Draft — pending legal review

This document is an unreviewed working draft. It has not been approved by a lawyer and is not a binding agreement. It is published so the terms we intend to operate under are transparent while they are being finalised. Do not rely on this text as a legal commitment — the final, reviewed version will replace it.

Privacy Policy

Last updated: 15 July 2026

This policy explains what personal data LinfyLab collects, why we collect it, who we share it with, and what control you have over it. We have tried to describe what the platform actually does, rather than list every possibility.

1. Who we are

LinfyLab operates an interactive coding-learning platform. This policy covers the LinfyLab website and application. The formal identity of the data controller and a data-protection contact address will be published alongside the reviewed version of this document.

2. What data we collect

Account and identity data from GitHub. When you sign in with GitHub OAuth, we receive and store profile information from your GitHub account — such as your GitHub id, username, display name, avatar, and email address — together with the OAuth access token that lets the platform act on your behalf. Sign-in requests the user:email, user, and repo scopes. The repo scope is GitHub's full repository scope, so the token we hold technically permits read and write access to every repository your account owns; we use it solely for your LinfyLab project repositories.

Learning data. We store the projects you enrol in, your progress through phases, milestones, and challenges, the code you submit, the results of running your code, and the AI review feedback generated for your submissions.

Repository data. We create repositories for your projects, write files into them — the project template and the starter files for each milestone — and read their contents in order to grade your work. We also receive webhook events from GitHub when you push commits.

Billing data. If you subscribe, we store your subscription status, the customer and subscription identifiers issued by Paddle, the start and end dates of your billing period and of any trial, and an invoice history — the amount due, the amount paid, the currency, the payment status, and the date each invoice was paid. We also retain the raw event payloads Paddle sends us about your subscription, which can contain personal data. We do not receive or store your full payment-card details.

Technical data. We process server logs and error reports. Our own server logs can include IP address, request metadata, timestamps, and diagnostic information about failures. Error reports are produced both by our servers and by the LinfyLab app running in your browser; they reference your account only by its internal id. If — and only if — you consent to analytics in the cookie banner, a sample of your sessions in the app is also recorded. Section 5 describes this under Sentry.

3. How we use your data

To authenticate you and keep your account secure.

To operate the learning platform — to create your project repositories, run and grade your submissions, generate AI review feedback, and track and display your progress.

To manage subscriptions and entitlement to paid content.

To keep the service working and safe — to diagnose errors, investigate abuse, and protect the platform and its users.

To communicate with you about your account and material changes to the service.

4. Legal bases for processing

Where data-protection law such as the GDPR applies, we rely on the following bases: performance of a contract, for the processing needed to give you the service you signed up for; legitimate interests, for keeping the platform secure, preventing abuse, and improving the product; legal obligation, for records we are required to keep, such as those relating to tax; and consent, where we ask for it specifically.

The precise mapping of each activity to its legal basis is part of the pending legal review.

5. Third-party processors and recipients

GitHub — provides sign-in and hosts the repositories used for your projects. We create repositories on your behalf, write project template and milestone files into them, read their contents, and receive webhook events when you push. Section 2 sets out the scopes we request.

Judge0 — a code-execution service. When you submit work, your project repository at that commit is packaged up and sent to Judge0 in full to be compiled and run against our tests — not only the file you changed.

Anthropic (Claude) — an AI provider. The code files in your project repository at that commit may be sent to Anthropic so an automated code review can be generated. That is the project's source files at that point, not only the changes you made.

Paddle — our payment provider and the Merchant of Record for all purchases. Paddle collects and processes your payment details directly under its own privacy policy, and returns to us only the identifiers and subscription status we need.

Sentry — error monitoring and, with your consent, session recording. Sentry receives error reports both from our servers and from the LinfyLab app running in your browser. An error report can include technical metadata about what failed, the browser you were using, and your account's internal id — we do not attach your email address, username, or IP address to it. Separately, Sentry offers Session Replay, which records a reconstruction of your session in the app — the pages you moved through and how you interacted with them. Session Replay runs only if you accept analytics in the cookie banner: if you do, sessions in which an error occurs are recorded, together with a portion of sessions generally; if you do not, no session is recorded. Text and form inputs are masked, and images and video are blocked, so the content you read and type is masked rather than recorded.

We also use infrastructure providers for hosting, databases, and queues. We do not sell your personal data, and we do not share it for third-party advertising.

6. International transfers

Some of the providers described above operate outside your country, including in the United States. Where we transfer personal data internationally, we rely on the safeguards offered by those providers, such as standard contractual clauses. The full transfer mapping is part of the pending legal review.

7. How long we keep data

We keep your account, learning progress, and submissions for as long as your account exists, so your history remains available to you.

Error reports and session recordings held by Sentry are removed on Sentry's own retention schedule. For the server logs we keep ourselves we have not yet set a retention period; defining and applying one is outstanding work.

Records we are legally required to keep, such as billing records, are retained for the period the law requires, even after account deletion.

Deleting your account deactivates it. We mark the account as deleted and immediately revoke your sessions and your access to the platform. It does not yet erase the underlying data: your account record — including your email address, display name, avatar, GitHub id and username, and the GitHub token — along with your submissions, progress, repository records, and invoices, is retained pending erasure.

We are building a defined erasure process to complete that step automatically. Until it ships, erasure on request is available: ask us and we will erase the data we are not legally required to keep. Precise retention periods are being confirmed as part of the legal review.

8. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to processing, to withdraw consent where processing is based on consent, and to receive your data in a portable format.

You can delete your account today from your account settings, in the danger-zone section. As section 7 explains, this deactivates the account and revokes your access and sessions, but it does not yet erase your data automatically. If you want your data erased, contact us and we will do it.

A self-serve data export is not yet available; we are building it. Until it ships, you can ask us for a copy of your data and we will provide it.

You can also revoke LinfyLab's access to your GitHub account at any time from your GitHub settings.

If you are in the EU or UK and believe we have handled your data improperly, you have the right to complain to your local data-protection authority.

9. Cookies and similar technologies

We use cookies and similar storage that are necessary to run the platform — to keep you signed in, to remember your language preference, to record your consent choices, and to guard the GitHub sign-in flow against request forgery.

Non-essential technologies are gated behind the cookie banner: anonymous usage analytics and the Sentry Session Replay recording described in section 5 run only if you choose to accept them there. You can make that choice when you first visit, and rejecting it leaves the platform fully usable.

A full cookie inventory is part of the pending legal review.

10. Security

We use industry-standard measures to protect your data, including encryption in transit over HTTPS, scoped access controls so that learners can only reach their own data, and signature verification on incoming webhooks.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant authorities where the law requires it.

11. Children

LinfyLab is not directed at children, and we do not knowingly collect personal data from children below the age of digital consent in their country. If you believe a child has given us personal data, please contact us and we will remove it.

12. Changes to this policy

We may update this policy as the platform develops. When we make a material change, we will update the date at the top of this page and, where appropriate, give notice in the app or by email.

13. Contact

If you have questions about this policy or want to exercise any of your rights, please contact us and we will respond as soon as we can. A dedicated privacy contact address will be published alongside the reviewed version of this document.