Skip to content
Kharita Challenges

Privacy

Kharita Challenges is where you practise and prove GIS skills. This notice says who is responsible for what it keeps about you, what that is and why, who else sees it, how long it is kept and what you can do about it. The terms say what you agree to by using the site. Last updated 28 September 2026.

Who is responsible

This deployment has not yet published the name and address of whoever runs it. Write to [email protected] about anything on this page, or use Support.

What we keep, and why

Your account

Your name, your email address and your password, stored only as an Argon2id hash, or the Google or GitHub account you chose to sign in with — its account number, never its password.

To give you an account and let you sign in. On what basis: Needed to provide the service you signed up for.

Your sessions

A random token in a cookie, of which we keep a hash, with the browser and IP address each sign-in came from.

To keep you signed in, and to look into misuse of an account. On what basis: Needed to provide the service you signed up for, and our legitimate interest in keeping accounts safe.

Your work

What you submit and how it was graded, your drafts, your assessment attempts, the credentials you earn, the classes you belong to and what you post in discussions.

To grade it, keep your record, issue your credentials and let others check them. On what basis: Needed to provide the service you signed up for.

How you sat an assessment

While you sit one: when you open each problem and first change your answer, when you paste into the workspace and how much — kept as its length and a set of numbers worked out from it that can show whether it matches an answer, never its words — when you leave the page and for how long, and how often you run your answer. A person reads it only if the result needs a second look, and what they decide is kept with the sitting.

To check a sitting was sat under its rule, which is what makes the credential it earns worth checking. On what basis: Our legitimate interest in credentials people can trust. The assessment tells you before you begin.

Your record

Your XP, level, streaks and a rating for each track, worked out from your graded work.

To show you your progress and, if your profile is public, your place on the leaderboard. On what basis: Needed to provide the service you signed up for.

Your profile

Your handle, name, bio, institution, country, picture and the links you add. It is private until you make it public. A picture is re-encoded when you upload it, which strips the location and camera details a photo can carry.

To show others what you choose to show. On what basis: Your choice to publish it, which you take back by making it private (consent).

The mentor

How many questions you asked on each problem, and when. What you asked, and what it answered, is not kept here.

To hold you to the number of questions you may ask. On what basis: Needed to provide the service you signed up for.

What you write to us

The name, email address and message you send from Support or with a request for a workspace or a class, and the account you were signed in with, if any.

To answer you. On what basis: Our legitimate interest in answering, or the steps before an agreement you asked about.

Security records

The IP address of recent requests to sign in, sign up and send forms, held in memory for minutes, and the back office’s log of who changed what.

To stop abuse, and to keep a record of every change to what people are graded against. On what basis: Our legitimate interest in a safe service with trustworthy grades.

How the site is used

Which pages are visited, with every address rebuilt so it carries no token, email address or name (see Analytics).

To learn which pages help and which don’t. On what basis: Your consent where the law asks for it first; elsewhere our legitimate interest, which you can refuse below.

We do not sell any of it, and none of it is used for advertising.

Graded by a program

Every grade is worked out by a program — the grader — from what you submitted, against checks the problem’s author wrote and measured. An assessment’s result, and whether it earns a credential, follows from those grades without a person deciding. How a sitting was sat is never graded: the notes read from its record decide nothing, and only a person who has read them can find that it was not sat under its rule and withdraw the credential it earned. Because a credential can matter to somebody deciding whether to hire you, you can ask for a person to look at any grade: write to Support about it and an operator will run it again against the stored record, look at it themselves and tell you what they found.

Who else sees it

  • Anybody with the link. Your profile and your place on the leaderboard, once you make your profile public; and a credential’s verification page, which shows its holder’s name, what it certifies and whether it still stands.
  • Your teachers. When you ask to join a class, its teacher sees your name, handle, picture, institution and country; once you are in, your level and XP and which of their assignments you have solved.
  • Cloudflare. Delivers every page and file of this site, so it sees your IP address and what you ask for.
  • Cloudflare R2. Stores the files uploaded here, profile pictures among them, for us.
  • Our hosting provider. Runs the servers the database and the site live on, for us.
  • Brevo. Sends our emails, so it has your address and each email sent to you, and records whether it was delivered, opened and followed.
  • Our mailbox. A message to Support is also mailed to [email protected], so that mailbox’s provider holds a copy of it.
  • Google and GitHub. Only if you choose to sign in with them. They tell us your account number, your name and your verified email address, and learn that you signed in here.
  • OpenAI. When you ask the mentor something: your question, your current work on the problem (up to 4,000 characters), the requirements your last submission missed and, when the mentor looks, your earlier attempts on the problem and a description of its data — never your name, handle or email address. It writes the reply. We ask OpenAI not to store the conversation; under its terms for this service it is not used to train its models, and it may be kept for a short time to detect abuse.
  • The maps’ tiles. Every map loads its background from OpenTopoMap, the OpenStreetMap Foundation, Esri and MapLibre, which see your IP address and which part of the map you are looking at.
  • jsDelivr. When you open a Python problem, your browser downloads Python itself from there, which sees your IP address.
  • Google Analytics. As described below, and only where it is allowed.

