Draft — pending legal review
This document is an unreviewed working draft. It has not been approved by a lawyer and is not a binding agreement. It is published so the terms we intend to operate under are transparent while they are being finalised. Do not rely on this text as a legal commitment — the final, reviewed version will replace it.
Privacy Policy
Last updated: 10 August 2026
This policy explains what personal data LinfyLab collects, why we collect it, who we share it with, and what control you have over it. We have tried to describe what the platform actually does, rather than list every possibility.
1. Who we are
LinfyLab operates an interactive coding-learning platform. This policy covers the LinfyLab website and application. The formal identity of the data controller and a data-protection contact address will be published alongside the reviewed version of this document.
2. What data we collect
Account and identity data from GitHub. When you sign in with GitHub OAuth, we receive and store profile information from your GitHub account — such as your GitHub id, username, display name, avatar, and email address — together with the OAuth access token that lets the platform act on your behalf. Sign-in requests the user:email, user, and repo scopes. The repo scope is GitHub's full repository scope, so the token we hold technically permits read and write access to every repository your account owns; we use it solely for your LinfyLab project repositories.
Learning data. We store the projects you enrol in, your progress through phases, milestones, and challenges, the code you submit, the results of running your code, and the AI review feedback generated for your submissions.
Repository data. We create repositories for your projects, write files into them — the project template and the starter files for each milestone — and read their contents in order to grade your work. We also receive webhook events from GitHub when you push commits.
Billing data. If you subscribe, we store your subscription status, the customer and subscription identifiers issued by Paddle, the start and end dates of your billing period and of any trial, and an invoice history — the amount due, the amount paid, the currency, the payment status, and the date each invoice was paid. We also retain the raw event payloads Paddle sends us about your subscription, which can contain personal data. We do not receive or store your full payment-card details.
Technical data. We process server logs and error reports. Our own server logs can include IP address, request metadata, timestamps, and diagnostic information about failures. Error reports are produced both by our servers and by the LinfyLab app running in your browser; they reference your account only by its internal id. If — and only if — you consent to analytics in the cookie banner, a sample of your sessions in the app is also recorded. Section 5 describes this under Sentry.
3. How we use your data
To authenticate you and keep your account secure.
To operate the learning platform — to create your project repositories, run and grade your submissions, generate AI review feedback, and track and display your progress.
To manage subscriptions and entitlement to paid content.
To keep the service working and safe — to diagnose errors, investigate abuse, and protect the platform and its users.
To communicate with you about your account and material changes to the service.
4. Legal bases for processing
Where data-protection law such as the GDPR applies, we rely on the following bases: performance of a contract, for the processing needed to give you the service you signed up for; legitimate interests, for keeping the platform secure, preventing abuse, and improving the product; legal obligation, for records we are required to keep, such as those relating to tax; and consent, where we ask for it specifically.
The precise mapping of each activity to its legal basis is part of the pending legal review.
5. Third-party processors and recipients
GitHub — provides sign-in and hosts the repositories used for your projects. We create repositories on your behalf, write project template and milestone files into them, read their contents, and receive webhook events when you push. Section 2 sets out the scopes we request.
Judge0 — a code-execution service. When you submit work, your project repository at that commit is packaged up and sent to Judge0 in full to be compiled and run against our tests — not only the file you changed.
Anthropic (Claude) — an AI provider. The code files in your project repository at that commit may be sent to Anthropic so an automated code review can be generated. That is the project's source files at that point, not only the changes you made.
Paddle — our payment provider and the Merchant of Record for all purchases. Paddle collects and processes your payment details directly under its own privacy policy, and returns to us only the identifiers and subscription status we need.
Sentry — error monitoring and, with your consent, session recording. Sentry receives error reports both from our servers and from the LinfyLab app running in your browser. An error report can include technical metadata about what failed, the browser you were using, and your account's internal id — we do not attach your email address, username, or IP address to it. Separately, Sentry offers Session Replay, which records a reconstruction of your session in the app — the pages you moved through and how you interacted with them. Session Replay runs only if you accept analytics in the cookie banner: if you do, sessions in which an error occurs are recorded, together with a portion of sessions generally; if you do not, no session is recorded. Text and form inputs are masked, and images and video are blocked, so the content you read and type is masked rather than recorded.
