Privacy notice · Updated October 7, 2026
Your practice.Your privacy.
Your code and drafts stay on your device. Free practice keeps progress locally. Web, Plus, and Pro memberships also sync learning progress to your account. Here is what is stored, why, and how to remove it.
Optional external coaching
Plus and Pro members can approve an external assistant with a fresh passkey sign-in. The connection reads authored practice material. You can separately allow recent synced completion summaries: exercise identity, outcome, timing and recorded assistance. It cannot read source, drafts, detailed logs, credentials or payment details, or change progress. No model runs inside the trainer.
Disconnect at Assistant connections to block future access. Your assistant provider controls copies already shared into its conversations; review that provider’s privacy and retention settings. Never paste secrets or full progress exports into chat.
01 / Your device
Code and detailed history
Source code, unfinished work, written predictions, detailed attempt logs, and appearance settings are stored locally.
02 / Your account
Learning progress
Web, Plus, and Pro accounts sync skill observations, completion summaries, and your practice-plan choices. It does not sync your source files.
03 / Service providers
Hosting and checkout
Cloudflare serves the app and stores account data. Stripe handles payment details when you buy a membership or pack.
Practice on your device
Browser exercises run in local browser runtimes. Subjects that need a native runtime send code to your paired local runtime. The account sync service does not receive your source code, editor drafts, written predictions, or detailed attempt event logs.
Your device stores those details along with practice answers, simulation drafts, preferences, and downloaded content. Browser storage can be cleared or evicted. A downloaded backup may contain source code and detailed history; you control where that file goes.
Anonymous practice history stays in a separate local profile. Creating or signing into an account does not automatically merge that history. A public track link contains the track identifier, while an exported profile card contains broad practice counts. Neither is a full progress backup.
Accounts and sync
Stay Practiced uses passkeys. Account registration does not ask for your name, email address, or a password. We store an account identifier, passkey public credentials and related metadata, and session records. Your authenticator keeps the private passkey; Stay Practiced does not receive your fingerprint or face scan.
An optional recovery code can restore access. It is shown once; the server keeps verification data rather than the readable code. Keep it private.
Cloud sync on Web, Plus, and Pro sends exercise and skill identifiers, timestamps, correct/assisted answer flags, skill observations, and completion metrics such as elapsed time, test counts, and hint use. Practice-plan choices such as subjects, role, experience, and track can also sync. These records let another signed-in device reconstruct your learning progress, without your source files or raw answers.
Free accounts and anonymous practice keep learning progress locally. Buying a pack alone does not enable cloud progress. Previously synchronized records stay in the account service until account deletion, even if your membership ends.
Free accounts cannot buy expansion packs. New pack purchases require a paid plan supporting the pack’s languages. Pack ownership stays with your account after a downgrade, while your current plan determines which items you can practice.
The server also stores membership status, pack ownership, and device authorization records so it can enforce access. Local account caches and pending sync records support reconnecting after a network failure.
Hosting and payments
Cloudflare hosts the website, API, account database, and downloadable content. Requests expose network information such as your IP address and browser headers to the hosting service. Application session records omit raw IP addresses and user-agent text; that does not mean the hosting provider receives no metadata. Authentication uses session cookies and local account storage. Security rate limiting uses rotating hashed request keys.
The app does not include advertising or a third-party visitor analytics script. The Stats screen summarizes your practice history; it is not a visitor tracking service. Hosting security and operational processing still apply. Read Cloudflare’s privacy policy.
Stripe handles checkout, payment methods, and information required for billing and tax. Stay Practiced stores billing and checkout identifiers, purchase and subscription state, dates, and event-processing records. It does not store your full card number. Stripe may retain its own payment records after you delete a Stay Practiced account. Read Stripe’s privacy policy.
Authorized content downloads use a distribution identifier linked to your account, the content, and its download time. Download and update requests also create access-control and rate-limit records. These requests do not upload your learner source code.
How long data stays
Local history remains until you delete it, clear site data, or the browser removes it. Account progress and ownership records remain until account deletion. Signing out ends access; it does not erase your browser’s databases.
Download associations and offline update authorizations use 30-day expiry windows. Rate-limit records use shorter request windows. After account deletion, unlinked checkout hashes have a 30-day expiry to handle delayed payment callbacks. Expiry and physical removal are different: expired bookkeeping is cleaned up by later service requests, rather than a guaranteed deletion at the exact expiry time.
The desktop app keeps credentials and offline authorization in operating-system-protected storage and encrypts its offline content. Desktop sign-out removes its lease and offline pack. Other issued offline leases can remain valid until they expire, for at most 30 days. Provider logs, backups, and Stripe’s payment records follow the providers’ retention policies.
Your data controls
Save a copy
Open the command menu and choose “Your data and progress.” Export saves the current profile’s local history to a file. Treat that file as private. Sign out before replacing an anonymous profile with an imported backup.
Clear local data
“Delete everything” in the anonymous data panel resets that local profile. Your browser’s clear-site-data control removes this site’s local history and cached content. Neither action deletes a server account or cancels billing.
Sign out
Sign-out returns the browser to its separate anonymous profile. It keeps local history and account caches on that device. Use clear-site-data as well if you want to remove those local copies from a shared computer.
Delete your account
Use the account panel and confirm with a fresh passkey. The service reconciles and cancels billing before removing application account records, cloud progress, and ownership. If billing reconciliation fails, deletion stays pending and data is retained so you can retry. Account deletion cannot erase exports, other devices’ local copies, or payment records held by Stripe.
Questions and changes
Stay Practiced is operated by Ryan P. Walsh. For questions about your data or a privacy request, contact Ryan. This opens LinkedIn, which has its own privacy policy. Do not send passkeys, recovery codes, or payment credentials.
This notice describes the current service. When data handling changes, this page and its update date will change.
Return to Stay Practiced