Last updated 28 August 2026
Privacy Policy
What codeset collects, why, who else processes it, how long we keep it, and how to have it deleted.
1. Who is responsible
The controller of your personal data is Codeset, Lda, Avenida Mouzinho de Albuquerque, N.º 48, 5.º B, 1170-265 Lisboa, Portugal, NIPC 518962938. For anything in this policy, write to hello@codeset.ai.
We are not required to appoint a Data Protection Officer, and have not.
2. What we hold
What you give us
- Account. When you sign in with Google we receive your email address, your name and your Google account identifier. We never see your Google password.
- Your learner overview. What you want to learn, why, and what you already know, written during onboarding and revised as the course goes on.
- Tutor conversations. The full transcript of what you and the tutor say to each other, including your answers to questions and assessments.
- Your work. The files in your workspace and the code you run in the sandbox.
- Billing details. If you pay, your name, billing address and any VAT number go to Stripe, who process the card. We store a Stripe customer reference, your credit ledger, and the invoices we are required to issue. We never receive or store your card number.
- Coupons. If you redeem a coupon, we store which code you redeemed, when, what it granted you and when any gifted plan ends. A gifted plan is an entitlement on your account, not a Stripe subscription; no card is asked for. If you later subscribe, that purchase goes through Stripe like any other.
- Feedback. If you send feedback, we store the message, the page you sent it from, and any screenshot you attach.
- Waitlist. While signups are closed, we keep the email address and name from a sign-in attempt that would have created an account, so we can write to you when a place opens. We keep nothing else, and we create no account. Unsubscribe from that mail and we keep the address only so we do not write again. Ask us and we delete the entry.
- Email preferences. If you opt in to product updates or inactivity reminders, we store when you consented and when you withdrew that consent, and a record that we sent you a message of a given kind.
- Vibecoding test. The public quiz can be taken without an account. If you sign in to save a result, we store the verdict, score, language, elapsed time and the one-sentence roast shown to you. Missed answers are not kept on that row. We also count each finished attempt in an anonymous per-language score tally, which is what the “you scored better than X%” comparison is drawn from. That tally holds no identifiers, only how many people got each score.
- Shared test boards. If you take the test through a room link, the name you type, your score, time and roast are shown to anyone holding that link. A room is not tied to an account: we keep a random token in your browser to recognise your own row, and nothing on the board identifies you beyond the name you chose. Rooms and everything in them are deleted once nobody has opened them for 90 days.
What the service produces about you
- Progress. Which lessons you have completed, assessment attempts and results, and the tutor's running notes on what you have grasped and what you haven't.
- Model call logs. Every request we send to a language model on your behalf, stored with the prompt and the response verbatim. We use these to debug lesson quality and account for cost. They are deleted on a fixed schedule (see below). Taking the public vibecoding test sends the questions you missed to the model to write the roast sentence; those prompts sit in the same log, whether or not you have an account.
- Usage and operations. Sandbox and workspace minutes, credit transactions, sign-in sessions, and server logs including IP address and browser.
What we send you
We email the address on your Google account. There are no tracking pixels in those messages, and we do not build a marketing audience at the email provider — we send one message at a time from our own records.
- Welcome. When you create an account. Contract: the account exists, and this tells you so.
- Waitlist invite. One email when a place opens, if you tried to sign up while we were full. Legitimate interests, the same basis as holding the waitlist row. Unsubscribe from that mail and we will not write again.
- Inactivity reminder and product updates. Only if you opt in. That choice is off by default, asked after you create an account (and again from your profile), and is not part of accepting the terms. Consent, which you can withdraw immediately from the link in the email or from your profile.
- Gifted plan ended. One email when a plan you redeemed with a coupon runs out. Contract: it tells you the access you had has changed.
- Invoices. The Portuguese fatura for a payment, sent through TOCOnline. Legal obligation.
What we don't do
We do not sell personal data, and we do not use your private work to train models, neither ours nor anyone else's.
