Privacy
Practice Pad runs in your desktop browser at practice-pad.app/javascript-interview-practice. You can try a question without an account. Account storage, AI review, payments and analytics are described below.
The browser version and your account
Without an account, the browser version keeps your code and progress only in your own browser’s storage on that device; your code and progress are not sent to us. Clearing the site’s data in your browser removes it.
Anyone with an active free trial, subscription or lifetime licence can sign in to create an account identified by their purchase email address. To sign in we email you an eight-digit code through Loops, our transactional email provider; the code expires after ten minutes and allows a limited number of attempts, and we store only a hash of it. Signing in sets one strictly necessary cookie that identifies your session for up to thirty days; it is not used for analytics or advertising. Signing out ends the session and removes your code and progress from that browser.
While you are signed in, your code and progress are saved to your account so they follow you to any browser you sign in on. If you had practised before signing in, that work is added to the account. Your account record holds your email address, when it was created and last used, and, if you have bought Pro, a link to your purchase record; purchases made under the same email before accounts existed are attached to it when you first sign in.
You can delete your account from the account dialog on the practice page. Deleting your account does not cancel your subscription; cancel it first from your account or through Paddle to stop future charges. Deleting the account removes your email address, sessions, saved code, progress and daily AI usage counts straight away. Monthly AI cost records linked to a hashed identifier are retained to prevent deleting and recreating an account from resetting its allowance. Purchase records are kept, with the link to the account removed, for as long as needed to honour a lifetime licence, prevent fraud and meet Paddle’s and our tax obligations; signing in again with the same email restores Pro from them.
AI review in the browser version
In the browser version, AI review is included with Pro, including during a free trial, and uses Practice Pad’s own Anthropic key, so you never enter one. When you send a message from the AI panel, the question, your current code and your messages in that conversation are sent to Anthropic’s API, which processes them under Anthropic’s commercial terms and does not use them to train models. We do not store the text of your messages or of the replies; we count the tokens each review uses and its estimated cost under a hashed identifier. For Pro accounts these counts enforce a £2 monthly allowance for monthly and lifetime plans, or £4 for yearly plans. No message, code or reply text is included in those records.
Pro purchases and licence verification
Practice Pad is provided by Michael Moore. Paddle acts as our reseller and merchant of record. It collects the purchase email, billing information and payment details needed to process your order, provide receipts, calculate tax and handle refunds. Practice Pad does not receive or store your full card number or card security code. See Paddle’s privacy notice.
Our payment service runs on Cloudflare. It uses the country associated with your IP address to display a price, and processes your connection to prevent abuse. Licence records include the quoted country, currency and amount, Paddle transaction and customer identifiers, payment/refund status, a hashed purchase email, and random device identifiers. Purchase credentials are stored as hashes on the server and encrypted locally on your Mac. Your practice code, Claude key and test output are not included in billing requests.
When an existing installation updates to the paid version, the app stores an encrypted decision on that Mac to preserve its full access. This migration does not send your workspace or installation history to our billing service.
The app checks purchase status after checkout, on launch and focus, and periodically while running. It stores a signed offline receipt valid for up to seven days. Purchase and device records are retained while needed to honour your lifetime licence, prevent fraud and resolve payment disputes. Paddle retains its own payment records according to its policy and legal obligations.
Purchase recovery emails
When you request Restore purchase, we send your entered email address and a one-use code to Loops to deliver that transactional email. This does not subscribe you to any marketing list. Codes expire after ten minutes and have a limited number of attempts. The server stores a hash of the code, not the code itself. Expired recovery and rate-limit records are cleared during routine billing traffic, after approximately one day and one hour respectively.
We process purchase and recovery information to fulfil your licence and provide support; fraud prevention and service security also protect our legitimate interests. Providers may process information outside your country under their applicable safeguards. To request access, correction or deletion of your personal information, contact michael@codemoore.com. Deleting records needed to verify a purchase can prevent automatic activation or recovery. You may also complain to your local data protection authority, including the UK Information Commissioner’s Office.
Existing installations
For previously installed versions, code and progress remain on your device. If you enable AI review with your own Anthropic key, the key is stored locally using operating-system-backed encryption and sent directly to Anthropic with the content you submit. It is never sent to Practice Pad’s payment service or analytics.
Previously installed versions send a small number of anonymous usage events to PostHog, hosted in the European Union. They exist to answer three basic questions: how many installations are used, whether they come back to it, and whether they get as far as running code.
This analytics is separate from purchase verification. The first time an installation runs, it generates a random identifier and stores it on your own Mac. That identifier is not derived from and is never combined with your name, email address, username, device name, IP address, or anything else that identifies you or your computer.
Exactly four events are recorded, and no others:
- First launch: the first time an installation is opened. Records the app version, the operating system platform, and the processor architecture.
