Privacy Policy
BuildRoulette Privacy Policy
Effective Date: January 1, 2026
Last Updated: September 3, 2026
BuildRoulette ("BuildRoulette", "we", "us" or "our") is dedicated to protecting the privacy, confidentiality and security of our users ("User", "you" or "your"). This Privacy Policy describes how we collect, use, disclose, retain and safeguard personal information when you access or use the BuildRoulette platform, website, cloud engineering challenges, certification practice CBTs, 100 Days Cloud RoadMap, Architecture Decision Records (EDRs), Path Finder career diagnostics and associated services (collectively, the "Service").
By accessing or using the Service, you acknowledge that you have read and understood the practices described in this Privacy Policy. If you do not agree with our practices, please do not use the Service.
1. Scope & Privacy Principles
This Privacy Policy applies to personal information collected through BuildRoulette. We operate under the following core data protection principles:
- Data Minimization: We collect only the information strictly necessary to provide, secure and enhance your technical learning experience.
- Least-Privilege Security: We never solicit, store or process root cloud provider credentials or private master keys.
- Identity Shielding: We apply administrative anti-scraping and masking controls to user email addresses across administrative dashboards and participant rosters.
- Strict No-Sale Covenant: We do not sell, rent, monetize or trade your personal information to third-party data brokers or advertisers.
2. Information We Collect
2.1 Account Information & Identity Profile
When you create an account, participate in challenges or apply to contribute, we may collect:
- Full name or public builder handle;
- Email address;
- Securely hashed authentication credentials;
- Account role, profile settings and creation timestamps;
- Contributor application details (e.g., GitHub profile, portfolio link, proposed contributions).
2.2 Learning Activity, Diagnostic Results & Gamification
To track your learning journey and award achievements, we record:
- Challenge attempt history, completion timestamps and submission outputs;
- Cloud roadmap milestones reached and daily streak tallies;
- Certification practice CBT exam scores, domain breakdown metrics and diagnostic logs;
- Earned experience points (XP), skill level ratings and claimed milestone awards;
- Path Finder career assessment inputs, role recommendations and target specializations.
2.3 Cloud Challenge & Infrastructure Verification Metadata
When you execute automated verification runners to validate cloud challenge solutions:
- Local Runner Architecture: Our verification scripts execute within your authenticated local shell environment or query designated public endpoints. BuildRoulette does not receive or store your AWS or cloud provider secret keys.
- Verification Telemetry: We collect high-level test outcome metadata, including assertion pass/fail statuses, execution latency, challenge identifier and timestamp.
2.4 Newsletter & Communication Data
If you opt in to receive updates, challenges or architectural case studies:
- Email address and subscription timestamp;
- CASL compliance and consent records;
- Cryptographic 1-click unsubscribe tokens and status logs.
2.5 Technical Telemetry & Device Information
When you navigate the Service, our servers automatically collect standard web telemetry:
- IP address (anonymized/truncated for general geographic telemetry);
- Browser user agent, device operating system and screen resolution;
- Referring URLs, page visit paths and platform interaction timestamps;
- Diagnostic error logs for debugging and platform availability monitoring.
3. Strict Prohibition on Cloud Root Credentials
BuildRoulette's automated verification systems are engineered exclusively to evaluate infrastructure compliance through least-privilege read queries or local CLI test runners.
CRITICAL SECURITY REQUIREMENT: Users must never transmit, upload or paste cloud provider root passwords, AWS Root Account credentials, IAM administrative secret keys, SSH private keys or unredacted infrastructure API tokens into BuildRoulette. BuildRoulette disclaims all liability for credentials improperly transmitted by users in violation of this policy.
4. How We Use Information & Purposes of Processing
We process personal information exclusively for legitimate educational and operational purposes, including to:
- Provide & Maintain the Service: Authenticate users, persist learning roadmaps, record CBT exam scores and calculate gamified badges.
- Execute Diagnostic Verifications: Evaluate challenge solutions against automated test assertions and deliver instant architectural feedback.
- Identity Shielding & Anti-Abuse: Monitor platform traffic for denial-of-service attempts, credential stuffing, scraping bots and leaderboard manipulation.
- Platform Communications: Send essential transactional notifications (e.g., password resets, account security alerts) and, where consented, educational newsletters.
- Analytics & Performance Optimization: Measure feature adoption, troubleshoot latency bottlenecks and improve curriculum quality.
- Legal Compliance: Comply with applicable statutory obligations, tax requirements and enforceable governmental requests.
