Legal
Privacy and security policy
How we handle your personal data and Shipcode's security measures.
Last updated: September 10, 2026
1. Data controller
Shipcode ("we") is the controller of personal data collected through the site and platform.
Privacy contact: privacy@shipcode.dev.
2. Data we collect
We may process:
- Account data: email, username, avatar, and authentication identifiers (e.g. OAuth with GitHub).
- Usage data: project progress, code submissions for validation, and technical logs (IP, browser, timestamps).
- Mentor data: your questions, AI responses, the relevant stage context, and token usage.
- Billing data: managed by our payment provider; we do not store full card numbers.
- Communications: messages you send us via support or contact forms.
3. Purpose and legal basis
We use your data to provide the Service, authenticate you, save your progress, process payments, improve the platform, and comply with legal obligations.
Legal bases include contract performance (account and subscription), legitimate interest (security and product improvement), and consent when required by law (e.g. optional marketing communications).
4. Security measures
We apply reasonable technical and organizational measures to protect your data against unauthorized access, loss, or alteration.
Passwords are not stored in plain text. Traffic between your browser and our servers uses TLS encryption.
Infrastructure (database, authentication, storage, and execution sandboxes) relies on providers with recognized certifications. Cloud tests run without network access, credentials, or persistent storage and with resource limits.
If we detect a security breach affecting your rights, we will inform you and notify the supervisory authority when required.
5. Processors and transfers
We share data with providers that help us operate the Service (hosting, authentication, isolated test execution, essential analytics, payments, and AI inference). They are bound by contracts requiring confidentiality and adequate protection.
When you use the Pro mentor, we send your question and the relevant project context to the paid Gemini Developer API. We do not send your Shipcode user identifier, and Google states that paid prompts and responses are not used to improve its products.
If we transfer data outside the European Economic Area, we use appropriate safeguards (standard contractual clauses or other EU Commission-approved mechanisms).
6. Retention
We retain your data while you maintain an active account and as long as necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
A cloud test's code archive is deleted when execution finishes, and a lifecycle rule removes it within one day if cleanup fails. After you delete your account, we will delete or anonymize other personal data except what we must retain by law.
7. Your rights
You may access, rectify, erase, restrict, or object to processing, and request data portability when GDPR or equivalent regulations apply.
To exercise them, write to privacy@shipcode.dev. You may also file a complaint with the AEPD (www.aepd.es) or another authority in your country.
9. Changes to this policy
We may update this policy. We will publish the current version on this page with the revision date. We will notify you of relevant changes by email or platform notice when necessary.