Legal

Privacy Policy

How we collect, use, and protect your personal data.

Last updated: September 21, 2026

1. About this Policy

This Privacy Policy explains how codeseed.app ("codeseed.app", "we", "us", or "our") collects, uses, stores, and protects personal data when you use our platform at codeseed.app (the "Service"). It applies to all users worldwide, including residents of the European Union, the United Kingdom, California (USA), Brazil, and Canada. It should be read together with our Terms of Service, which governs your use of the Service more broadly.

This Policy is written in compliance with the following legal frameworks, whichever applies to you based on your location:

  • EU General Data Protection Regulation (GDPR) 2016/679
  • UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
  • Brazil's Lei Geral de Proteção de Dados (LGPD) — Federal Law No. 13,709/2018
  • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
  • EU ePrivacy Directive 2002/58/EC (Cookie Law)
  • Children's Online Privacy Protection Act (COPPA) — for US residents under 13

By using codeseed.app, you acknowledge that you have read and understood this Policy.

2. Who We Are (Data Controller)

codeseed.app is the data controller responsible for your personal data. We are based in Romania, a member state of the European Union, and operate under EU law.

Data Controller: codeseed.app (registered legal entity name and address: [TODO: confirm legal entity name], [TODO: confirm registered address])
Contact: privacy@codeseed.app
Supervisory Authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — Romania

2.1 Data Protection Officer

We have not appointed a Data Protection Officer. Based on the scope of processing described in this Policy, we do not believe our processing activities meet the GDPR Article 37 threshold that would require one (we do not carry out large-scale systematic monitoring or large-scale processing of special categories of data). [TODO: confirm this assessment, or appoint a DPO, before relying on it]. For any privacy question or request, contact us at privacy@codeseed.app.

3. What Personal Data We Collect

3.1 Account data (collected via GitHub OAuth)

  • GitHub user ID (numeric, used as unique identifier)
  • GitHub username / handle (e.g. @johndoe)
  • Display name (as set on your GitHub profile)
  • Primary email address associated with your GitHub account
  • Profile avatar URL (hosted on GitHub's servers)

3.2 Platform activity data

  • Projects you have claimed and their status (active, completed, abandoned)
  • Your current progress step within a claimed project
  • GitHub repository URL of your project repo
  • Number of commits pushed to your project repo (synced via GitHub webhooks)
  • AI verification results and feedback for your project steps
  • Your role on the platform (learner, mentor, or both)

3.3 Communication data

  • Messages exchanged between you and a mentor or learner — stored in our database, accessible only to the two participants in a claim. codeseed.app staff can access this data only in response to a valid legal order.
  • Notification content (e.g. 'Your PR was reviewed') — stored unencrypted.

3.4 Technical data

  • IP address and browser type/version — recorded in the session record created each time you sign in (used for security and abuse prevention), and stored persistently in our database for as long as that session record exists. See §7.3 for how long that is.
  • Session tokens (stored in secure, HttpOnly cookies managed by Better Auth — expire after logout)
  • Timestamps of account creation and last activity

3.5 Data you choose to provide

  • Project ideas submitted as a mentor (title, description, steps, resources, tech stack)
  • Preferred programming language and experience level (set in Settings)

4. How We Collect Your Data

  • Directly from you when you sign in with GitHub (OAuth 2.0 flow via Better Auth)
  • Automatically via our platform as you use the Service (project claims, messages, notifications)
  • From GitHub, via our GitHub App — a single installation owned by codeseed.app, not installed on your personal account — when you push commits, open pull requests, or trigger webhooks on the private repository we create for you under our organization

If you are in the EU, EEA, or UK, we process your personal data under the following legal bases:

5.1 Performance of a contract (Art. 6(1)(b))

Processing your account data, project claims, and GitHub integration data is necessary to provide the Service you have requested. Without this data, we cannot create your account, create your project repository, or connect you with mentors.

5.2 Legitimate interests (Art. 6(1)(f))

We process certain technical data (IP addresses, session logs, error logs) based on our legitimate interest in securing the platform, preventing abuse, and improving the Service. We have carried out a balancing test and determined that our interests do not override your rights and freedoms, given the minimal and security-focused nature of this processing.

5.3 Compliance with a legal obligation (Art. 6(1)(c))

We may retain certain data if required by applicable EU or Romanian law (e.g. for tax or accounting purposes if applicable, or in response to a valid legal order).

