Privacy Policy
Effective 2026-09-15. This policy covers CodingNeed at codingneed.com. For privacy questions or requests, contact care@codingneed.com or use our contact form.
Information we use
- Accounts: email, display name, a salted password hash, session records, verification status, and the policy version accepted at signup.
- Learning: preferences, timezone, activity, bookmarks, progress, code drafts, practice outcomes, study notes, and saved interview transcripts.
- Support: name, reply email, topic, and message when you contact us.
- Operations: hosting providers may process IP addresses, requested URLs, browser details, and errors. Application error logs are designed to exclude passwords, cookies, and submitted code.
Why we process it
We use this information to provide accounts, save your work, recommend revision, respond to support requests, recover access, and protect the service against misuse. Optional analytics, when configured and accepted, help us understand public learning pages. We do not sell your account information.
Cookies and browser storage
An essential HttpOnly session cookie keeps you signed in for up to seven days. Guest progress, recovery copies, and cookie preferences use browser storage. Clearing it removes device-only work. Account deletion removes that account’s recovery copies in the browser used for deletion; clear site data separately on other devices.
Optional Google Analytics loads only after you accept analytics in Cookie settings. You can reject it or withdraw permission using the footer control. This does not disable essential account cookies. Our analytics integration excludes account pages, URL query strings, code, names, and email addresses. Google may process normal connection information under its Privacy Policy.
Execution, AI, and email providers
JavaScript, TypeScript, Python, and SQLite exercises execute in isolated browser workers. Runtime and editor assets download from jsDelivr, which receives normal connection information. Remote compiled-language submissions, when enabled, send code and test input to the configured Judge0 sandbox. Optional AI coaching sends the conversation and code you choose to submit to the configured AI provider. Do not submit confidential information in practice code.
Recovery and verification emails use the configured SMTP provider. The website and MySQL account database are hosted with Hostinger. Providers may retain operational information under their own terms and the site owner’s configuration.
Advertising
This release does not automatically load advertising scripts. If Google advertising is enabled later, Google and other vendors may use cookies to select ads based on visits to this and other websites. Manage personalized advertising through Google My Ad Center and participating vendors’ choices at YourAdChoices. Applicable advertising consent controls and vendor disclosures must be available when ads are introduced; our analytics preference control is not an advertising consent platform.
Retention and deletion
Account and learning records remain until deletion. Expired sessions and request-limit records are rejected and cleared during API activity. Recovery links expire after 30 minutes and verification links after 60 minutes; a replacement invalidates the older link. Expired token records are cleared during account-email activity.
Contact messages expire after 180 days, are excluded from the inbox after expiry, and are deleted during subsequent inbox or contact activity. Hosting backups, email correspondence, and provider logs may have separate retention schedules; email us for details about your request. Copies you download or retain on other devices are under your control.
Your controls
Profile settings let you export learning data, change your password, revoke other sessions, and delete a learner account after password confirmation. An account responsible for authored lessons requires ownership transfer before deletion. You can also request access, correction, deletion, or information about processing by contacting us. We may need to verify ownership. Your rights and our obligations depend on applicable law.
Security and changes
We use access controls, password hashing, secure cookies, and request limits. No online service can guarantee absolute security. Contact us if personal information was submitted without appropriate permission, including information about a child. Policy changes will appear here with a new effective date.
AI study coach providers
When you choose to send a message to the AI study coach, your message, included code and recent conversation context are sent through our server to the configured provider, Google Gemini or OpenAI. The coach shows the active provider before sending. Do not include passwords, API keys, sensitive personal information or proprietary code you are not permitted to share. Provider processing and retention depend on the provider and the service configuration; AI responses can be inaccurate.