component.guide

Privacy

Effective 30 July 2026. This page is kept in the same repository as the site, so every change to it has a date and a public diff.

component.guide is a teaching site about how user-interface components are built. This page explains what it knows about you, why, and how to make it stop.

The short version is that there are no third-party trackers on this site, nothing about you is sold or shared with advertisers, exactly one cookie is optional, and asking us to delete your account deletes the data rather than just the login. Everything below is the long version of those four sentences.

1. Who we are

Where this page says “we”, it means the operator of component.guide, which is the party legally answerable for everything described here. If you want to reach us about anything on this page, write to us and you will get an answer from a person.

[ To complete before publishing: registered legal entity, registered address, privacy contact address, whether an EU or UK representative is required, and the governing law. ]

2. If you are only reading

You can read every chapter and run every lab without an account. When you do, the server writes a single line recording which page was asked for, the method, the language it was served in, the response status and the time. That line is not joined to a name, an email address or an IP address, and it is not sold, shared or given to anyone.

Your IP address is necessarily seen, because otherwise the page could not be sent to you. It is used for one additional purpose: a rate limit that stops a single address from repeatedly hammering the sign-in and newsletter endpoints. Those counters hold nothing but an address, a path and a number, and they are deleted every hour.

3. Cookies

This site sets five cookies in total. All five are first-party, which means no other website can read them, and none of them are used to build a profile of you or to follow you elsewhere on the internet.

Four are required for the site to function and are set without asking, because there is no meaningful choice to offer. A session cookie keeps you signed in and lasts thirty days. A locale cookie remembers that you asked to read in English, 繁體中文 or 简体中文, and lasts a year. A consent cookie records the answer you gave the cookie notice so that we stop asking, and also lasts a year. A flag-overrides cookie only ever exists if a developer has set it by hand while debugging; if you have never opened a browser console, you do not have it.

The fifth is optional and is not set unless you say yes. It stores a random identifier — no name, no email address, nothing that leads back to you — so that if a feature is being tested you stay on the same side of that test between page loads, rather than watching the site change shape as you read. If you decline, it is never written; if you accept and later change your mind, it is deleted immediately rather than at some future expiry date. You can change that answer here, as often as you like.

The optional cookie. Checking…

4. If you have an account

An account exists so that you can save your progress, receive the newsletter if you asked for it, and pay for Pro if you want it. What follows is the whole of what an account stores, not a summary of it.

We hold your email address, the display name you chose, and an avatar image address if the Google or GitHub profile you signed in with had one. We hold a cryptographic hash of your password rather than the password itself, and if you have turned on two-factor authentication, the secret and backup codes that make it work. If you signed in with Google or GitHub we also hold that provider’s account identifier, the permissions you granted, and the tokens needed to keep the connection alive — we never ask for access to your repositories, your contacts or your files.

Each device you are signed in on has a session record holding the IP address and browser it was created from, which is what allows you to see and revoke a laptop you no longer own. Security-relevant events — signing in and out, changing a password, turning two-factor on or off, revoking a session — are recorded against your account so that a break-in could be reconstructed afterwards.

If you subscribe to Pro we hold your tier and the customer and subscription identifiers issued by our payment provider. Card numbers never reach this site at all; they are entered on the provider’s own page and we never see them.

5. Why we are allowed to

Data protection law requires a stated lawful basis for each use of your data, so here are ours. Running your account, keeping you signed in and delivering what you have paid for rests on our contract with you: without that data there is no service to give you. Keeping the site up and unbroken — rate limits, security records, error reports and counting how often a page was read — rests on our legitimate interest in operating it, and in each case we use the least identifying form of the data that still works.

The optional cookie and the newsletter rest on your consent, which means they are off until you turn them on and withdrawing is as easy as giving — one click above, or one link in the footer of every email. Keeping records of what you paid and when rests on a legal obligation, and we cannot delete those early even if you ask.

6. Who else touches your data

Five companies are involved, each doing one job, and none of them is permitted to use your data for its own purposes. This is the complete list, and if it changes this page changes with it.

Cloudflare serves every page and stores the database, the files and the page counts; nothing on this site exists anywhere else. Sentry receives a report when the site throws an error so that it can be fixed, and times roughly one request in ten for performance. Lemon Squeezy takes the payment and is the merchant of record, which is why your card details are entered on their page and never sent to us. CodeSandbox runs the live code editors in the Lab, so opening a lab page contacts them, while reading an ordinary chapter does not.

Finally, Google Fonts delivers the three typefaces this site is set in. Your browser fetches them directly from Google, which means Google sees your IP address the first time you load a page here. We would rather it did not, and we intend to serve the fonts from our own domain instead; until we have, it would be dishonest to leave it off this list.

7. How long we keep it

“Until you ask us to stop” is not a retention period, so here are real ones. Rate-limit counters last an hour and are then purged by a scheduled job. Sign-in sessions last thirty days, or until you revoke them. Page counts, security events and error reports are kept for ninety days.

Your account and everything attached to it is removed within thirty days of you asking us to delete it. A newsletter subscription lasts until you unsubscribe, and the unsubscribe link is in every email we send. Invoices and payment records are kept for seven years because tax law requires it, and that is the one thing on this page we cannot delete on request.

8. Your rights

You can correct your name and email address yourself from your settings; nothing else about you is stored as free text, so there is nothing else there to correct. Withdrawing consent for the optional cookie is a single click, in section three above or in the notice itself.

The remaining rights need a person to act on them, so we do them by hand rather than pretending otherwise. Write to us and we will send you a machine-readable copy of everything we hold, delete your account and its data, restrict a particular use, or pass your data to another service. You will have an answer within thirty days, including if the answer is no and why.

9. Children, changes and complaints

This site is not directed at children under sixteen and we do not knowingly hold their data. If you believe a child has created an account, tell us and it will be removed.

When this page changes, the change is a commit with a date and a diff you can read. Substantive changes are announced in the changelog before they take effect; corrected typos are not.

If you think we have handled your data badly, please tell us first — we would much rather fix it than read about it. You also have the right to complain to your national data protection authority, and you do not need our permission or our involvement to do so.