Privacy Policy
This describes what CodeOrbit stores about you and what you can do about it. It is written to be read, not to be survived.
Who is responsible
CodeOrbit is run by Timmie Hemmingsson, a sole trader in Sweden, trading as Vireo, at Vistop Kullen 1, 521 95 Kättilstorp, Sweden. That person is the data controller under the GDPR.
For any privacy question, including the requests described below, contact support@aver-web.se.
If you believe your data is being handled unlawfully you can complain to the Swedish Authority for Privacy Protection (IMY), imy.se.
What is stored, and why
Account. Your email address, display name and a hash of your password. Without these there is no account. Lawful basis: performance of a contract.
Profile. Username, and optionally a display name, avatar URL, bio and GitHub username. Your XP, level, continuity count and preferences (theme, language, timezone, preferred notification time) are stored here too. Lawful basis: performance of a contract.
Learning activity. Which algorithms you have opened and your status on each, your challenge results (score, time, comparisons, and your solution code if you submit it), and any badges awarded. This is the product. Lawful basis: performance of a contract.
Billing. If you subscribe, a record of the subscription and its status. Card numbers are never seen or stored by CodeOrbit — payment details go directly to Stripe or Google. Lawful basis: performance of a contract, and legal obligation for accounting records.
Usage analytics. Product events such as “challenge started” and “visualization opened”, linked to your account id — only if you say yes when CodeOrbit asks, on the web or in the app. Lawful basis: consent. Nothing is sent before you answer or after a no, and you can withdraw at any time in Settings → Privacy → Usage analytics. Withdrawing does not affect what was sent while your yes stood. Your answer is stored on your device so we do not ask again, and in the app the analytics library keeps an anonymous id and not-yet-sent events on the device while your yes stands.
Error reports. When something crashes, a technical report including the error, the page and your browser or device type. Lawful basis: legitimate interest in the product working.
Feedback you send. If you use Settings → Feedback, what you write and any screenshots you attach are stored, along with which category and area you picked, your account id, the platform and the app version. Free text and images are whatever you chose to put in them, so please leave out anything you would not want stored — the rest of this page is the only promise about what happens to it. Whether we may reply is a separate question in the form, off unless you turn it on. Lawful basis: legitimate interest in fixing what is reported, and consent for the reply.
The launch note. If you ask for the launch note on the landing page, the address you enter is stored together with the project you asked about, your language and where the request came from (the campaign parameters in the link you used). One confirmation email is sent first; an unconfirmed address is deleted after three days. A confirmed address is kept with Resend (EU region) until you unsubscribe, which every email we send lets you do. Lawful basis: consent, withdrawable at any time.
Each submission is also emailed to the person who maintains CodeOrbit, so that it is read rather than queued. That message contains what you wrote, the category and area, and a link to any screenshots. It goes through Resend and arrives in an ordinary mailbox, which means a copy of your report exists outside the systems the deletion below can reach — if you later delete your account, the stored submission goes with it, but a message already sent cannot be recalled. Please bear that in mind when deciding what to include.
Your username, avatar, level and XP are publicly readable — they appear on leaderboards and shared results. Nothing else is.
What is not done
- Your data is never sold, rented or traded.
- There is no advertising, and no advertising or cross-site tracking pixels.
- No profile is built about you for anyone else’s purposes.
- Fonts are self-hosted, so loading a page does not tell a font provider you were here.
Who else processes it
These are the only third parties involved, and only for the stated purpose:
- Appwrite — the database and authentication. Self-hosted on infrastructure controlled by the operator, in the EU.
- Cloudflare — hosting, the API, and object storage for generated share images and any screenshots attached to feedback.
- Stripe — subscription payments on the web. Stripe receives your payment details directly; CodeOrbit never sees them.
- Google Play — subscription payments in the Android app, on the same basis.
- PostHog — product analytics.
- Sentry — error reporting.
- Resend — product email: the welcome message, payment receipts, and the notification sent when you submit feedback, and the launch-note list with its confirmation email. Your email address is shared, and for a feedback notification so is what you wrote and which account it came from, because the notification carries the report itself. Account verification and password resets are sent by Appwrite, not by Resend.
Some of these operate outside the EU. Where they do, transfers rely on the European Commission’s Standard Contractual Clauses.
How long it is kept
Account and learning data is kept while your account exists. Delete the account and it is erased immediately — see below, and that includes the subscription and purchase records held here.
Accounting records of payments are kept until the end of the seventh year after the calendar year in which the financial year closed, because Swedish bookkeeping law requires it (bokföringslagen 7 kap. 2 §). Those live with Stripe and Google, who are the ones processing the payment; CodeOrbit does not retain a copy after the account is gone.
Your rights, and how to actually use them
Under the GDPR you can ask for a copy of your data, correct it, have it deleted, object to processing based on legitimate interest, withdraw a consent you have given, or ask for it in a portable format. Two of those are buttons rather than emails:
- Get a copy. Settings → Privacy → Export downloads everything held about you as JSON, immediately.
- Delete everything. Settings → Account → Delete account erases your profile, progress, results, badges, feedback and account immediately and irreversibly. Images go with it: the screenshots attached to your feedback and any share images generated from your results are deleted from object storage, not merely unlinked. Cancel any subscription first. While one is active or in a trial we refuse the deletion rather than leave you paying for an account that is gone, and that refusal lasts until the period you have paid for ends. In any other state — a lapsed payment among them — the deletion goes through, and nothing here cancels anything with Stripe or Google Play, so check that billing has actually stopped before you delete.
For anything else, email the address above. A response is due within one month under Art. 12(3).
Children
CodeOrbit is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child has an account here, email the address above and it will be removed.
Changes
If this policy changes materially you will be told by email before the change takes effect. The date at the top always reflects the current version.