Nobody else, except where the law obliges us.

Cloudflare, Google, GitHub, OpenAI and Esri are based in the United States, and so your data can travel there. Where the law asks for a safeguard for that, we rely on each provider’s data protection terms, which use the European Commission’s standard contractual clauses or the EU–US Data Privacy Framework.

How long we keep it

Your account

Until you delete it. Deleting takes everything that is yours with it, at once.

An address never confirmed

The account it was typed for is deleted 30 days later, if nothing was done with it.

A session

Until you sign out, or 30 days after it runs out — then its browser and IP address go with it.

A confirmation or reset link

7 days after it was used or ran out.

A submission waiting to be graded

The copy waiting in the queue is emptied once it is graded and its record removed a day later. The graded submission is part of your work.

What you write to us

2 years after it arrives, or sooner, when you delete your account, if you sent it signed in.

How you sat an assessment

Each moment a year after it happened, or sooner, when you delete your account. Your answers, the score and a review’s outcome stay with the sitting, as part of your work.

The back office’s log

As long as the platform runs. Once an account is deleted, the log no longer links to it.

Backups

A copy of the whole database is taken before each release and the five newest are kept, so something deleted is gone from them once five more releases have gone out.

Analytics

For as long as the Analytics property keeps it: at most 14 months.

Analytics

We use Google Analytics to count visits and see which pages help. It is never given a token, an email address, a person’s handle or a company’s private problem: every address is rebuilt before it is sent, and it does not run at all on the sign-in, sign-up, password, invitation or profile pages. Google signals and ad personalisation are off.

In the EEA, the UK and Switzerland, and wherever we cannot tell where you are, it stays off until you allow it, and a yes lasts 13 months before you are asked again. Elsewhere it is on unless you turn it off here, or your browser sends Global Privacy Control. Once allowed, Google sets the cookies listed below. Read how Google uses data when you use our partners’ sites or apps.

Cookies and storage

None of these is used to follow you to other sites.

__Host-kharita_session

Keeps you signed in. We keep only a hash of it.

Cookie · 30 days from when you sign in, or until you sign out

__Host-kharita_confirm

Lists the confirmation links this browser asked for — by number, not the links — so a link’s password counts only in the browser it was typed in.

Cookie · a day

__Host-kharita_sent

The address a confirmation email was just sent to, for the page that says so.

Cookie · 10 minutes

__Host-kharita_oauth_…

Carries a Google sign-in from start to finish.

Cookies · 10 minutes, during that sign-in only

__Host-kharita_github_…

Carries a GitHub sign-in from start to finish.

Cookies · 10 minutes, during that sign-in only

kharita-theme

Your light or dark choice.

Your browser’s storage · until you clear it

kharita-map-height

How tall you last made the map.

Your browser’s storage · until you clear it

kharita-attempt-…

Which assessment you are sitting and when it started, so a reload loses nothing.

Your browser’s storage · until the sitting ends

kharita-analytics

Your answer about analytics, and the day you gave it.

Your browser’s storage · a yes for 13 months, a no until you clear it

_ga, _ga_…

Google Analytics, only once analytics is allowed: tells one visit from another.

Cookies · up to 2 years

kharita.admin.briefMode

In the back office only: whether you last edited a brief visually or as Markdown.

Your browser’s storage · until you clear it

Your rights

  • A copy of it. Download a copy in your settings gives you everything kept about your account, as one file.
  • Correcting it. Most of it is in your settings; for anything else, write to us.
  • Deleting it. Delete your account in your settings, and everything that is yours goes with it.
  • Taking back a consent. Make your profile private, or turn analytics off, at any time — as easily as you turned them on.
  • A person, not a program. Ask for a person to look at any grade, as above.
  • Objecting, or anything else. To object to something we do on the basis of our legitimate interests, to ask us to hold back from using your data while a question is settled, or to ask anything about this page, write to [email protected]. We answer within a month.

If you think we have got something wrong, you can complain to a data protection authority: the one where you live or work in the EEA, the ICO in the UK, the FDPIC in Switzerland, or in Morocco the CNDP (Commission nationale de contrôle de la protection des données à caractère personnel), under law 09-08.

Age

Kharita is for people aged 16 and over, and nobody younger may make an account. If you know of an account that belongs to somebody younger, tell us and we will delete it.

Changes

The date at the top says when this notice last changed.