CodeBaobab legal

Privacy Policy

Last updated: August 29, 2026

This Privacy Policy explains what information CodeBaobab handles, why it is used, and the choices available to you. It applies when you visit the site, use the curriculum or code workspace, or sign in.

1. Information we handle

Account information

When you create an email account, Supabase processes your email address and password and gives CodeBaobab your user ID, email address, and authentication metadata. CodeBaobab does not store your plaintext password. When you choose GitHub, GitHub and Supabase may also provide your name, avatar, provider user ID, and related account metadata. We do not receive your GitHub password.

Learning and browser data

When you sign in, CodeBaobab stores your completed course chapters and accepted problem submissions under your Supabase user ID so your progress can follow your account across devices. We store the problem or chapter identifier, completion status, and completion time. Editor drafts, selected problems, theme, and workspace layout remain in local storage on your device.

Payment and subscription information

When you purchase Pro, Stripe processes the checkout and may collect your email, billing address, tax information, and payment-method details. CodeBaobab receives billing identifiers, the plan purchased, payment or subscription status, and related transaction information needed to provide and support Pro access. We do not receive or store your complete card number.

Technical and communication data

Hosting and authentication services may process technical records such as IP address, browser or device type, request time, requested pages, and security events. If you contact us, we receive the information included in your message.

2. Code execution

Python and JavaScript code entered in the practice workspace is executed and judged in your browser. The current application does not save that source code to a CodeBaobab backend. Your browser may retain editor drafts in local storage so you can continue later on the same device.

3. How information is used

  • to authenticate you and maintain your signed-in session;
  • to provide lessons, practice tools, account-synced learning progress, and saved preferences;
  • to process purchases, confirm Pro access, manage subscriptions, and prevent payment fraud;
  • to protect the service, prevent abuse, troubleshoot errors, and maintain reliability;
  • to respond to questions or account requests; and
  • to comply with law and enforce our Terms of Service.

4. When information is shared

We do not sell personal information. Information may be handled by:

  • Supabase, which provides authentication and stores authentication and learning-progress records;
  • GitHub, when you choose GitHub to sign in;
  • Stripe, which processes payments, subscriptions, billing management, tax details, and payment fraud checks;
  • hosting and infrastructure providers, which deliver and secure the website;
  • professional advisers or authorities when reasonably necessary to comply with law or protect rights; and
  • a successor in a merger, financing, reorganization, or sale, subject to appropriate protections.

5. Cookies and local storage

CodeBaobab uses browser storage for authentication sessions, a local learning-progress cache, code drafts, and interface settings. We do not currently use advertising cookies or third-party behavioural advertising. Blocking or clearing browser storage may sign you out and erase preferences and drafts. Account-synced progress returns after you sign in again, but progress created while signed out may be lost before it is imported into an account.

6. Retention

Authentication, learning-progress, and billing-entitlement records are retained while your account or paid access remains active and as reasonably necessary for security, accounting, tax, legal, and operational purposes. Stripe retains payment records under its own policies and legal obligations. Local browser data remains until you or your browser clears it. Account deletion also deletes the linked course and problem progress records. We remove or anonymize other information when it is no longer reasonably needed, subject to legal requirements and backup cycles.

7. Your choices and rights

You can sign out, clear local browser data, disconnect CodeBaobab from GitHub when applicable, or stop using the service. You may ask to access, correct, or delete account information, or ask a privacy question, by emailing support@codebaobab.com. We may need to verify your identity before acting on a request. Depending on where you live, additional privacy rights may apply.

8. International processing

CodeBaobab’s service providers may process information in countries other than your own. Information may therefore be subject to the laws of those jurisdictions. We use providers and safeguards intended to protect information consistently with this Policy.

9. Security

We use reasonable administrative and technical safeguards appropriate to the current service. No internet transmission or storage method is completely secure, so absolute security cannot be guaranteed. Protect access to your password or connected GitHub account and sign out on shared devices.

10. Children

CodeBaobab is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.

11. Policy changes and contact

We may update this Policy to reflect changes to the service or law. We will post the revised Policy with a new last-updated date and provide additional notice when appropriate. Questions, requests, or complaints may be sent to support@codebaobab.com.