refer to Be Bitwise Limited, which is the data controller for your personal data under UK GDPR.
If you have any questions about this policy or how your data is handled, please contact us at privacy@bebitwise.io.
2. Data We Collect
A free account is required to access educational content on Be Bitwise. We collect the minimum amount of personal data necessary to provide the service. The categories of data we collect are as follows:
- Account information (required). When you create an account, we collect your e-mail address. An account is required to access the platform’s educational content. You may optionally provide a display name in your profile settings.
- Learning progress. We store records of which modules you have completed, checkpoint results, quiz scores, and code challenge attempts so that your progress is preserved across sessions and devices.
- Notes. If you use the Notes feature, the content of your notes is stored on our servers and associated with your account.
- Certificates. When you earn a completion certificate, we store your display name, the module or pathway completed, and the date of completion in order to generate and verify the certificate.
- Technical data. We may collect IP addresses, browser type, and device information for security and rate-limiting purposes. This data is not used for advertising or profiling.
3. How We Use Your Data
We use your personal data to:
- Create and manage your account and authenticate you when you sign in.
- Save and display your learning progress, notes, and certificates.
- Send transactional e-mails such as account verification, password reset, and magic-link sign-in links.
- Send platform notifications, such as updates about your learning progress, new content availability, or service announcements, where you have opted in to receive them.
- Detect and prevent abuse, fraud, and security threats.
- Comply with our legal obligations.
We do not sell your personal data. We do not use your data for advertising purposes. We do not share your data with third parties except as described in this policy.
4. Legal Basis for Processing
Under UK GDPR and the UK Data Protection Act 2018, we rely on the following legal bases for processing your personal data:
- Contract. Processing your e-mail address and learning data is necessary to provide you with the Be Bitwise service in accordance with our Terms of Service.
- Legitimate interests. We process technical data such as IP addresses to protect the security and integrity of the platform.
- Legal obligation. We may process data where required to comply with applicable law.
5. Data Processors and Sub-processors
Be Bitwise uses a small number of third-party services to operate the platform. Each acts as a data processor on our behalf, processing your data only on our instructions and in accordance with a data processing agreement.
Supabase. Supabase provides our backend database and authentication services. It stores account data, learning progress, notes, and certificates in secure, cloud-hosted infrastructure. For details of Supabase’s own data practices, please refer to their Privacy Policy.
Resend. Resend handles transactional and platform e-mail delivery on our behalf. It processes your e-mail address solely for the purpose of delivering e-mails such as account verification, sign-in links, and platform notifications. For details of Resend’s data practices, please refer to their Privacy Policy.
Cloudflare. Cloudflare provides infrastructure services including content delivery (CDN), DNS resolution, edge computing, bot-detection (Turnstile), and key-value storage for our short-link service. As part of delivering the platform, Cloudflare processes technical data such as IP addresses and request metadata. This processing is necessary for performance, reliability, and security. For details of Cloudflare’s data practices, please refer to their Privacy Policy.
Stripe. Stripe processes payments and manages subscriptions where you choose to purchase an optional paid feature. Stripe collects your e-mail address, billing address, and payment-method details directly; we never handle or store your full card details. For details of Stripe’s data practices, please refer to their Privacy Policy.
Judge0 (via RapidAPI). When you run code in a coding exercise, the source code you submit is sent to Judge0 — a sandboxed remote-execution service accessed through RapidAPI — so that it can be compiled and executed. The execution result is returned to you and is not stored on our servers. For details of RapidAPI’s data practices, please refer to their Privacy Policy.
Fly.io. Fly.io hosts the virtual machines that power our interactive labs, practice sandboxes, debugger, and compiler. When you start a lab or sandbox session, your user identifier and session metadata are provided to Fly.io so that a machine can be allocated to you. For details of Fly.io’s data practices, please refer to their Privacy Policy.
Have I Been Pwned. When you create an account or change your password, we check the password against the Have I Been Pwned Pwned Passwords database to prevent you from choosing a password that has appeared in a known breach. The check uses k-anonymity: we only send the first five characters of the SHA-1 hash of your password, never your password itself, your e-mail, or any other identifier. For details, please refer to the Have I Been Pwned Privacy Policy.
