Privacy Policy
Last updated: 25 August 2026
The short version
We collect what is needed to give you an account, run your code, remember your progress and take payment. We do not sell personal data, and we do not use your submissions to train our own models.
What we collect
- Account data — email address, name and profile picture, as provided by you or by the identity provider you sign in with.
- Practice data — the code you submit, the results of running it, quiz answers, progress, streaks and scores.
- Billing data — subscription status and plan. Card details are entered on our payment provider's side and never reach our servers.
- Technical data — logs and error reports containing IP address, browser and the page or endpoint involved, kept so the service can be debugged and protected against abuse.
Why we collect it
To create and secure your account, to execute and grade your submissions, to show you your own history and progress, to process subscriptions, to send transactional email (sign-in, billing, account notices), to rate-limit abuse, and to diagnose failures.
Code execution and the AI mentor
Code you submit runs in an isolated sandbox with no network access. It is stored against your account so you can see your own history.
When you ask the AI mentor for a review, the relevant challenge and the code you wrote are sent to Anthropic's API to produce the answer. That request is made per feature use, not in the background, and Anthropic acts as a processor for it.
Who processes data on our behalf
- Clerk — authentication and account management.
- Neon — the PostgreSQL database holding accounts, submissions and progress.
- Lemon Squeezy — payments and subscriptions, acting as merchant of record.
- Anthropic — the model behind the AI mentor, for the requests described above.
- Upstash — Redis used for caching and rate limiting.
- Resend — delivery of transactional email.
- Sentry and Axiom — error monitoring and application logs.
- Vercel and Railway — hosting.
Some of these operate outside the European Economic Area; where that is the case, transfers rely on the standard contractual clauses in their terms.
Cookies
We use the cookies our authentication provider needs to keep you signed in, and a small amount of browser storage for interface preferences such as your chosen list or grid view. We do not run advertising trackers.
How long we keep it
Account and practice data are kept while your account exists. Delete your account and they are deleted with it, except records we are required to keep for accounting, and backups, which age out on their own cycle. Logs and error reports are short-lived.
Your rights
You can ask for a copy of your data, correction of it, or its deletion, and you can object to a particular use. Write to support@codejump.io and we will answer within 30 days. If you are in the EU or UK and are not satisfied with our answer, you can complain to your national data protection authority.
Changes
If this policy changes in a way that affects you, the date at the top changes and we say so by email before the change takes effect.