Skip to content
Legal

Privacy policy

Last updated October 10, 2026

the short version

We collect what we need to run QuackCode, save your progress, power the Duck and handle your subscription. We don't sell your information and we don't run ads or third-party trackers. Other people see your work only through features you choose: leagues, friends, a public profile or replay, a class you join or an employer assessment you take. You can delete your account at any time in Settings.

1. Who we are and what this covers

QuackCode ("QuackCode", "we", "us") is a web app that teaches real-world coding with AI. QuackCode is run by [Legal entity name], which is the controller of the personal information described here. This policy covers:

2. What we collect

If you join the waitlist: your email address, the role you picked (for example developer, student, instructor or hiring), and when you signed up.

If you use the app:

If an employer invites you to an assessment: we receive your name and email address from the employer, as they entered them, so we can send you the invite. This can happen before you have a QuackCode account.

3. Cookies, local storage and analytics

The app stores your sign-in session and a local copy of your progress in your browser's local storage, so it works smoothly and offline. The website stores only your light or dark theme choice.

We don't use advertising cookies, third-party trackers or ad SDKs. We may use Vercel Web Analytics on the website, which counts visits in aggregate and doesn't use cookies.

4. The Duck and our AI provider

When you use the Duck, we send your message, the relevant project files and your current code to our AI provider, Anthropic, to generate the reply. We don't send your name or email with it. Under its commercial terms, Anthropic does not use this data to train its models.

Please don't put personal information, passwords, API keys or other secrets in your code or messages. AI replies can be wrong, so check what the Duck tells you.

5. How we use it

What we doInformation usedLegal basis (EU, UK)
Run the app and save your progress across devicesAccount, profile, learning activityContract
Grade checks and build your scorecardsLearning activityContract
Generate Duck repliesYour message, the relevant project files and your current codeContract
Run weekly leagues and move learners between tiersPublic name, Duck, XP, league tier and historyContract
Connect you with friends and show each other your progressPublic name, Duck, streak, XP, friend code and friendsContract
Show your public profile and public replays, if you turn them onProfile, completed projects and scores, replays you make publicContract
Run classes and show instructors their students' progressAccount, profile, learning activity, class data, replays of assigned workContract
Run assessments and show the results to the employer who invited youCandidate name and email, assessment results and replayContract
Send assessment invites on an employer's behalfName and email address entered by the employerLegitimate interests (ours and the employer's)
Manage your free trial and subscriptionAccount, subscription statusContract
Send account emails: sign-in links, password resets and receiptsEmail address, account, subscription statusContract
Email you product updatesEmail address, waitlist roleConsent (unsubscribe any time)
Improve projects, hints and difficulty, using statistics and de-identified samples of learner workLearning activityLegitimate interests
Answer support requestsSupport emails, accountContract or legitimate interests
Keep QuackCode secure and prevent abuse, including sandbox and trial abuseAccount, technical data, learning activityLegitimate interests
Prevent abuse of leagues, friends, profiles, classes and assessments, such as XP cheating, offensive usernames, harassment and spam invitesAccount, profile, league and friend activity, class and assessment data, technical dataLegitimate interests
Meet legal, tax and accounting dutiesSubscription and billing recordsLegal obligation

Scroll sideways to see the whole table.

We never use your work to train third-party AI models. We don't use your information for advertising, we don't sell it, and we don't make decisions about you that have legal or similarly significant effects based only on automated processing. In Hire, scores are produced automatically, but QuackCode doesn't make hiring decisions: the employer does, and our terms don't allow employers to use QuackCode as the only basis for such decisions without human review.

6. What other people can see

Some features show your activity to other people. Your "public name" is your username if you set one, otherwise your first name.

FeatureWho sees itWhat they seeYour control
Weekly leaguesThe other learners in your league group (up to 30 at your tier, Bronze to Diamond)Your public name, the Duck you chose and your XP that weekYou're placed in a league only in weeks you earn XP
FriendsPeople you connect with using a friend codeYour public name, Duck, current streak, XP this week, total XP and whether you practiced todayRemove a friend any time; this stops the sharing for both of you
Public profileAnyone with the link app.quackcode.dev/u/<username>Your name, username, Duck, when you joined, total XP, streak, league tier, the projects you finished with your best score and number of attempts, and the replays you made publicOff by default; needs a username. Turn it on or off in Settings
Shared replaysAnyone with the link to a replay you made publicYour scores, a timeline of what you did (edits, prompts to the Duck, check runs, hints and review flags) and snapshots of your codePrivate unless you make it public. Make it private or delete it any time
Classes you joinThe class owner (the instructor)Your name, email address, streak, last active date and total XP, and for assigned projects: your best score and score breakdown, flags (for example accepting AI code without running checks), number of attempts and the replay of that submissionLeave the class any time. The instructor can also remove you
Classes you runStudents who join with your codeThe class name, your public name and the assignmentsRemove students, or delete the class with your account
Hire assessments you takeOnly the employer who invited youYour name and email as the employer entered them, your status, start and submit times, scores and the replay of the assessmentTaking an assessment is your choice. Submitted scores and status stay with the employer (see section 8)