Google Fonts. Our e-mail templates reference web fonts hosted by Google Fonts. When your e-mail client renders one of our e-mails, your IP address may be disclosed to Google in order to fetch the font file. For details, please refer to Google’s Privacy Policy.
We will update this list when we engage additional sub-processors. Material changes will be noted at the top of this page under “Last updated”.
6. International Data Transfers
Be Bitwise is established in the United Kingdom and your personal data is primarily processed within the United Kingdom and the European Economic Area (EEA). However, some of the sub-processors listed above are headquartered outside the UK — including Stripe, Resend, Judge0 / RapidAPI, Have I Been Pwned, and Google Fonts, which are based in the United States — and a small portion of your data may be transferred to or processed in those jurisdictions as part of delivering the service.
Where personal data is transferred outside the United Kingdom to a country that is not the subject of a UK adequacy decision, we rely on the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), as appropriate, to provide an equivalent level of protection as required by UK GDPR. These clauses are incorporated in our data processing agreements with each relevant sub-processor.
You may request a copy of the transfer mechanism in place for any specific sub-processor by contacting us at privacy@bebitwise.io.
7. Cookies
We use a small number of cookies that are strictly necessary for the service to function, to authenticate you, and to protect the site from automated abuse. We do not set any cookies for advertising, tracking, or third-party analytics.
- Authentication cookies. Set by Supabase (cookie names beginning with
sb-) to maintain your signed-in session. These are HTTP-only, secure, and session- scoped or short-lived; they are deleted when you sign out. - Cloudflare bot-management and challenge cookies. Cloudflare sits in front of our platform and sets a small number of cookies to distinguish legitimate users from automated traffic and to remember that you have passed a security challenge. These are strictly necessary for security and fraud prevention. The cookies we may see from Cloudflare are:
__cf_bm— Cloudflare Bot Management. Rolling session cookie (typically 30 minutes) used to identify automated traffic.cf_clearance— issued after you successfully complete a Cloudflare security challenge (for example, on sign-up or sign-in). It tells Cloudflare that subsequent requests from your browser do not need to be re-challenged. Lifetime is set by Cloudflare and is typically up to 30 days.cf_chl_*(e.g.cf_chl_prog,cf_chl_seq) — transient cookies used only while a challenge is being solved, and discarded once the challenge is complete.
- Preference storage. We store your light/dark theme preference in
localStorageon your device. This is not a cookie and is not sent with any network request.
8. Data Retention
We retain your account data for as long as your account remains active. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain it for a longer period.
Anonymised or aggregated data (for example, aggregate counts of module completions) may be retained indefinitely as it does not identify you.
9. Your Rights
Under UK GDPR you have the following rights regarding your personal data:
- Access. You have the right to request a copy of the personal data we hold about you.
- Rectification. You have the right to ask us to correct inaccurate or incomplete data.
- Erasure. You have the right to request that we delete your personal data (“the right to be forgotten”).
- Restriction. You have the right to ask us to restrict processing of your data in certain circumstances.
- Portability. You have the right to receive your data in a structured, commonly used, machine-readable format.
- Objection. You have the right to object to processing based on legitimate interests.
You can delete your account yourself at any time from your profile settings (“Delete Account”). Deletion is immediate and removes your account data from our systems within 30 days. Any active subscription is cancelled immediately as part of this process.
To exercise any other right, please contact us at privacy@bebitwise.io. We will respond within one calendar month.
You also have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk.
10. Data Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. These measures include encrypted connections (HTTPS/TLS), hashed password storage via Supabase Auth, and access controls limiting who can access production data.
No method of transmission over the internet is completely secure. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately at security@bebitwise.io.
11. Children
Be Bitwise is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review this policy periodically. Continued use of the service after a change constitutes your acceptance of the updated policy.
13. Contact Us
For any questions or concerns regarding this Privacy Policy or the handling of your personal data, please contact:
Be Bitwise Limited
Company number 17165156 (England and Wales)
66 Paul Street, London, England, United Kingdom, EC2A 4NA
E-mail: privacy@bebitwise.io