We also use infrastructure providers for hosting, databases, and queues. We do not sell your personal data, and we do not share it for third-party advertising.
6. International transfers
Some of the providers described above operate outside your country, including in the United States. Where we transfer personal data internationally, we rely on the safeguards offered by those providers, such as standard contractual clauses. The full transfer mapping is part of the pending legal review.
7. How long we keep data
We keep your account, learning progress, and submissions for as long as your account exists, so your history remains available to you.
Error reports and session recordings held by Sentry are removed on Sentry's own retention schedule. Our own operational server logs are kept only for as long as they are needed to keep the service secure and to diagnose faults, and their retention periods are being finalised as part of the legal review.
Deleting your account is a permanent deletion of the data we hold for it, not a deactivation. Your account record — including your email address, display name, avatar, GitHub id and username, and the GitHub access token — is removed from our database, together with your sessions, learning progress, submissions, AI review feedback, our records of your project repositories, and your subscription and invoice records. There is no restore: signing in again with GitHub creates a new, empty account.
Two things are deliberately kept, with your identity removed rather than the record itself: content you authored for the platform as a course author, and our internal administrative logs. In both cases the link to your account is erased, so what remains is no longer connected to you.
Before the account is deleted, any active subscription is canceled with Paddle, and the billing event payloads we hold for your Paddle customer record are scrubbed, with later billing events for that customer blocked from re-introducing your details. In rare cases our payment provider may reuse a customer identifier for a later account, and our billing event records may then contain earlier details.
Paddle is our payment provider and the merchant of record for every purchase, which means Paddle, not LinfyLab, is the seller on your invoice. Paddle keeps its own customer and transaction records under its own privacy policy, including to meet its tax and accounting obligations, and states that it retains some transactional data for five years. Deleting your LinfyLab account does not delete Paddle's records, and asking Paddle to delete your buyer data does not delete your LinfyLab account: those are two separate requests, to two separate companies.
Repositories we created in your GitHub account belong to that account. Deleting your LinfyLab account deletes our records of them and the access token we hold, but it does not delete the repositories from GitHub, and the authorisation you granted LinfyLab stays listed in your GitHub settings until you revoke it there.
Precise retention periods for the records described above are being confirmed as part of the legal review.
8. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to processing, to withdraw consent where processing is based on consent, and to receive your data in a portable format.
You can delete your account yourself at any time, from your account settings under Danger Zone. As section 7 explains, that permanently deletes the data we hold for the account rather than deactivating it, and it cannot be undone.
You can download a copy of your data — your profile, learning progress, submissions, AI review feedback and billing history — from the Your Data section of your account settings. Access tokens and other secrets are excluded from the export.
Deleting your LinfyLab account does not reach Paddle. If you also want the customer and transaction records Paddle holds as merchant of record deleted, you need to make that request to Paddle directly, as section 7 explains.
If you cannot sign in, or you want to exercise a right that the self-serve tools above do not cover, contact us.
You can also revoke LinfyLab's access to your GitHub account at any time from your GitHub settings.
If you are in the EU or UK and believe we have handled your data improperly, you have the right to complain to your local data-protection authority.
9. Cookies and similar technologies
We use cookies and similar storage that are necessary to run the platform — to keep you signed in, to remember your language preference, to record your consent choices, and to guard the GitHub sign-in flow against request forgery.
Non-essential technologies are gated behind the cookie banner: anonymous usage analytics and the Sentry Session Replay recording described in section 5 run only if you choose to accept them there. You can make that choice when you first visit, and rejecting it leaves the platform fully usable.
A full cookie inventory is part of the pending legal review.
10. Security
We use industry-standard measures to protect your data, including encryption in transit over HTTPS, scoped access controls so that learners can only reach their own data, and signature verification on incoming webhooks.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant authorities where the law requires it.
11. Children
LinfyLab is not directed at children, and we do not knowingly collect personal data from children below the age of digital consent in their country. If you believe a child has given us personal data, please contact us and we will remove it.
12. Changes to this policy
We may update this policy as the platform develops. When we make a material change, we will update the date at the top of this page and, where appropriate, give notice in the app or by email.
13. Contact
If you have questions about this policy or want to exercise any of your rights, please contact us and we will respond as soon as we can. A dedicated privacy contact address will be published alongside the reviewed version of this document.