- Launch: each time the app is opened after that. Records the same three details.
- Question opened: an interview question is selected. Records which question, by its identifier and title.
- Code run: code is executed using the Run tests button. Records the language, JavaScript or TypeScript, the selected difficulty, and which question was open.
No other app analytics is collected. Analytics never sends your code or editor contents, your console output, error messages or variable values, file names or filesystem paths, clipboard contents, your computer's name, or your Claude API key. There is no session recording, no screen or keystroke capture, and no automatic collection of interface interactions: only the four events above are ever sent. Your IP address is not stored alongside these events, and no location is derived from them.
Development builds send nothing at all.
Website
This website uses Google Analytics and privacy-limited PostHog analytics hosted in the European Union to understand traffic, page and section views and question-page use.
Website PostHog analytics uses anonymous, session-scoped identifiers. Automatic click and form capture, session recording, person profiles, heatmaps, console logs, and error capture are disabled. Only named interactions such as primary button clicks and aggregate browser performance measurements (FCP, LCP, INP, and CLS) are sent. Form contents, email addresses, code, and arbitrary URL parameters are never included.
We sometimes compare two versions of the Pro offer. While a comparison is running and you are shown one of its versions, your browser keeps that anonymous PostHog identifier in its local storage, so you see the same version when you return and we can compare how often each version leads to a trial. This also links your visits to this website during that time. The identifier is deleted on your first visit after the comparison ends, and after 90 days at most, and is never kept if your browser sends Do Not Track.
In the browser editor, we measure whether you start editing and your approximate active coding time, with the selected question and language. Time stops when you leave the editor or after 30 seconds without an edit. This includes short thinking pauses, not just typing time. We send duration totals, never your code, individual keys, or clipboard contents.
Checkout sends named milestones to PostHog when it opens, accepts customer details, selects a payment method, starts or completes payment, encounters a provider error, or closes. We include stage timings, retry counts, payment method category, billing country, currency, the displayed amounts and trial availability. We record only whether an email was provided, never its value. Anonymous visit and transaction identifiers connect browser milestones to server-confirmed purchases and payment failures. Failure reports include provider error codes, but no free-form messages, card details, addresses, form contents or checkout URLs. Browser exit and prolonged payment processing are recorded as observations, not proof of a failed payment. Unsent failure reports are cleared after seven days when retried; successful reports are cleared from our delivery queue. Do Not Track remains respected. Starting and finishing the walkthrough, seeing the Pro offer, starting checkout and confirmed Pro activation are also measured in the practice page. Your code, messages and email address are never included in analytics events.
For a first paid lifetime Pro purchase, we send Google Analytics and PostHog the verified transaction identifier, plan, currency, price excluding tax and tax amount. The transaction identifier prevents duplicate reporting. When available, each service's existing anonymous browser and session identifiers associate that purchase with the originating visit. PostHog also receives the landing page path, referrer hostname and campaign labels so we can compare visits and paid conversions. This first-visit attribution is kept in this browser tab for up to 24 hours. We do not send either service your name, email, card details, code or checkout URL. Browser and session identifiers stored with a purchase are cleared after successful reporting. Automatic renewals are not reported as new acquisitions. If tracking is blocked or Do Not Track is enabled, we do not create this purchase attribution.
When a free trial starts, we send PostHog the same verified details with a value of zero, but not Google Analytics. We keep that trial’s anonymous PostHog identifier until the trial converts to a paid subscription or is cancelled, then report that outcome under the same identifier and delete it. We also send Loops, our email provider, your purchase email address with the trial’s start, end date and outcome, so that it can send eligible contacts a reminder two days before a monthly or yearly trial ends, and stop reminders once it is cancelled or has converted. Workflow reminders do not reach unsubscribed contacts.
Abuse prevention
We retain hashed purchase email identifiers, Paddle customer identifiers and random browser purchase identifiers to limit each customer to one free trial across monthly and yearly plans. This history remains after cancellation or account deletion. We do not receive full card numbers or use card fragments to identify a person.
Anonymous AI review uses a browser cookie, request limits and a shared monthly spending cap. When enabled, Cloudflare Turnstile performs background verification using browser and connection information, without an additional sign-in step. Cloudflare processes that information to detect automated abuse under its Turnstile Privacy Addendum. These checks can limit free AI availability and cannot identify every returning person.
Windows waitlist (closed)
The previous waitlist is closed and no longer accepts signups. If you joined it, your email address and whether you visited from Windows were sent to Loops, the email service used to manage the list, and are still held there. That information was only ever used to contact you about the Windows version of Practice Pad. It was not added to a general marketing list or shared with third parties for advertising, and every email from the list includes a link that lets you unsubscribe.
Contact
Questions about this policy: contact michael@codemoore.com.
Last updated: 28 September 2026.