5.4 Consent (Art. 6(1)(a))

Where we rely on your consent (e.g. for non-essential cookies, if any are introduced in the future), you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

6. How We Use Your Data

  • Create and maintain your codeseed.app account
  • Display your profile (handle, avatar) to mentors and learners you interact with
  • Match you with appropriate projects based on your language and level preferences
  • Create a private GitHub repository for you when you claim a project
  • Track your project progress and sync commit activity via GitHub webhooks
  • Deliver notifications about PR reviews, mentor messages, and claim updates
  • Restrict access to messages between a learner and mentor to the two participants in that claim
  • Generate AI verification feedback as you complete each project step
  • Send transactional emails (e.g. review notifications) via our email provider
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations applicable to us

7. Data Retention

7.1 Active accounts

We retain your personal data for as long as your account is active and as long as necessary to provide the Service.

7.2 After account deletion

  • Your profile and the claims, chat messages, and notifications tied to projects you claimed as a learner are permanently erased from our production database immediately upon your request — not on a delay. This includes the entire chat thread for each of those claims, not just messages you personally sent: because the thread only exists in the context of your claim, a mentor's messages within it are erased too when you delete your account.
  • Messages you sent elsewhere (e.g. as a mentor on someone else's claim, or in the shared general chat channel) are kept so the conversation stays intact for the other participant, but are disconnected from your identity at the same time your account is deleted — they no longer show as sent by you.
  • Existing email delivery log entries for your email address are erased at the same time as the rest of your account. The one exception is the deletion-confirmation email itself, whose delivery log entry is created after your account is already gone — it falls under the 180-day technical-log retention in §7.3 below like any other email log, rather than being erased immediately.
  • We run our own automated daily encrypted backup of the production database, retained for 14 days on a rolling basis before being overwritten — so a backup taken shortly before your deletion request may retain a copy of erased data for up to 14 days afterward. These backups exist only to recover from an operational incident (e.g. a bad deployment or accidental data loss); we do not use them to reconstruct or reinstate a deleted account.
  • If you claimed a project as a learner, the private GitHub repository created for it is queued for deletion at the same time your account is deleted, and a mentor's collaborator access to a repository they mentor on is queued for revocation the same way. This GitHub-side cleanup runs asynchronously with automatic retries (it is not necessarily instantaneous) and is not a precondition for your account and platform data being erased — a temporary GitHub outage never delays or blocks the deletion of your account itself.
  • Any data our self-hosted analytics script independently collects when you browse the site (see §10.3) is not touched by account deletion — we do not send it your name, email, or GitHub handle in the first place, so there is nothing identifying you there for us to delete.
  • Anonymised aggregate statistics (e.g. total claim counts per project) may be retained indefinitely as they cannot identify you.

7.3 Technical logs

  • Authentication session records (Better Auth, including the IP address and browser type described in §3.4): 90 days, automatically deleted by a scheduled job.
  • GitHub webhook delivery logs: 30 days, automatically deleted by a scheduled job.
  • Email delivery logs (record of each notification, welcome, or account email sent — not its contents): 180 days, automatically deleted by a scheduled job.
  • Application error logs: written only to our own server's structured console/container logs — not sent to any third-party error-tracking service, and not stored in a database table with its own retention job. Their retention is governed by our hosting platform's own log rotation, not a specific number of days we set ourselves.

7.4 Legal holds

If we are required by law to retain data for a longer period (e.g. under Romanian accounting law or a valid legal order), we will retain only the minimum data required and for the minimum duration required.

8. Third-Party Processors & Data Sharing

We share your personal data with the following third-party processors, each bound by a Data Processing Agreement (DPA) and appropriate safeguards:

Hetzner Online GmbH

Location: Germany (EU) — our server is specifically in Hetzner's Helsinki, Finland datacenter

Purpose: Dedicated server hosting for our application infrastructure, our self-hosted PostgreSQL database, and our self-hosted analytics — this is where your account, project, and platform activity data is stored at rest, and where requests are processed. Not a US company, and no data-hosting region ambiguity: we control the server directly.

