Privacy Policy
Last updated: August 12, 2026
FTC Programming Atlas is an educational project for FTC programming documentation. Most content can be viewed without an account. Authentication is required only for people who have been granted editor access.
1. Data we may process
- Email address entered for magic-link authentication and verification of editor access.
- Authentication and session data generated technically by Supabase Auth. The Atlas client stores the session locally in the browser in order to keep the user authenticated.
- Technical access data that may appear in the hosting or backend infrastructure, such as IP address, browser type, request time, and information necessary for security and operation.
- Content uploaded by editors, including documentation, files, and media. Editors should not upload sensitive personal data that is not necessary for the project.
2. Why we use this data
Data is used for authentication, editor access control, application security, content administration, and the technical operation of the Atlas. Public access to documentation does not require providing an email address.
3. Legal basis
For editor authentication and administration, processing is based primarily on the legitimate interest of securing and administering access to the project. Technical data required for operation and security is processed for the same purpose. Providing an email address is optional for visitors; without it, you can browse the Atlas but cannot authenticate as an editor.
4. Third-party services
The Atlas uses external services that are necessary for its operation:
- Supabase for the database, authentication, storage, and APIs. Supabase describes its platform as including Postgres, Auth, Storage, and APIs and publishes information about its security controls.
- Netlify for hosting and delivering the site. Netlify may process technical data required to provide and secure the service.
- esm.sh for delivering the Supabase JavaScript module to the browser.
- YouTube or other external media sources only when documentation includes external content; loading that content may send the provider ordinary technical connection data.
5. Cookies and tracking
FTC Programming Atlas does not intentionally implement behavioral advertising, marketing analytics, or tracking cookies. Authentication may use browser local storage to maintain the session. External services may have their own practices when their resources are accessed.
6. How long we keep data
Authentication data is kept for as long as it is needed to administer editor access and project security, after which it may be deleted or disabled. Published content remains until editors modify or remove it. Technical data and backups may be retained according to the retention periods and policies of infrastructure providers.
7. International transfers
Technical providers may use infrastructure in multiple jurisdictions. Where relevant, transfers are governed by the mechanisms and safeguards described in the providers' terms and data-protection agreements. Netlify states that it uses mechanisms such as Standard Contractual Clauses and, for certain transfers, the EU–U.S. Data Privacy Framework.
8. Your rights
Under the GDPR, you may have rights to access, rectification, erasure, restriction of processing, objection, and, where applicable, data portability. You also have the right to lodge a complaint with the competent supervisory authority.
9. Security
The Atlas uses HTTPS, browser security policies, database-level access control, and separate rules for editor operations. No technical measure can guarantee absolute security, but the project is configured to limit unauthorized access and unnecessary data exposure.
10. Changes to this policy
This policy may be updated when Atlas functionality, providers, or data-processing practices change. The date of the latest update is shown at the top of this page.