Privacy Policy
Last updated: 30 August 2026
This notice describes how GotchiCode (“GotchiCode”, “we”, “us”) collects, uses, and shares information when you use our website and related services (the “Services”). If you do not agree with it, please do not use the Services.
GotchiCode is a small, independently run learning platform. We do not have a marketing department, an advertising business, or a sales team, and this notice is deliberately specific about that rather than reserving rights we have no intention of using.
The short version
- We collect what an account and a progress tracker need: your email, your username, what you have completed, and the code you submit for grading.
- We do not sell or share your personal information, and we have never done so. We do not run advertising, ad networks, retargeting, or tracking pixels.
- We use no analytics or advertising cookies. The only cookie we set is the one that keeps you signed in.
- We do not ask for your date of birth, your phone number, your postal address, or your precise location, and we do not collect biometric data.
- You can delete your account yourself, at any time, from Settings. Deletion removes your account and its data.
- Contact us about anything in this notice through the contact form.
1. What we collect
Information you give us
- Account details. Your email address, a username, and an optional display name. Sign-in itself (your password, passkeys, two-factor codes, magic links) is handled by our identity provider, WorkOS; we never see or store your password. If you sign in with Google, GitHub, Microsoft, or Apple instead, we receive your email address, basic profile name, and avatar from that provider.
- Profile picture. A preset avatar, a snapshot of your own Gotchi, or a photo you upload. Uploads are cropped in your browser and stored as a small square image.
- Name on your certificates. Optional, and the only field where we invite you to give a real name. See Certificates below, because that field is the one piece of your data designed to be shown to third parties.
- Learning content you create. Code you submit for grading, questions you ask the Gotchi mentor, community posts and comments, guild membership, and reviews you write.
- Support messages. What you write in the contact form, plus a reply-to email address if you send it while signed out.
Information created as you use the Services
- Progress and gamification. Lessons and courses completed, XP, rank, streaks, the days you were active, your pet’s name and cosmetics, arcade scores, and items you have earned.
- Product analytics. Page views, lesson starts, and time spent on a lesson, recorded against your account when you are signed in and anonymously when you are not. We use these to see which lessons are too hard or too long. These records contain no IP address and no device fingerprint.
- Billing status. Whether a subscription is active, past due, or cancelled, and the history of those changes.
Information handled but not stored
Your IP address reaches our servers, as it must for any website. We use it to rate-limit abuse of the code sandbox and the sign-in form, where it is held briefly in a cache and then expires, and it appears in short-lived server request logs. We do not keep IP addresses in our database, attach them to your account, or use them to work out where you are beyond what rate limiting requires.
Your payment card details are entered on our payment processor’s pages and go directly to them. GotchiCode never receives, sees, or stores your card number.
What we never collect
We do not collect government identifiers, health data, precise geolocation, biometric data, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, or union membership. We do not buy personal information from data brokers, marketing partners, or public databases, and we do not enrich your profile from outside sources.
2. How we use it
- To create your account, sign you in, and keep the account working.
- To run the courses: grade submissions, save progress, award XP, and issue certificates.
- To provide the Gotchi mentor and other AI-assisted help you ask for.
- To show public leaderboards, profiles, and community posts (see section 4).
- To send you the service emails described in section 3.
- To answer support requests you send us.
- To take payment and manage subscriptions, if you have a paid plan.
- To keep the Services secure: prevent abuse of the sandbox, detect fraud, enforce our terms.
- To understand which lessons work and improve the curriculum.
- To comply with the law.
We do not use your information to build advertising profiles, and we do not use your data to make automated decisions that produce legal or similarly significant effects about you.
3. Emails we send
Some emails are part of the service and cannot be switched off while you have an account: email confirmation, password reset, account-deletion confirmation, and billing notices such as a failed payment. Everything else is optional: product updates, community notifications, and learning reminders can all be turned off under Settings → Notifications.
4. What is public
Parts of GotchiCode are public by design, and you should treat them as visible to anyone:
- Your profile page at
/u/your-username: username, display name, avatar, rank, XP, a country if one is set on your account, the month you joined, and the course you are currently taking. - Leaderboards, which show the same profile fields alongside your XP.
- Community threads, posts, guild membership, and reviews you write, attributed to your profile.
- Certificates you have been issued, to anyone you give the certificate number to. See below.
Your email address is never shown on a public page, never included in a public API response, and never revealed to other users.
5. Certificates of completion
When you finish a course or a whole learning path, we issue you a certificate with a unique certificate number. A certificate is only useful if someone else can check it, so anyone holding that number can open its page and download its PDF without an account. The number is long and random, so it cannot be guessed: in practice, only the people you give it to can see the certificate.
A certificate shows the name you chose to have printed, the course or path you completed, the date, your GotchiCode username, and the certificate number. Nothing else. If you set a real name under Settings → Certificates, that is the name a recipient will see, which is the point of the field. Leave it blank and we print your display name or username instead. You can change or clear it at any time and every certificate re-renders with the new name.
6. Who we share it with
We share personal information only with the service providers we need to run GotchiCode, each handling it on our instructions and for no purpose of their own:
- Our hosting and infrastructure providers, which store the database and run the servers.
- Our payment processor, which handles checkout, card details, and subscription billing if you subscribe. They receive your email address and payment information.
- Our email provider, which delivers the service emails in section 3 and receives your email address and the message.
- Our identity provider (WorkOS), which runs the sign-in screen and holds your credentials: email address, password hash, passkeys, two-factor settings, and the social providers (Google, GitHub, Microsoft, Apple) you choose to link, plus the IP address and device used at sign-in for abuse protection.
