CodePen: exposed!
Read the original on dbushell.com ↗I promise this post is not merely a comment on a Hacker News submission because good lord that would be desperate but that is where I’m starting:
They send all typed into editor input to codepen.dev almost immediately (you would see in 1-2 sec after you typed your secret that it appears in respective Network/Response tab) even before one saved it.
Apparently CodePen 2.0 sends data to their servers as you type
This post hit the front page with over 100 upvotes.
The author seems concerned as if CodePen is doing something untoward. In reality that behaviour should be fully expected. CodePen processes your code to generate a live preview. And to the relief of our browsers that’s done server-side without shipping a JavaScript bomb. CodePen has other features like live collaboration that require it too.
Technically an “autosave” feature can be done locally using browser storage but CodePen uses the server for that too. This allows users to restore unsaved changes from anywhere. You can test this by logging in cross browser, or deleting cached site data.

The author concludes:
Thus, if you ever entered some secrets in there by mistake consider them compromized even if you did not publish/save the pen
Yeah, of course. Don’t be so cavalier with sensitive data on your clipboard! This is true for all web-based editing software. Google Docs, etc. They’re effectively keyloggers by design.
User expectations
It does raise an interesting question: what is reasonable to expect users to understand? It’s easy to respond “Well duh!” to our Hacker News friend (and I did). But why did I expect CodePen to behave this way when others didn’t?
It’s a tricky question for product owners to handle. Burying details in the Terms of Service that nobody will ever read doesn’t help anyone (except lawyers).
Gamers Nexus on YouTube recently exposed LG TV spyware doing really insidious stuff. We all know smart devices phone home but LG’s tactics are another level. Probably illegal. Consumer (and human) rights are certainly a reasonable expectation!
The grey area between what’s obviously wrong and what’s reasonable to expect is murky.
I’d highly recommend the CodePen Radio podcast where the team discuss product design and development. It’s very insightful.
The license
There is one aspect of CodePen that I think is a much bigger concern for users and far less understood. This one is “hidden” in CodePen’s Terms of Service.
All public code snippets are MIT licensed:
Public Pens you build on CodePen are MIT licensed, meaning other people are free to use it for whatever they like under the terms of the MIT license. Don’t put anything on CodePen where that wouldn’t be OK.
I’ve seen a lot of stuff shared on CodePen where I wonder if the author intended, or even had permission, to effectively give it away for free.
Personally I think CodePen using the MIT license this way is a brilliant idea. It allows CodePen to do what it does. Most user-generated content websites have absurdly long terms around content rights. GitHub’s user-generated content section is just shy of 1500 words.
Using the MIT license solves this problem succinctly. I’ve pasted the entire license below. You really should have it memorised by now. It’s the Lord’s prayer for developers.
Copyright [YEAR] [COPYRIGHT HOLDER]
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
The MIT License - Open Source Initiative
This is not an advertisement for CodePen Pro but you can pay to retain ownership.
From what I’ve witnessed over the years, users (and developers) simply do not understand copyright and licenses. I’m surprised CodePen doesn’t make this a little clearer. But then again, I’ve not heard of any disputes over “stolen” code, so maybe it’s another non-issue?
With CodePen 2.0 exposing the file system I’d like to see a LICENSE.txt for every pen.

Would that work? What happens if users try to change or edit the license? Does it need to be locked? I don’t know the best solution but I’d like to see the MIT license visible.
No spicy drama here I’m afraid! Just a public service announcement and unanswered questions around user expectations. CodePen is not even selling your data for model training, what a bunch of bores! On that note, I guess with LLM code washing it doesn’t matter anymore :(
Thanks for reading! Follow me on Mastodon and Bluesky. Subscribe to my Blog and Notes or Combined feeds.