Last updated 28 August 2026

Privacy Policy

What codeset collects, why, who else processes it, how long we keep it, and how to have it deleted.

1. Who is responsible

The controller of your personal data is Codeset, Lda, Avenida Mouzinho de Albuquerque, N.º 48, 5.º B, 1170-265 Lisboa, Portugal, NIPC 518962938. For anything in this policy, write to hello@codeset.ai.

We are not required to appoint a Data Protection Officer, and have not.

2. What we hold

What you give us

  • Account. When you sign in with Google we receive your email address, your name and your Google account identifier. We never see your Google password.
  • Your learner overview. What you want to learn, why, and what you already know, written during onboarding and revised as the course goes on.
  • Tutor conversations. The full transcript of what you and the tutor say to each other, including your answers to questions and assessments.
  • Your work. The files in your workspace and the code you run in the sandbox.
  • Billing details. If you pay, your name, billing address and any VAT number go to Stripe, who process the card. We store a Stripe customer reference, your credit ledger, and the invoices we are required to issue. We never receive or store your card number.
  • Coupons. If you redeem a coupon, we store which code you redeemed, when, what it granted you and when any gifted plan ends. A gifted plan is an entitlement on your account, not a Stripe subscription; no card is asked for. If you later subscribe, that purchase goes through Stripe like any other.
  • Feedback. If you send feedback, we store the message, the page you sent it from, and any screenshot you attach.
  • Waitlist. While signups are closed, we keep the email address and name from a sign-in attempt that would have created an account, so we can write to you when a place opens. We keep nothing else, and we create no account. Unsubscribe from that mail and we keep the address only so we do not write again. Ask us and we delete the entry.
  • Email preferences. If you opt in to product updates or inactivity reminders, we store when you consented and when you withdrew that consent, and a record that we sent you a message of a given kind.
  • Vibecoding test. The public quiz can be taken without an account. If you sign in to save a result, we store the verdict, score, language, elapsed time and the one-sentence roast shown to you. Missed answers are not kept on that row. We also count each finished attempt in an anonymous per-language score tally, which is what the “you scored better than X%” comparison is drawn from. That tally holds no identifiers, only how many people got each score.
  • Shared test boards. If you take the test through a room link, the name you type, your score, time and roast are shown to anyone holding that link. A room is not tied to an account: we keep a random token in your browser to recognise your own row, and nothing on the board identifies you beyond the name you chose. Rooms and everything in them are deleted once nobody has opened them for 90 days.

What the service produces about you

  • Progress. Which lessons you have completed, assessment attempts and results, and the tutor's running notes on what you have grasped and what you haven't.
  • Model call logs. Every request we send to a language model on your behalf, stored with the prompt and the response verbatim. We use these to debug lesson quality and account for cost. They are deleted on a fixed schedule (see below). Taking the public vibecoding test sends the questions you missed to the model to write the roast sentence; those prompts sit in the same log, whether or not you have an account.
  • Usage and operations. Sandbox and workspace minutes, credit transactions, sign-in sessions, and server logs including IP address and browser.

What we send you

We email the address on your Google account. There are no tracking pixels in those messages, and we do not build a marketing audience at the email provider — we send one message at a time from our own records.

  • Welcome. When you create an account. Contract: the account exists, and this tells you so.
  • Waitlist invite. One email when a place opens, if you tried to sign up while we were full. Legitimate interests, the same basis as holding the waitlist row. Unsubscribe from that mail and we will not write again.
  • Inactivity reminder and product updates. Only if you opt in. That choice is off by default, asked after you create an account (and again from your profile), and is not part of accepting the terms. Consent, which you can withdraw immediately from the link in the email or from your profile.
  • Gifted plan ended. One email when a plan you redeemed with a coupon runs out. Contract: it tells you the access you had has changed.
  • Invoices. The Portuguese fatura for a payment, sent through TOCOnline. Legal obligation.

What we don't do

No advertising, no profiling, no tracking you across the web. The only measurement we run is Plausible, an EU-hosted analytics service that counts page views and a small set of product events (starting a course, finishing a lesson, beginning checkout) without cookies, without a device fingerprint and without an identifier that follows you between sites or sessions. It tells us that a page was visited or that an action happened, roughly from where and from which referrer; it does not tell us that you visited it. There is no Google Analytics here, no advertising pixel and no behavioral profile. We set two cookies, both required to keep you signed in and connect you to your sandbox; the whole list is in the Cookie Policy. That is also why you have not been asked to accept cookies: nothing we store on your device needs your consent.

We do not sell personal data, and we do not use your private work to train models, neither ours nor anyone else's.

