Koda · Stackrift
Privacy Policy
Last updated: May 29, 2026 · Effective: May 29, 2026
This Privacy Policy explains how Koda collects, uses, shares, and protects information when you use the Koda mobile application ("Koda," "the app"). Koda is operated by Stackrift ("we," "us," "our"), the data controller. By creating an account or using Koda, you agree to the practices described here. If you do not agree, please do not use the app.
1. Who we are & scope
Koda is a learn-to-code application operated by Stackrift, an independent software studio. This policy covers the Koda app on iOS and Android. Our company-wide and website practices are described in the Stackrift Privacy Policy. Each of our apps has its own app-specific policy; this one governs Koda.
2. Information we collect
Account & authentication
- Email address and authentication tokens, handled by our authentication provider (Supabase). We never see or store your password in plaintext.
- Sign in with Apple. If you use Apple sign-in, Apple provides us a user identifier and, depending on your choice, your email or a private relay email. We use it only to create and secure your account.
- Age / year of birth. We ask for your birth year at sign-up to confirm you meet our minimum age (see Section 13). We store your age-eligibility status, not a full date of birth.
Profile & learning data
- Display name, optional profile picture, learning preferences and settings.
- Your progress, streaks, XP, badges, accuracy statistics, and lesson/exercise history — the data that makes the app work and persists across your devices.
Code you write and run ("Your Content")
- When you run code, the code and any input you provide are transmitted to our code-execution service to compile/run it and return the output to you.
- We do not retain the content of your code. We store only execution metadata — the language, the size in bytes, the result status, and a timestamp — to enforce fair-use limits and diagnose problems. Program output is returned to your device and not stored on our servers.
- Please don't paste secrets, passwords, or other people's personal data into code you run.
Device, diagnostic & usage data
- Crash and error diagnostics (via Sentry): crash reports, error messages, app version, OS version, and device model, to find and fix bugs.
- Product analytics (via PostHog): in-app events and feature usage, to understand what's working and improve Koda. This is pseudonymous and used in aggregate.
Advertising data (free tier only)
- If you use the free tier and consent (via Apple's App Tracking Transparency prompt on iOS, and where applicable on Android), we collect your device's advertising identifier and limited ad-interaction data to serve ads via Google AdMob and keep Koda free. If you decline, you'll still see ads, but non-personalized ones.
Purchases
- Subscription and purchase status, managed by RevenueCat together with the Apple App Store / Google Play. We never see or store your payment card details — those stay with Apple/Google.
AI features
- If and when you use AI-assisted features (e.g., an AI tutor or code feedback), the text you submit and relevant code/context are sent to our AI provider, Anthropic, to generate a response. Anthropic does not use data submitted through its API to train its models. These features are optional.
Support communications
- If you email us, we keep your message and contact details to respond and improve support.
3. Permissions we request
- Camera — only when you tap "take a photo" to set a profile picture.
- Photo library — only when you pick an existing image as your profile picture.
- Notifications — to send streak reminders and learning nudges (you can disable these any time in device settings).
- Network — required to sign in, sync progress, load lessons, and run code.
- Tracking / Advertising ID — only with your consent (ATT on iOS; on Android the
AD_IDpermission), used by AdMob for ad personalization and frequency capping. You can opt out in your device's ad settings.
4. How we use information
- Provide and operate the app — sign-in, syncing, lessons, and running your code.
- Personalize and remember your learning state across devices.
- Process subscriptions and unlock premium features.
- Diagnose crashes, secure the service, and prevent abuse (e.g., enforce fair-use run limits).
- Understand usage in aggregate to improve the product.
- Serve ads on the free tier (with consent where required).
- Provide optional AI features when you use them.
- Comply with legal obligations.
5. Legal bases (EEA/UK users)
Where the GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the app you signed up for); consent (advertising/tracking, and optional AI features — you can withdraw it any time); legitimate interests (security, abuse prevention, diagnostics, and product improvement, balanced against your rights); and legal obligation where applicable.
6. Third-party services we use
Each is an independent provider governed by its own privacy policy. We share only the data needed for each to perform its function.
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, file storage (US) |
| Apple | Sign in with Apple; App Store purchases |
| AdMob advertising; Google Play purchases | |
| RevenueCat | Subscription management |
| Sentry | Crash & error diagnostics |
| PostHog | Product analytics |
| Expo / EAS | Builds and over-the-air updates |
| Our code-execution infrastructure | Compiling and running the code you write (no code content retained) |
| Anthropic | Optional AI features (does not train on API data) |
7. Advertising & your choices
On the free tier we use Google AdMob. With your consent we show personalized ads; without it, we show non-personalized ads. You can control this through Apple's App Tracking Transparency, Android's ad settings, and — for EEA/UK users — the in-app consent (UMP) form available in Settings → Ad privacy options. Under certain US state laws (e.g., California's CPRA), personalized advertising may be considered "sharing" of personal information; you can opt out using the controls above. We do not sell your personal information.
8. How we share information
We share personal data only with the processors listed in Section 6 (to provide the service), when required by law or to protect rights and safety, and in connection with a business transfer (e.g., merger or acquisition), in which case this policy continues to govern your data. We do not sell your personal data.
9. International data transfers
We and our providers process data in the United States and potentially other countries. Where required, transfers are protected by appropriate safeguards such as Standard Contractual Clauses.
10. Data retention
We keep your account and learning data while your account is active. Diagnostic and analytics data is kept for a limited period and then deleted or aggregated. Code-execution metadata is retained only as long as needed for fair-use enforcement and troubleshooting. When you delete your account, we delete or anonymize your personal data (see Section 12), subject to limited retention required by law.
11. Your rights
Depending on where you live (e.g., GDPR/UK GDPR, California's CCPA/CPRA, and similar laws), you may have the right to access, correct, delete, port, or restrict your personal data, to object to certain processing, and to withdraw consent. To exercise any of these, email support@stackrift.dev. You also have the right to lodge a complaint with your local data protection authority. We will not discriminate against you for exercising your rights.
12. Account & data deletion
You can delete your account and associated data at any time:
- In the app: Settings → Delete account; or
- On the web: koda-privacy.vercel.app/delete-account; or
- By emailing support@stackrift.dev.
We process deletion requests within 30 days.
13. Children's privacy
Koda is not directed to children under 13 (or the higher minimum age required in your country). We ask for your birth year at sign-up to enforce this and do not knowingly collect personal information from children under that age. If you believe a child has provided us personal information, contact us and we will delete it.
14. Security
We protect your data with encryption in transit (HTTPS/TLS) and at rest, database row-level security, and access controls. No system is perfectly secure, but we work to safeguard your information with reasonable, industry-standard measures.
15. Changes to this policy
We may update this policy from time to time. Material changes will be communicated in the app or by email, and the "Last updated" date above will change. Continued use after an update means you accept the revised policy.
16. Contact
Questions or requests? Email support@stackrift.dev. Data controller: Stackrift.