Last updated: July 10, 2026
We collect information you provide directly: email, username, password (hashed), and profile photo. When you sign in with Google, we receive your name, email, and profile picture from Google. We also log device info, IP address, and session data for security purposes.
Your data is used to: authenticate your account, track problem-solving progress and statistics, send verification emails and OTPs, manage active sessions across devices, and improve platform features.
Code you submit is stored to display your submission history and is executed in an isolated sandbox (Judge0) for evaluation. We do not share your submitted code with third parties.
We use httpOnly cookies to store access and refresh tokens for authentication. These are essential for the platform to function and cannot be disabled while remaining logged in.
We use Google OAuth for sign-in, ImageKit for profile photo storage, and Judge0 for code execution. Each is governed by its own privacy policy.
Account data is retained as long as your account is active. You may request account deletion via the Contact page; we will remove your personal data within a reasonable timeframe, excluding data required for legal/security purposes.
Passwords are hashed with bcrypt. Tokens are stored in httpOnly, secure cookies. We use Redis for token revocation to invalidate sessions immediately when needed.
You may access, update, or delete your profile information at any time from your account settings. You can log out of individual devices or all devices from the Sessions page.
We may update this policy periodically. Material changes will be communicated via email or an in-app notice.
Privacy questions or data requests? Reach out via the Contact page.