Docs

Privacy and security

Bitling is local-first. Your projects and practice history stay on your computer, and nothing is sent to Bitling.

What stays where

  • Your projects are ordinary files in the folder you chose. Keep them, move them, or put them under version control like any other code.
  • The extension remembers your folder choice and a couple of small preferences inside the browser on your computer.
  • The desktop app keeps your library and history in a local database (workspace.db) and your settings in settings.json, both in ~/.practice-workspace/. It doesn't need the network.
  • Test results are read only in projects you turn on test pickup for: the desktop app reads the report file that project's own tests write, inside the project folder, and keeps the counts in workspace.db. It never runs your tests and doesn't look at running programs. See test results.
  • You don't need an account, and there's no telemetry or analytics. There's no hosted Bitling server, and the extension never talks to one.
  • The app contacts a server only if you set one up yourself: Settings → Account is optional, for trying sign-in against a development sync server you run. The app then contacts only that server: when you sign in or out there, when you save or join a collection on the Collections page or open one (to read its assignments, problem set and feedback), when you write a problem for one or make a project for one of its problems (to read that problem), when you share an attempt with a collection's mentor or comment, and, only if you also turn on sync, to upload problem details, attempt summaries, sessions, reflections and a few preferences (never your code or project files) and to bring in the same from your other computers. Each of those kinds has its own switch, and Settings lists every field that goes. You can save a copy of what the server holds, or delete the account there, which needs the server to be reachable and leaves your practice data on your computers as it is. The sign-in token stays in your system keychain, and signing out leaves your practice data as it is too.
  • A shared collection is a list of problems in weeks and sections, and it isn't part of sync. Saving one uploads it to that server, whether or not sync is on and before you share it: its title, your notes, the name you sign it with, and each problem's name, platform and page link. Sharing it only makes a link others can join with. Never a problem's text or any code: the people who join make each project on their own computer, from the problem's page. Deleting your account deletes the collections you made with their assignments, problem sets and anything shared in them (the people who joined lose access; projects they made stay theirs) and takes you out of the ones you joined along with the progress and attempts you shared there, and the app removes its copies of them. There's no hosted server for this yet, so it only works with a development server you run.
  • Assignments: a collection's author can assign weeks with a due date. In a collection you joined, the app tells the server which assigned problems you've solved (their ids only: never when, how long, your hints, notes or code) only once you turn on “Share my progress with the group” for that assignment; it’s off until you do. The server keeps your report with your account; the author sees only whether none, some, most or all of the members who share finished (never a count), and nothing until at least three share. A due date is a guide: nothing is locked, timed or watched.
  • Mentor feedback: in a collection you joined, you can choose to share one attempt with its author. The app shows exactly what goes first: which problem, how it ended, your reflection's answers, and an optional question and name. Never your code, times, hints or test results. The author sees only what was shared with them and can comment; you see the comments and can reply. The server keeps a shared attempt with your account, so it knows whose thread a comment is in (a comment itself stores only its text and whether the author or you wrote it); the author sees your chosen name, if any, never your email. Stopping sharing deletes the attempt and its comments from the server, and so does leaving the collection. Nothing is graded, ranked, timed or watched.
  • Problem sets: a collection's author can write practice problems of their own for it: a statement, constraints, worked examples and tags. Never starter code, a solution, tests, a time limit or a score, and the server refuses anything that reads as code. The server shows them only to the author and the people who joined. Making a project for one reads it from the server and writes the project in your project folder with the template you pick, never replacing a file that's there; nothing you write in it is sent. It then sits in your library like a captured problem (so, with sync on, its title, difficulty and a link naming the set go with your problem details).

The one request that leaves your computer during capture goes to the practice site itself: on some sites Bitling asks for the same problem details the page loads. The privacy page covers this, and every permission, in full.

What the extension can and can't do

It can

  • read the problem on a supported site, when you open the popup there,
  • write projects into the one folder you gave it access to,
  • remember small preferences in the browser, and
  • talk to the Bitling desktop app on the same computer, if it's installed.

It can't

  • read other tabs, other sites, or your browsing history,
  • see files outside the folder you chose,
  • run arbitrary programs or shell commands. With the desktop app, it can only ask the app to open a project in an editor, terminal, or file manager the app found, or to open the project's problem.html with your system's default app for HTML files.
  • submit solutions for you, or
  • capture proctored or employer assessment pages.

The saved problem.html is cleaned up before it's written and contains no scripts. The original details are kept as data in .practice/problem.json, which is never run.

Assessments are off-limits

Bitling is for practice. Each site's reader checks whether a page is a proctored or employer assessment, and those pages are refused no matter what. If a reader can't tell what a page is, Bitling treats it as unsupported rather than guessing.

How the extension talks to the desktop app

The two use Chrome's native messaging: the browser starts a small helper program that ships with the app, bitling-native-host, and passes messages to it directly. There's no local web server and no open port.

  • Only the Bitling extension may connect. The registration names its extension ID, and Chrome enforces that.
  • Every message is checked against a fixed set of actions. Anything unknown or malformed is rejected.
  • Projects are only written inside your project folder. Paths that try to climb out with .. or through a symlink are refused, and nothing is written.
  • It can open a project in an editor, terminal, or file manager it found on your computer, or open a project's problem.html with your system's default app for HTML files, and only at a project path it has checked. It never runs arbitrary commands.
  • It works even when the app window isn't open.