Safeguard: GDPR-compliant EU processor, DPA in place

Privacy policy: hetzner.com/legal/privacy-policy

GitHub, Inc. (Microsoft)

Location: United States

Purpose: OAuth authentication, repository management, webhook events

Safeguard: SCCs + DPA

Privacy policy: docs.github.com/en/site-policy/privacy-policies

Mistral AI

Location: France (EU)

Purpose: AI step verification and cross-user verification reuse. Mistral AI is headquartered in the EU and natively subject to GDPR, not a US company processing data under a transfer mechanism.

Safeguard: EU-based processor, GDPR-native DPA. Prompt content is not used to train Mistral's models unless we explicitly opt in, which we do not.

Privacy policy: mistral.ai/terms/#privacy-policy

Namecheap, Inc. (Private Email)

Location: United States

Purpose: Transactional email delivery via SMTP (welcome emails, notification emails, account deletion confirmations) — sent through Namecheap's Private Email SMTP service.

Safeguard: [TODO: confirm whether a Data Processing Agreement or Standard Contractual Clauses are in place with Namecheap for this account before relying on this as a safeguard.]

Website analytics (self-hosted)

Location: Same infrastructure as our application (see Hetzner, above)

Purpose: Aggregate website traffic and usage measurement, served from our own analytics.codeseed.app subdomain rather than a third-party analytics company.

Safeguard: Self-hosted on our own EU infrastructure; not shared with an external analytics vendor.

We do not share your personal data with any other third parties, except where required by law (e.g. in response to a valid court order or request from a competent authority). In such cases, we will notify you where legally permitted to do so.

9. International Data Transfers

codeseed.app is based in the EU (Romania). Our application servers, our database, and our analytics all run on Hetzner infrastructure in Helsinki, Finland (EU) — this covers the large majority of where your data actually resides and is processed. Only two of our processors are US companies: GitHub and our email provider, Namecheap (see Section 8). Mistral AI, our AI processor, is EU-based and is not a transfer-to-the-US situation at all. The United States does not have an EU adequacy decision covering all transfers. For the two US processors, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46(2)(c), where incorporated in our DPA with a given US processor — see Section 8 for the confirmed safeguard for each individual processor; where that is not yet confirmed, this mechanism is not yet relied upon for that processor
  • Where applicable, the EU-US Data Privacy Framework (for processors certified under it)

For UK users: transfers are governed by the UK's International Data Transfer Agreements (IDTAs) or the Addendum to EU SCCs approved by the UK ICO.

For Brazilian users: transfers are carried out in accordance with LGPD Articles 33–36, using contractual mechanisms equivalent to SCCs.

10. Cookies & Local Storage

This section summarizes our cookie and storage use. For the full, itemized list — exact cookie names, purpose, duration, and attributes — see our dedicated Cookie Policy.

10.1 Strictly necessary cookies

We use only strictly necessary cookies, which do not require your consent under the ePrivacy Directive and GDPR:

  • better-auth.session_token: Better Auth session token. In production this is served as __Secure-better-auth.session_token (the __Secure- prefix is added automatically whenever the cookie is set over HTTPS). HttpOnly, Secure (in production), SameSite=Lax. Expires after logout or after 7 days.
  • better-auth.session_data: a short-lived (5 minute) cache of your session, used to avoid a database lookup on every request. Same __Secure- prefixing (in production) and HttpOnly/Secure/SameSite=Lax attributes as the session token above.

We do not set a separate CSRF-token cookie. Cross-site request forgery protection on authentication itself comes from the SameSite=Lax attribute on the cookies above (which stops them being sent on cross-site requests) together with Better Auth's built-in origin validation on its own authentication endpoints, not from a dedicated token cookie.

10.2 Local storage

We do not store personal data in browser local storage or session storage. Session state is managed entirely server-side by Better Auth via the cookies listed above.

10.3 Website analytics

We use a self-hosted, first-party website analytics script, served from analytics.codeseed.app — a domain we operate ourselves, not a third-party analytics company. It loads on every page to measure aggregate traffic and usage (e.g. page views, referrers). We do not use Google Analytics, Meta Pixel, advertising trackers, or any third-party ad-tech tracking technology, and we do not pass your name, email, or GitHub handle to this script. Its own cookie and data-retention behavior is governed by the analytics software itself; we have not independently audited that behavior for the purposes of this policy.