3. Why we are allowed to hold it

Under the GDPR, each thing we do has a legal basis:

WhatBasis
Running your account, teaching you, running your code, taking paymentContract (Art. 6(1)(b)): without it there is no service to provide.
Issuing invoices and keeping accounting recordsLegal obligation (Art. 6(1)(c)): Portuguese tax law requires it.
Model call logs, server logs, cookieless page-view and product-event statistics, abuse prevention, improving the tutor, and the signup waitlistLegitimate interests (Art. 6(1)(f)): keeping the service working, correct and affordable, and letting in the people who asked to join. The logs carry a fixed expiry and are not used to profile you.
Anything you opt into that isn't covered above, including product updates and inactivity remindersConsent (Art. 6(1)(a)): which you can withdraw at any time, from the email or from your profile. Withdrawal is immediate.

4. How long we keep it

DataKept for
Model call logs (your prompts and the model's replies, verbatim)90 days, then deleted automatically
Tutor transcripts, progress, learner overview, workspace files, saved vibecoding-test attemptsAs long as your account exists
Sign-in sessions7 days, or until you sign out
Waitlist entry (email and name, while signups are closed)Until you get an account or ask us to remove it. If you unsubscribe, we keep the address only so we do not write again.
Email consent record and send logAs long as your account exists; deleted with the account
Feedback you send usAs long as your account exists
Invoices and accounting records10 years, as Portuguese tax law requires; this outlives your account
Aggregate usage counters, once your account is deletedRetained without any link to you

The 90-day period is enforced by a scheduled job that deletes the rows.

5. Who else processes it

We use the companies below to run codeset. They process your data on our instructions, under contract, and for nothing else.

ProcessorWhat forWhere
Microsoft Ireland Operations Ltd. (Azure)Hosting: the database (accounts, courses, transcripts, billing records), your workspace files and generated audio, the models that teach and mark, the sandboxes that run your code, and the email we send youEU (West Europe)
Google Ireland LimitedSign-in. We receive your email address, name and Google account idEU and United States
Stripe Payments Europe, Ltd.Payments, subscriptions, billing address and VAT id, tax calculationEU and United States
Cloudflare, Inc.DNS and TLS for our domainsGlobal edge network
Cloudware (TOConline)Issuing the certified Portuguese invoice (fatura) for each paymentPortugal
Plausible Insights OÜPage-view and product-event statistics. No cookies, no cross-site tracking, no profile of you as an individualEU (Estonia and Germany)

Everything we host (your account, your transcripts, your files, and the models that teach you) runs in the European Union. Where a processor is reachable from outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision. Ask us and we will tell you which applies to whom.

Beyond those processors, we disclose personal data only when the law requires it (a court order or a lawful request from an authority) or when it is necessary to establish or defend a legal claim. If codeset is ever sold, your data may transfer with it, and this policy continues to apply until you are told otherwise.

6. Your rights

You can ask us to:

  • Show you what we hold about you, and give you a copy;
  • Correct anything that is wrong;
  • Delete your account and its data;
  • Export your data in a portable format;
  • Restrict or object to processing we do on the basis of legitimate interests;
  • Withdraw consent you have given, without affecting what we did before.

You can delete your account yourself from your profile. For anything else, email hello@codeset.ai from the address on your account and we will respond within one month.

Deleting your account is permanent. Your transcripts, progress, generated courses, workspace files, stored audio and saved vibecoding-test attempts are erased, and we cannot restore them. Two things deliberately survive: invoices we are legally required to keep for 10 years, and operational counters with your identity stripped out. Courses you published stay published, without your name attached; tell us first if you want them taken down instead.

You also have the right to complain to a supervisory authority. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD). If you live elsewhere in the EU, you can complain to your own national authority.

7. Security

Your session cookie is HttpOnly, so no script running on the page can read it. Sandboxes are isolated per project and torn down when idle, and untrusted previews of your code are served from a separate hostname so they cannot reach your session. Data is encrypted in transit and at rest. Access to production data is limited to the people who need it to operate the service.

If a breach puts your rights at risk, we will notify the CNPD within 72 hours and tell you directly where the law requires it.

8. Children

codeset is not aimed at children, and we do not knowingly collect data from anyone under 13. If you believe a child has given us personal data, write to hello@codeset.ai and we will delete it.

9. Changes

If we change how we handle your data, we will update this page and the date at the top, and for material changes we will tell you before they take effect. The list of processors above is the current one.

Adapted from Legalmattic by Automattic, used under CC BY-SA 4.0. This page is likewise available under CC BY-SA 4.0.