Saltar al contenido principal

Data protection information

Privacy Policy

Last updated: July 26, 2026

This policy explains in plain language which personal data CodeaTu processes, why it uses it, and how you can exercise your rights. It applies to codeatu.com, user accounts, and its educational features.

Summary

Controller
Ángel González, the person responsible for CodeaTu.
Purposes
Account management, educational services, progress tracking, and platform security.
Legal bases
Performance of the requested service, consent, legitimate interests, and legal obligations.
Rights
Access, rectification, erasure, objection, restriction, portability, and complaint.

1. Data controller

Controller: Ángel González, the person responsible for the CodeaTu educational platform.

Privacy contact: kanto03@gmail.com.

2. Data we process

  • Account and identity: name, email address, profile image, login-provider identifier, role, group, and technical session data. This data comes from Google or GitHub when you choose one of them to sign in.
  • Learning activity: courses and sections completed, quiz and poll answers, code submitted for challenges, results, attempts, and points earned.
  • Content you provide: reviews, comments, or other communications you voluntarily submit.
  • Technical and security data: IP address, date and time, requested URL, browser, device, error logs, rate-limit data, and events needed to prevent abuse and maintain the service.
  • Data stored on your device: theme preference and, when you use the editors, code drafts or interface state stored in your browser.

We do not request special categories of personal data. Do not include personal or confidential information or secrets in code, reviews, or text fields.

3. Purposes and legal bases

PurposeLegal basis
Create your account, authenticate you, and maintain your session.Performance of the requested service (GDPR Art. 6(1)(b)).
Provide courses, grade exercises, and retain your progress.Performance of the requested service (GDPR Art. 6(1)(b)).
Manage reviews and communications you choose to send.Your consent or responding to your request (GDPR Arts. 6(1)(a) and 6(1)(b)).
Measure aggregated use and improve the website.Legitimate interest in improving the service (GDPR Art. 6(1)(f)).
Prevent abuse, resolve incidents, and protect the platform.Legitimate interest in security and, where applicable, legal obligations (GDPR Arts. 6(1)(c) and 6(1)(f)).

CodeaTu does not use your data to send advertising and does not sell personal data.

4. Providers and recipients

The following categories of providers may process data to operate the platform:

  • Google and GitHub: authentication providers you use voluntarily. Read the privacy policies of Google and GitHub.
  • Vercel: website hosting, delivery, and aggregated web analytics. Vercel Web Analytics does not use third-party cookies to identify you. Read its privacy and compliance information.
  • Database infrastructure: stores accounts, sessions, progress, answers, and reviews on CodeaTu's behalf.
  • Piston execution engine: receives the code, language, and input needed to run challenges. Evaluated code may also remain linked to your progress in CodeaTu.

Data may also be disclosed to authorities when legally required. Some providers may process information outside the European Economic Area; where applicable, the safeguards required by the GDPR and the provider's terms will be used.

5. Retention

  • Account and progress data is retained while you keep your account or while it is needed to provide the service.
  • Sessions are retained until they expire or are closed.
  • Reviews, answers, and code linked to progress are retained for the life of the account unless you request erasure and there is no lawful reason to retain them.
  • Technical, security, and audit logs are retained for the time needed to investigate incidents, prevent abuse, and meet legal responsibilities.
  • Locally stored data remains on your device until you replace it or clear your browser storage.

Afterwards, data may be kept blocked only for applicable statutory limitation periods and will be erased or anonymised when it is no longer needed.

6. Cookies and local storage

CodeaTu uses essential technical cookies to authenticate you, protect the sign-in flow, and maintain your session. It also uses browser storage to remember preferences and temporarily retain editor work. These technologies support features you request and are not used for advertising.

In production, Vercel Web Analytics provides aggregated statistics about pages, routes, approximate origin, and technical device characteristics. Under its standard setup, it does not set third-party cookies or create cross-site profiles.

You can clear or block this data in your browser, although doing so may sign you out or stop some features from remembering your preferences.

7. Your rights

You may request access to and rectification or erasure of your data, restriction of or objection to processing, and, where applicable, data portability. You may also withdraw consent at any time without affecting earlier lawful processing.

Send your request to kanto03@gmail.com and state which right you wish to exercise. We may request additional information when needed to verify your identity. Requests are generally answered within one month.

If you believe the processing breaches data-protection law, you may lodge a complaint with the Spanish Data Protection Agency (AEPD).

8. Automated grading and profiling

The platform automatically grades quizzes and challenges to calculate results and points. This assessment is educational and does not produce legal or similarly significant effects on you. CodeaTu does not create advertising profiles.

9. Children

Children under 14 must not create an account or submit data without authorisation from a parent or legal guardian. If we learn that data has been provided without the required authorisation, it may be erased. Use the privacy contact to request this.

10. Security and policy changes

We apply reasonable technical and organisational measures to reduce the risk of unauthorised access, alteration, loss, or disclosure. No internet-connected system can guarantee absolute security.

This policy may be updated when the service, providers, or law changes. The current version will be published here with its update date and, if a change is material, communicated through an appropriate channel.