Scroll sideways to see the whole table.

Replays include your prompts to the Duck and snapshots of your code, so keep personal information and secrets out of them. Nobody else sees your work beyond what's listed here and in section 7.

7. Who we share it with

We use service providers that process information for us under contract and only on our instructions:

ProviderWhat they do for us
SupabaseDatabase and sign-in (United States)
VercelHosting the website and the app, and running server functions
AnthropicGenerating Duck replies
ResendSending sign-in and account emails, and assessment invites on employers' behalf
StripePayments and billing, when paid plans are on
GitHub and GoogleSign-in, only if you choose to sign in with them

Instructors and employers. If you join a class, its instructor receives the information listed in section 6 for that class. If you take an employer's assessment, that employer receives your results and the replay for that assessment, and nothing else from your account. Instructors and employers are responsible for how they use this information. Apart from this and the features in section 6, nobody else sees your work.

We may also disclose information if the law requires it, to protect people's safety or our rights, or as part of a merger or sale of QuackCode, in which case this policy keeps applying to your information.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

8. How long we keep it

9. Your choices and rights

We answer requests within 30 days (45 where state law allows) and may need to confirm it's you, usually by email from the address on your account. We won't treat you differently for using your rights.

10. US state privacy rights

If you live in California or another US state with a consumer privacy law (such as Colorado, Connecticut, Virginia, Texas or Oregon), you have the right to know what personal information we collect and how we use and disclose it, to access and get a copy of it, to correct it, and to delete it. The categories we collect are listed in section 2: identifiers (such as your name, email, username, friend code, account IDs and IP address), commercial information (your subscription and billing records), internet or other electronic activity (your learning activity, league, friend, class and replay data, and technical data), professional or employment-related information (your results in an employer's assessment, if you take one), and inferences limited to your skill scores in QuackCode. We collect them from you, your browser and device, GitHub or Google if you sign in with them, Stripe for payments, and employers who invite you to an assessment. We use them for the purposes in section 5 and disclose them only as described in sections 6 and 7.

We don't sell or share personal information as those laws define it, and we don't use sensitive personal information to infer anything about you. You can use an authorized agent to make a request; we'll ask the agent for proof of your permission. If we deny a request, you can appeal by replying to our answer.

11. If you're in the EU or UK

The legal bases we rely on are listed in section 5. You also have the right to object to processing based on legitimate interests, to restrict processing, to data portability, and to withdraw consent at any time without affecting earlier processing. You can complain to your local data protection authority. We store information in the United States; where the law requires, transfers are protected by the European Commission's Standard Contractual Clauses or an equivalent safeguard.

For Hire, the employer decides to assess you and what to do with your results, while we run the assessment in QuackCode. That means the employer and QuackCode may each be responsible for your assessment data under data protection law. For questions about an employer's use of your results or its hiring decisions, contact the employer; for anything about QuackCode, contact us.

12. Age and children

You must be at least 13 to use QuackCode. If you're under 18 (or the age of majority where you live), you need a parent or guardian's permission. In the EU or UK, if you're under 16, you need a parent's consent where local law requires it. The same applies to classes and Hire. Hire assessments are only for people who are 18 or older, or of legal working age where they live. QuackCode is not directed at children under 13, and we don't knowingly collect their information. If you believe a child under 13 has given us information, email privacy@quackcode.dev and we'll delete it.

13. Security

Information is encrypted in transit, passwords are stored hashed by our sign-in provider, and access to production systems is limited to the people who need it. No system is perfectly secure; if a breach affects your information, we'll tell you and the authorities as the law requires.

14. Changes and contact

If we change this policy, we'll update the date at the top. If a change materially affects how we use your information, we'll tell you by email or in the app before it takes effect.

Privacy questions and requests: privacy@quackcode.dev. Help with the app: support@quackcode.dev. Anything else: hello@quackcode.dev.