5. Anti-Scraping & Administrative Email Masking Policy
To protect our community members from targeted phishing, unauthorized outreach and automated data harvesting, BuildRoulette enforces system-level Anti-Scraping & Email Masking Protocols:
- Administrative Masking: Customer and participant email addresses displayed within administrative rosters, user dossiers and analytics tables are algorithmically masked (e.g.,
a***@e***.com). - Access Restrictions: Unmasked email access is restricted strictly to automated background transactional mailers via encrypted environment variables.
- Roster Protection: Public leaderboards and community showcases display only user-selected builder handles and earned milestone badges—never contact addresses.
6. Commercial Electronic Messages & CASL Compliance
BuildRoulette complies with Canada’s Anti-Spam Legislation (CASL) and global anti-spam regulations:
- Express Consent: We send promotional newsletters, product announcements and challenge releases only to individuals who have provided express opt-in consent.
- Instant Unsubscribe Mechanism: Every commercial email contains a clear, functioning 1-click unsubscribe link.
- Immediate Processing: Opt-out requests are processed immediately and synchronized across all mailing queues without delay. Unsubscribing from marketing emails does not affect critical transactional notices.
7. Information Sharing & Third-Party Service Providers
We do not sell, rent or trade your personal data. We share information only with vetted third-party service providers bound by strict confidentiality and data protection agreements:
- Hosting & Infrastructure: Cloud hosting, CDN and managed database providers;
- Transactional Email Delivery: High-reputation SMTP providers (e.g., Postmark, Amazon SES, Mailgun);
- Security & DDoS Mitigation: Web Application Firewalls (WAF) and DDoS filtering networks;
- Analytics & Error Monitoring: Anonymized application performance monitoring tools.
We may disclose personal information if required to do so by law, court order or subpoena or if we determine in good faith that disclosure is necessary to protect platform security, investigate fraud or defend legal claims.
8. Data Security & Storage Safeguards
We implement administrative, technical and physical safeguards appropriate to the sensitivity of personal information:
- Encryption in Transit: All traffic is encrypted using Transport Layer Security (TLS 1.3 / HTTPS).
- Encryption at Rest: Databases, persistent storage and backups utilize industry-standard AES-256 encryption.
- Credential Protection: Passwords are cryptographically hashed using modern salted hashing algorithms (Argon2id / Bcrypt).
- Least-Privilege RBAC: Administrative access to production databases and servers is restricted to authorized personnel via multi-factor authentication (MFA).
9. Data Retention & Account Erasure
We retain personal information only for as long as necessary to fulfill the educational purposes outlined in this Policy, maintain academic continuity, resolve disputes and comply with legal records retention statutes.
- Active Accounts: Learning progress, streak counts and earned awards are retained as long as your account remains active.
- Account Erasure: You may request permanent deletion of your account and associated personal data at any time by contacting
privacy@buildroulette.com. Upon verified request, all personal identifiers will be purged or permanently anonymized within 30 calendar days. - Audit Logs: Anonymized telemetry and security logs are retained for a rolling 90-day window for forensic auditing before automated purging.
10. Individual Privacy Rights (PIPEDA & Global Standards)
Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and comparable privacy legislation, you have the right to:
- Access: Request a copy of the personal information BuildRoulette holds about you.
- Rectification: Request correction of inaccurate, outdated or incomplete personal data.
- Consent Withdrawal: Withdraw your consent to discretionary data processing at any time.
- Erasure / Deletion: Request deletion of personal records where statutory retention requirements no longer apply.
- Inquiries & Complaints: Submit formal inquiries regarding our information handling practices.
We will respond to all verified access and correction requests within thirty (30) days without charge, except where permitted by law.
11. Cross-Border Data Transfers
BuildRoulette is managed from Ontario, Canada, with cloud infrastructure distributed across secure North American data centers. When information is transferred across jurisdictions, it is subject to the laws of the receiving jurisdiction, including lawful access by foreign law enforcement authorities. We ensure adequate contractual and technical safeguards accompany all cross-border processing.
12. Children's Privacy
The Service is designed for cloud engineers, students and professionals aged 18 and older. We do not knowingly collect personal information from individuals under the age of 13 (or under 16 where applicable by law). If we discover that personal data from a child has been collected without verified parental consent, we will promptly delete the data from our systems.
13. Policy Updates & Notification
We may update this Privacy Policy periodically to reflect enhancements to our platform, changes in legal standards or operational modifications. When material revisions occur, we will update the "Last Updated" date at the top of this document and provide prominent notice on the platform or via email. Your continued use of the Service after the effective date of an updated policy constitutes your agreement to the updated terms.
14. Privacy Officer & Contact Information
For inquiries, data access requests, consent revocations or privacy-related concerns, please contact our Privacy Officer:
BuildRoulette Privacy Office
Attention: Privacy Officer
Email: privacy@buildroulette.com
Website: https://buildroulette.com
Location: Toronto, Ontario, Canada