Legal

Privacy Policy

Blok is an independent project built by a single UvA student, not a company with a legal department — so this page says plainly what the site actually does with your data. It is not affiliated with or endorsed by the University of Amsterdam.

What this site collects right now

Blok is free to use at the moment. There is no checkout and no payment of any kind, so no card, billing or payment details are collected, and nothing about you is sent to a payment provider.

You can read the first lecture of every course without an account, and without giving Blok any personal data at all. Sign-up is open to @student.uva.nl, @uva.nl, @student.auc.nl and @auc.nl addresses, and requires clicking a verification link sent to that address before you can sign in. An account that is never verified is cleared out automatically once it is more than 24 hours old.

Signed out, the site sets two cookies:

  • A theme cookie (blok_theme), written only when you click a colour theme in the header. It holds one of four fixed theme identifiers and is kept for a year so your choice survives a reload.
  • A consent cookie (blok_cookie_consent), written only when you dismiss the notice at the bottom of the page. It records that the notice was shown and dismissed, and nothing else.

Once you sign in, the site sets one more: a session cookie written by Better Auth, the authentication library Blok runs on. Its name ends in session_token (prefixed __Secure- in production); it is marked HTTP-only, so no script running on the page can read it. It lasts up to 30 days, refreshing itself while you keep using the site. It is cleared when you sign out, and replaced with a fresh one when you reset your password — which also revokes every other session open on the account. During a password reset only, the site also sets a fourth, short-lived cookie, blok_reset_relay — scoped to the /reset-password path, held for at most ten minutes, and cleared as soon as the reset attempt finishes, whether it succeeds or fails. It exists so the reset token never appears in the address bar of the page where you set a new password.

Beyond those cookies, our hosting providers (Vercel for the website, Neon for the database) keep ordinary server request logs as part of running any web service — the kind of access logs any host keeps, not something Blok configures or reads. The email address you sign up with is also shared with Resend, the transactional email provider that sends account verification, password-reset and notification emails on Blok's behalf — it receives nothing beyond the address a given email is sent to. Blok itself runs no analytics, no advertising, and no tracking pixel of any kind.

What an account holds

Creating an account stores: your email address, whether and when it has been verified, a display name — given at sign-up, or taken from your Microsoft profile if you sign in that way — your role (student or admin), your stored colour-theme preference, the date you accepted these terms, and the timestamps of when the account was created and last updated. Your password is never stored in a readable form — only a one-way Argon2id cryptographic hash of it, using an algorithm designed so the original password cannot be recovered from the hash.

What study activity holds

Once you open a lecture, the site records that you viewed it, when you last viewed it, and whether you have marked each topic complete — so your dashboard can show you where you left off. In the question bank, it records which questions you have marked complete or for review. Nothing you write or answer is stored beyond those marks. Reading without an account records nothing.

Why each category is held

Account data exists to identify who is signed in and to keep your progress and preference data attached to the right person. Progress and question-bank marks exist so the site can show you where you left off and what you flagged to revisit. The theme and consent cookies exist because you set them yourself, by clicking something on the page.

How long data is kept

The theme cookie and the consent cookie each last up to a year from when they are set, or until you clear them. The session cookie lasts up to 30 days, refreshed by continued activity, and is cleared on sign-out or replaced on a password reset. The reset-relay cookie lasts at most ten minutes and is always cleared once a reset attempt finishes. An unverified account is cleared out once it is more than 24 hours old. Deleting your account anonymises the personal fields on it (email, name, image) and erases your lecture progress history; your question-bank marks stay attached to the anonymised account, which no longer identifies you.

How to have your data erased

To ask a question about this policy or to request that your data be erased, email support@blok.study — the same address linked from the Contact link in the footer of every page.

Blok uses only the cookies needed to run the site and remember your preferences. See our Privacy Policy.