11. Your Rights

11.1 Rights for EU/EEA and UK residents (GDPR / UK GDPR)

Under the GDPR and UK GDPR, you have the following rights with respect to your personal data:

  • Right of access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): Correct inaccurate or incomplete personal data — most profile data can be updated directly via GitHub or our Settings page.
  • Right to erasure (Art. 17): Request deletion of your personal data ('right to be forgotten'). You can delete your account at any time via Settings → Delete Account.
  • Right to restriction of processing (Art. 18): Ask us to restrict processing of your data in certain circumstances.
  • Right to data portability (Art. 20): Receive your personal data in a structured, machine-readable format. Use Settings → Export Data.
  • Right to object (Art. 21): Object to processing based on legitimate interests.
  • Rights related to automated decision-making (Art. 22): We do not carry out fully automated decision-making with legal or significant effects.
  • Right to withdraw consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time without affecting prior processing.

11.2 Rights for California residents (CCPA/CPRA)

  • Right to know: Request disclosure of the categories and specific pieces of personal information we collect, use, and share.
  • Right to delete: Request deletion of your personal information — use Settings → Delete Account.
  • Right to correct: Request correction of inaccurate personal information we hold about you.
  • Right to opt out of sale or sharing: We do NOT sell or share your personal information for cross-context behavioural advertising. No opt-out mechanism is required.
  • Right to non-discrimination: We will not discriminate against you for exercising any CCPA rights.
  • Sensitive personal information: We do not collect or use sensitive personal information beyond what is necessary to provide the Service, and we do not use it for inferring characteristics.

11.3 Rights for Brazilian residents (LGPD)

  • Confirmation and access to your data
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymisation, blocking, or deletion of unnecessary or excessive data
  • Data portability
  • Deletion of data processed with consent
  • Information about third-party entities with which your data is shared
  • Information about the possibility of denying consent and the consequences
  • Revocation of consent

11.4 Rights for Canadian residents (PIPEDA)

You have the right to access personal information we hold about you and to challenge its accuracy and completeness. Contact us at privacy@codeseed.app.

11.5 How to exercise your rights

To exercise any of the above rights, contact us at privacy@codeseed.app. We will respond within 30 days (or 45 days where permitted by law). We may ask you to verify your identity before processing your request.

12. Children's Privacy

codeseed.app is not directed at children. The minimum age to use codeseed.app is:

  • 16 years in the EU/EEA and UK (digital consent age under GDPR Art. 8 — or the applicable age in your EU member state if lower, such as 13 in Germany or 14 in Austria and Italy)
  • 13 years in the United States (subject to COPPA)
  • 13 years in other jurisdictions, unless local law requires a higher age

Additionally, since codeseed.app requires a GitHub account, users must meet GitHub's minimum age requirement (13 years), which applies regardless of location.

We do not knowingly collect personal data from children below the applicable minimum age. If we become aware that we have collected data from a child below this age, we will delete that data promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@codeseed.app.

13. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure:

  • All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS)
  • Messages between learners and mentors are accessible only to the two participants in a claim — enforced at the application layer
  • Database access is controlled by application-level authorisation checks in our API — unauthenticated requests are rejected before reaching the database
  • Authentication is handled by Better Auth with GitHub OAuth — we never store passwords
  • Session tokens are stored in HttpOnly, Secure, SameSite=Lax cookies — inaccessible to JavaScript
  • Security headers are set on all responses: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), and Permissions-Policy
  • API rate limiting is in place to prevent abuse — per-IP limits apply to all public write endpoints
  • Access to production infrastructure is restricted to authorised personnel only via SSH key authentication
  • Third-party processors are contractually required to implement equivalent security standards

No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it responsibly to privacy@codeseed.app.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices or applicable law. When we make material changes, we will:

  • Update the 'Last updated' date at the top of this page
  • Post a notice in the platform's Changelog
  • Send an email notification to registered users where required by law

We encourage you to review this Policy periodically. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy, to the extent permitted by law.

15. Contact & Complaints

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Email: privacy@codeseed.app
Response time: Within 30 days

If you are in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority. The lead supervisory authority for codeseed.app is:

ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
B-dul G-ral Gheorghe Magheru 28-30, Sector 1, 010336 București, România
www.dataprotection.ro

UK residents may contact the Information Commissioner's Office (ICO). California residents may contact the California Attorney General.