← BackPrivacy Policy
Last Updated: October 2, 2026
1. Introduction & Core Principles
At Codinx, founded by Nathan Francisco Lobo, we respect and safeguard the digital privacy of students, educators, and developers. This unified Privacy Policy explains how data is collected, stored, processed, and protected across all Codinx web services-including the central portal (codinx.app), Codinx Notes (notes.codinx.app), and Codinx Labs (labs.codinx.app).
2. Information We Collect
We only collect minimal, purpose-specific information necessary to deliver educational software:
- Profile Information: When you authenticate via Codinx Single Sign-On (SSO), your central profile details (user UUID, full name, email address, avatar, verified student status, institute, and branch) are synchronized across authorized services.
- Academic & Study Records Codinx Notes: Study notes, summaries, attachments, subject and semester tags, education level, institution and branch associations, and reading bookmarks you contribute or save. Notes also records service-relevant activity such as searches, document views, downloads, and connection timestamps.
- Execution Telemetry & Runtimes Codinx Labs: Source code submitted for compilation, terminal standard I/O streams, compiler diagnostic output, execution duration, and allocated memory metrics.
- Security & Audit Logs: Timestamped login and service authorization events, service access records, device types, and session metadata displayed on your central Codinx Security dashboard.
3. Ephemeral Sandboxes & Container IsolationCodinx Labs
Code execution within Codinx Labs occurs inside isolated, ephemeral container environments or client-side Web Workers:
- Ephemeral Binaries: Temporary compilation files, object files, and scratch directories generated during code execution are purged immediately upon container teardown.
- Local Python Execution: Where applicable, Python execution is executed directly in your browser using WebAssembly (Pyodide), ensuring code runs client-side on your device without leaving your machine.
- Execution Limits: Remote execution and compilation may be subject to timeouts, output-size caps, per-user rate limits, and CPU, memory, process, and thread limits. These controls help isolate workloads and protect the service.
- Zero Model Training: We do not use your proprietary experiment code, algorithms, or test data to train generative machine learning models without your explicit opt-in.
4. Study Materials, Attribution & StorageCodinx Notes
Notes and educational documents uploaded to Codinx Notes are stored securely with database encryption. We process this information to organize and deliver study resources, attribute note authors, display verified student badges, and provide AI-generated note summaries:
- Attribution: Contributed study notes display author verification markers and roll badges so students receive proper academic attribution for their shared work.
- Storage Security: Document metadata and study summaries are stored in encrypted cloud storage with role-based access control policies. Codinx Notes does not receive central account credentials or password hashes.
- Activity Records: Note views, searches, downloads, and access timestamps may be recorded in the central Codinx Security page so you can review service access.
5. Multi-Service Token Isolation & Cookies
Codinx maintains strict architectural decoupling between services. Network communications with Codinx Labs and its remote execution runners are encrypted using TLS 1.3:
- Shared Domain Cookies: Authentication tokens are stored in secure HTTP-only cookies partitioned under the
.codinx.app domain with SameSite=Lax and Secure flags, safeguarding session credentials against cross-site scripting (XSS). - Zero Cross-Database Exposure: Downstream services (Notes and Labs) never have direct access to central account password hashes or private auth database tables. Notes content and metadata are protected through managed database encryption and role-based access controls.
- Functional Storage: Browser local storage may retain client-side authentication state, guest-device identifiers, user preferences such as themes or selected semesters, and other settings needed for service features. No third-party advertising tracking cookies are used.
6. We Never Sell Your Data
Codinx does not sell, monetize, rent, or trade your personal data, code, or study materials to data brokers or third-party advertisers. Your work remains yours.
7. Third-Party Infrastructure Services
To provide reliable cloud infrastructure, Codinx collaborates with trusted industry providers under strict data-protection agreements:
- Brevo: Dispatches transactional emails including password resets, account verification OTPs, and security alerts.
- Razorpay: Handles secure payment processing for optional verified services. Codinx never receives or stores your bank credentials or payment card details.
- Supabase: Provides managed, encrypted PostgreSQL storage with row-level security.
8. User Rights & Data Deletion
You maintain full sovereignty over your data under global data protection regulations:
- Access & Export: You can request a summary of the personal information and logs associated with your account.
- Right to Erasure: You can request the permanent deletion of your account, uploaded study notes, and experiment history at any time by contacting support.
9. Children's Privacy
Codinx is an educational platform primarily targeted at secondary, collegiate, and university students. We do not knowingly collect personal identifiable information from children under the age of 13 without appropriate parental or institutional guardian consent.