- An AI model provider, when you use the Gotchi mentor or pet chat. Your message and the lesson you are working on are sent so an answer can come back. Do not put personal information you would not want processed by a third party into those chats.
We may also disclose information if the law requires it, to establish or defend legal claims, to protect someone’s safety, or, if GotchiCode is ever sold or merged, to the acquiring party, who would be bound by this notice.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other state privacy laws. We have not done so in the past twelve months, and we do not do so with the data of anyone we know to be under 16.
7. Cookies and tracking
We set one cookie: a session cookie that keeps you signed in. It is HttpOnly, and on our secure deployment it is also marked Secure. We use no analytics cookies, no advertising cookies, no tracking pixels, no web beacons, and no third-party social plugins. Your browser also stores a little data locally so the free demo can remember lessons you passed before signing up; that stays on your device until you sign in and claim them or clear your browser.
Because we do not track you across sites, there is nothing for a Do Not Track or Global Privacy Control signal to turn off. We honour them by not doing the thing in the first place.
8. Third-party links
The Services link to other websites, such as documentation and tools referenced in lessons. We do not control those sites and are not responsible for their privacy practices. This notice covers only GotchiCode.
9. Where your information is processed
GotchiCode is operated from, and its data is stored in, the United States. If you use the Services from elsewhere, including the European Economic Area or the United Kingdom, your information will be transferred to and processed in the United States, whose data protection laws may differ from your own. Where we transfer personal data out of the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism with our providers.
10. How long we keep it
- Account, profile, and progress data: for as long as your account exists.
- After you delete your account: removed from our live systems. Analytics events and support tickets are detached from your account rather than deleted, so they no longer identify you but historical totals stay accurate.
- Operational backups: where we hold them, deleted data can persist until that backup rolls over, and is not restored into the live service.
- Billing records: kept as long as tax and accounting law requires, even after account deletion.
- Server logs and rate-limit records: minutes to days, then discarded.
11. How we protect it
Passwords are stored only as salted hashes. Traffic to the site is encrypted in transit. Session cookies are HttpOnly and Secure. Submitted code runs in an isolated, resource-capped sandbox with no network access. Administrative access is restricted. That said, no service can promise perfect security, and we cannot guarantee that a determined attacker will never get through.
12. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from them. If you are between 13 and the age of majority where you live, you may use GotchiCode only with a parent or guardian’s permission. If you believe a child under 13 has given us personal information, tell us through the contact form and we will delete the account and its data.
13. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing, withdraw a consent you gave, and not be discriminated against for exercising any of these rights.
Some of them you can exercise yourself, immediately:
- Correct your information: edit your display name, avatar, certificate name, and password in Settings.
- Delete your account: Settings → Account, or the delete account page. We email you a confirmation link, and the deletion is final.
- Turn off optional emails: Settings → Notifications.
For anything else, including a copy of your data, use the contact form. We will respond within 45 days, and will tell you if we need a further 45 days. So that we do not hand your data to someone else, we verify requests against the account they concern: the quickest route is to send the request while signed in, or from the email address on the account. We only use what you send us to verify the request, and we delete it afterwards. You may use an authorised agent, but we may ask for proof of their authority.
If we refuse a request, we will explain why. If you disagree, you may appeal through the contact form, and we will reply in writing within 60 days.
If you are in the EEA, the UK, or Switzerland
GotchiCode is the data controller for the information described here. We rely on these legal bases:
- Performance of a contract, for running your account, delivering the courses, and taking payment.
- Legitimate interests, for keeping the Services secure and understanding how lessons are used, weighed against your rights.
- Consent, for optional emails and for anything you choose to publish, which you can withdraw at any time without affecting what was lawful before.
- Legal obligation, for keeping tax and accounting records.
You may also complain to your local supervisory authority. In the EEA you can find yours at edpb.europa.eu, in the UK at ico.org.uk, and in Switzerland at edoeb.admin.ch.
If you are in California
In the past twelve months we have collected these categories of personal information under the CCPA/CPRA: identifiers (email, username, account name, IP address); California customer records (name, contact information); internet activity (your activity within GotchiCode); commercial information (subscription and payment status); and inferences limited to your learning progress. We collect them for the purposes in section 2, from you and from your use of the Services, and we retain them for the periods in section 10. We disclose them to the service providers in section 6 for business purposes only.
We have not sold or shared personal information in the past twelve months, and we do not process sensitive personal information for the purpose of inferring characteristics, so there is nothing for a “Do Not Sell or Share” or “Limit the Use of My Sensitive Personal Information” request to stop. Your rights to know, delete, correct, and not be discriminated against are exercised as described above. We offer no financial incentive in exchange for personal information.
California residents may also request, once a year and free of charge under the “Shine the Light” law, details of personal information disclosed to third parties for their direct marketing purposes. We make no such disclosures.
If you are in Virginia, Colorado, Connecticut, Utah, or a comparable state
You have the rights to confirm whether we process your personal data, access it, correct it, delete it, obtain a portable copy, and opt out of targeted advertising, sale of personal data, and profiling with legal or similarly significant effects. We do none of those three things, so the opt-out right has nothing to act on. Exercise the rest through the contact form; the response and appeal timelines above apply.
14. Changes to this notice
We will update this notice as the Services change or the law requires. The date at the top always reflects the current version. If a change materially affects how we handle your information, we will say so prominently in the app or by email before it takes effect.
15. How to contact us
GotchiCode is run by an individual and does not publish a postal address or telephone number. The contact form is the way to reach us about this notice, about your privacy rights, or about anything else; it files a ticket that goes straight to the operator. Choose the Account category for privacy requests. If you are signed in, your message is linked to your account automatically, which also verifies it.