Privacy Policy
Draft - last updated July 3, 2026
What we collect
CoderFlow stores the minimum needed to run a spaced-repetition service: your email address, an optional display name, your timezone, your preferences (theme, sound), your review history and self-ratings, problems you log, your streak, and anonymous product events (like "review completed"). We never collect payment card details - payments are processed by Stripe, and we only store your subscription status.
What we don't do
We don't sell your data, we don't use third-party ad trackers, and we don't scrape or connect to your accounts on other platforms. The pseudocode you type during reviews is stored in your private history and is never executed or shared.
Cookies
We use only essential cookies: one to keep you signed in and one for security (CSRF protection). There are no analytics or advertising cookies, which is why we don't need to ask you to accept any.
Your rights
From Settings you can export everything we hold about you as JSON, or permanently delete your account - deletion is immediate and removes your personal data from our database entirely (GDPR/CCPA). You can also email us to exercise any data right.
Where data lives
Data is stored in a PostgreSQL database with encryption in transit and at rest, hosted in the region shown on our status page. Email sign-in links are delivered via Resend; authentication via Google OAuth is optional and only shares your email and name with us.
Contact
Questions about this policy: noreply@coderflow.dev.