Legal

Privacy and security policy

How we handle your personal data and Shipcode's security measures.

Last updated: September 10, 2026

1. Data controller

Shipcode ("we") is the controller of personal data collected through the site and platform.

Privacy contact: privacy@shipcode.dev.

2. Data we collect

We may process:

  • Account data: email, username, avatar, and authentication identifiers (e.g. OAuth with GitHub).
  • Usage data: project progress, code submissions for validation, and technical logs (IP, browser, timestamps).
  • Mentor data: your questions, AI responses, the relevant stage context, and token usage.
  • Billing data: managed by our payment provider; we do not store full card numbers.
  • Communications: messages you send us via support or contact forms.

3. Purpose and legal basis

We use your data to provide the Service, authenticate you, save your progress, process payments, improve the platform, and comply with legal obligations.

Legal bases include contract performance (account and subscription), legitimate interest (security and product improvement), and consent when required by law (e.g. optional marketing communications).

4. Security measures

We apply reasonable technical and organizational measures to protect your data against unauthorized access, loss, or alteration.

Passwords are not stored in plain text. Traffic between your browser and our servers uses TLS encryption.

Infrastructure (database, authentication, storage, and execution sandboxes) relies on providers with recognized certifications. Cloud tests run without network access, credentials, or persistent storage and with resource limits.

If we detect a security breach affecting your rights, we will inform you and notify the supervisory authority when required.

5. Processors and transfers

We share data with providers that help us operate the Service (hosting, authentication, isolated test execution, essential analytics, payments, and AI inference). They are bound by contracts requiring confidentiality and adequate protection.

When you use the Pro mentor, we send your question and the relevant project context to the paid Gemini Developer API. We do not send your Shipcode user identifier, and Google states that paid prompts and responses are not used to improve its products.

If we transfer data outside the European Economic Area, we use appropriate safeguards (standard contractual clauses or other EU Commission-approved mechanisms).

6. Retention

We retain your data while you maintain an active account and as long as necessary to comply with legal obligations, resolve disputes, or enforce our agreements.

A cloud test's code archive is deleted when execution finishes, and a lifecycle rule removes it within one day if cleanup fails. After you delete your account, we will delete or anonymize other personal data except what we must retain by law.

7. Your rights

You may access, rectify, erase, restrict, or object to processing, and request data portability when GDPR or equivalent regulations apply.

To exercise them, write to privacy@shipcode.dev. You may also file a complaint with the AEPD (www.aepd.es) or another authority in your country.

8. Cookies and similar technologies

We use strictly necessary cookies for session and security. Analytics or marketing cookies, if any, will only be activated with your consent when required by law.

You can manage preferences from your browser settings.

9. Changes to this policy

We may update this policy. We will publish the current version on this page with the revision date. We will notify you of relevant changes by email or platform notice when necessary.