← Back

Privacy Policy

Last Updated: October 2, 2026

1. Introduction & Core Principles

At Codinx, founded by Nathan Francisco Lobo, we respect and safeguard the digital privacy of students, educators, and developers. This unified Privacy Policy explains how data is collected, stored, processed, and protected across all Codinx web services-including the central portal (codinx.app), Codinx Notes (notes.codinx.app), and Codinx Labs (labs.codinx.app).

2. Information We Collect

We only collect minimal, purpose-specific information necessary to deliver educational software:

  • Profile Information: When you authenticate via Codinx Single Sign-On (SSO), your central profile details (user UUID, full name, email address, avatar, verified student status, institute, and branch) are synchronized across authorized services.
  • Academic & Study Records Codinx Notes: Study notes, summaries, attachments, subject and semester tags, education level, institution and branch associations, and reading bookmarks you contribute or save. Notes also records service-relevant activity such as searches, document views, downloads, and connection timestamps.
  • Execution Telemetry & Runtimes Codinx Labs: Source code submitted for compilation, terminal standard I/O streams, compiler diagnostic output, execution duration, and allocated memory metrics.
  • Security & Audit Logs: Timestamped login and service authorization events, service access records, device types, and session metadata displayed on your central Codinx Security dashboard.

3. Ephemeral Sandboxes & Container IsolationCodinx Labs

Code execution within Codinx Labs occurs inside isolated, ephemeral container environments or client-side Web Workers:

  • Ephemeral Binaries: Temporary compilation files, object files, and scratch directories generated during code execution are purged immediately upon container teardown.
  • Local Python Execution: Where applicable, Python execution is executed directly in your browser using WebAssembly (Pyodide), ensuring code runs client-side on your device without leaving your machine.
  • Execution Limits: Remote execution and compilation may be subject to timeouts, output-size caps, per-user rate limits, and CPU, memory, process, and thread limits. These controls help isolate workloads and protect the service.
  • Zero Model Training: We do not use your proprietary experiment code, algorithms, or test data to train generative machine learning models without your explicit opt-in.

4. Study Materials, Attribution & StorageCodinx Notes

Notes and educational documents uploaded to Codinx Notes are stored securely with database encryption. We process this information to organize and deliver study resources, attribute note authors, display verified student badges, and provide AI-generated note summaries:

  • Attribution: Contributed study notes display author verification markers and roll badges so students receive proper academic attribution for their shared work.
  • Storage Security: Document metadata and study summaries are stored in encrypted cloud storage with role-based access control policies. Codinx Notes does not receive central account credentials or password hashes.
  • Activity Records: Note views, searches, downloads, and access timestamps may be recorded in the central Codinx Security page so you can review service access.

5. Multi-Service Token Isolation & Cookies

Codinx maintains strict architectural decoupling between services. Network communications with Codinx Labs and its remote execution runners are encrypted using TLS 1.3:

  • Shared Domain Cookies: Authentication tokens are stored in secure HTTP-only cookies partitioned under the .codinx.app domain with SameSite=Lax and Secure flags, safeguarding session credentials against cross-site scripting (XSS).
  • Zero Cross-Database Exposure: Downstream services (Notes and Labs) never have direct access to central account password hashes or private auth database tables. Notes content and metadata are protected through managed database encryption and role-based access controls.
  • Functional Storage: Browser local storage may retain client-side authentication state, guest-device identifiers, user preferences such as themes or selected semesters, and other settings needed for service features. No third-party advertising tracking cookies are used.

6. We Never Sell Your Data

Codinx does not sell, monetize, rent, or trade your personal data, code, or study materials to data brokers or third-party advertisers. Your work remains yours.

7. Third-Party Infrastructure Services

To provide reliable cloud infrastructure, Codinx collaborates with trusted industry providers under strict data-protection agreements:

  • Brevo: Dispatches transactional emails including password resets, account verification OTPs, and security alerts.
  • Razorpay: Handles secure payment processing for optional verified services. Codinx never receives or stores your bank credentials or payment card details.
  • Supabase: Provides managed, encrypted PostgreSQL storage with row-level security.

8. User Rights & Data Deletion

You maintain full sovereignty over your data under global data protection regulations:

  • Access & Export: You can request a summary of the personal information and logs associated with your account.
  • Right to Erasure: You can request the permanent deletion of your account, uploaded study notes, and experiment history at any time by contacting support.

9. Children's Privacy

Codinx is an educational platform primarily targeted at secondary, collegiate, and university students. We do not knowingly collect personal identifiable information from children under the age of 13 without appropriate parental or institutional guardian consent.

10. Contact Information

For privacy-related inquiries, data deletion requests, or security disclosures:

Email: [email protected] / [email protected] / [email protected]
Lead Developer: Nathan Francisco Lobo