3. Why we are allowed to hold it
Under the GDPR, each thing we do has a legal basis:
| What | Basis |
|---|---|
| Running your account, teaching you, running your code, taking payment | Contract (Art. 6(1)(b)): without it there is no service to provide. |
| Issuing invoices and keeping accounting records | Legal obligation (Art. 6(1)(c)): Portuguese tax law requires it. |
| Model call logs, server logs, cookieless page-view and product-event statistics, abuse prevention, improving the tutor, and the signup waitlist | Legitimate interests (Art. 6(1)(f)): keeping the service working, correct and affordable, and letting in the people who asked to join. The logs carry a fixed expiry and are not used to profile you. |
| Anything you opt into that isn't covered above, including product updates and inactivity reminders | Consent (Art. 6(1)(a)): which you can withdraw at any time, from the email or from your profile. Withdrawal is immediate. |
4. How long we keep it
| Data | Kept for |
|---|---|
| Model call logs (your prompts and the model's replies, verbatim) | 90 days, then deleted automatically |
| Tutor transcripts, progress, learner overview, workspace files, saved vibecoding-test attempts | As long as your account exists |
| Sign-in sessions | 7 days, or until you sign out |
| Waitlist entry (email and name, while signups are closed) | Until you get an account or ask us to remove it. If you unsubscribe, we keep the address only so we do not write again. |
| Email consent record and send log | As long as your account exists; deleted with the account |
| Feedback you send us | As long as your account exists |
| Invoices and accounting records | 10 years, as Portuguese tax law requires; this outlives your account |
| Aggregate usage counters, once your account is deleted | Retained without any link to you |
The 90-day period is enforced by a scheduled job that deletes the rows.
5. Who else processes it
We use the companies below to run codeset. They process your data on our instructions, under contract, and for nothing else.
| Processor | What for | Where |
|---|---|---|
| Microsoft Ireland Operations Ltd. (Azure) | Hosting: the database (accounts, courses, transcripts, billing records), your workspace files and generated audio, the models that teach and mark, the sandboxes that run your code, and the email we send you | EU (West Europe) |
| Google Ireland Limited | Sign-in. We receive your email address, name and Google account id | EU and United States |
| Stripe Payments Europe, Ltd. | Payments, subscriptions, billing address and VAT id, tax calculation | EU and United States |
| Cloudflare, Inc. | DNS and TLS for our domains | Global edge network |
| Cloudware (TOConline) | Issuing the certified Portuguese invoice (fatura) for each payment | Portugal |
| Plausible Insights OÜ | Page-view and product-event statistics. No cookies, no cross-site tracking, no profile of you as an individual | EU (Estonia and Germany) |
Everything we host (your account, your transcripts, your files, and the models that teach you) runs in the European Union. Where a processor is reachable from outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision. Ask us and we will tell you which applies to whom.
Beyond those processors, we disclose personal data only when the law requires it (a court order or a lawful request from an authority) or when it is necessary to establish or defend a legal claim. If codeset is ever sold, your data may transfer with it, and this policy continues to apply until you are told otherwise.
6. Your rights
You can ask us to:
- Show you what we hold about you, and give you a copy;
- Correct anything that is wrong;
- Delete your account and its data;
- Export your data in a portable format;
- Restrict or object to processing we do on the basis of legitimate interests;
- Withdraw consent you have given, without affecting what we did before.
You can delete your account yourself from your profile. For anything else, email hello@codeset.ai from the address on your account and we will respond within one month.
You also have the right to complain to a supervisory authority. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD). If you live elsewhere in the EU, you can complain to your own national authority.
7. Security
Your session cookie is HttpOnly, so no script running on the page can read it. Sandboxes are isolated per project and torn down when idle, and untrusted previews of your code are served from a separate hostname so they cannot reach your session. Data is encrypted in transit and at rest. Access to production data is limited to the people who need it to operate the service.
If a breach puts your rights at risk, we will notify the CNPD within 72 hours and tell you directly where the law requires it.
8. Children
codeset is not aimed at children, and we do not knowingly collect data from anyone under 13. If you believe a child has given us personal data, write to hello@codeset.ai and we will delete it.
9. Changes
If we change how we handle your data, we will update this page and the date at the top, and for material changes we will tell you before they take effect. The list of processors above is the current one.
Adapted from Legalmattic by Automattic, used under CC BY-SA 4.0. This page is likewise available under CC BY-SA 4.0.