Privacy policy
Last updated October 10, 2026
We collect what we need to run QuackCode, save your progress, power the Duck and handle your subscription. We don't sell your information and we don't run ads or third-party trackers. Other people see your work only through features you choose: leagues, friends, a public profile or replay, a class you join or an employer assessment you take. You can delete your account at any time in Settings.
1. Who we are and what this covers
QuackCode ("QuackCode", "we", "us") is a web app that teaches real-world coding with AI. QuackCode is run by [Legal entity name], which is the controller of the personal information described here. This policy covers:
- the website at quackcode.dev and its waitlist;
- the QuackCode web app at app.quackcode.dev;
- emails we send and support conversations with us.
2. What we collect
If you join the waitlist: your email address, the role you picked (for example developer, student, instructor or hiring), and when you signed up.
If you use the app:
- Account details. Your email address, name, avatar and how you sign in (email and password, an email sign-in link, GitHub or Google). If you sign in with GitHub or Google, we receive your name, email address, profile photo URL and an account identifier from them. Passwords are handled by our sign-in provider and stored hashed; we never see them.
- Profile. Your username, the Duck costume you chose, your track, your onboarding answers, such as your experience level and goals, and your profile settings, including whether your public profile is on.
- Learning activity. The code you write in projects, your specs and prompts, your chats with the Duck, check runs, hints, review flags, scores, XP, streaks, project submissions, completed projects and drills, and capstone progress.
- Leagues and friends. Your league tier, the league group you're placed in each week, your weekly XP and league history, your friend code and the friends you connect with.
- Shared replays. Replays you create from a scorecard: your scores, a timeline of what you did (edits, prompts to the Duck, check runs, hints and review flags), snapshots of the code you wrote, and whether each replay is public.
- Classes (Campus). If you create a class: its name, join code, assignments and members. If you join one: your membership and your work on assigned projects.
- Assessments (Hire). If you create an assessment: the project it's based on and the candidates you invite, including the names and email addresses you enter for them. If you take one: your status, start and submit times, scores, flags and the replay of your work.
- Subscription status. Your plan, trial dates, renewal dates and Stripe customer ID. Card details go only to Stripe; we never receive them.
- Technical data. IP address, browser and device type, server logs and error logs.
- Support emails. What you send us and our replies.
If an employer invites you to an assessment: we receive your name and email address from the employer, as they entered them, so we can send you the invite. This can happen before you have a QuackCode account.
3. Cookies, local storage and analytics
The app stores your sign-in session and a local copy of your progress in your browser's local storage, so it works smoothly and offline. The website stores only your light or dark theme choice.
We don't use advertising cookies, third-party trackers or ad SDKs. We may use Vercel Web Analytics on the website, which counts visits in aggregate and doesn't use cookies.
4. The Duck and our AI provider
When you use the Duck, we send your message, the relevant project files and your current code to our AI provider, Anthropic, to generate the reply. We don't send your name or email with it. Under its commercial terms, Anthropic does not use this data to train its models.
Please don't put personal information, passwords, API keys or other secrets in your code or messages. AI replies can be wrong, so check what the Duck tells you.
5. How we use it
| What we do | Information used | Legal basis (EU, UK) |
|---|---|---|
| Run the app and save your progress across devices | Account, profile, learning activity | Contract |
| Grade checks and build your scorecards | Learning activity | Contract |
| Generate Duck replies | Your message, the relevant project files and your current code | Contract |
| Run weekly leagues and move learners between tiers | Public name, Duck, XP, league tier and history | Contract |
| Connect you with friends and show each other your progress | Public name, Duck, streak, XP, friend code and friends | Contract |
| Show your public profile and public replays, if you turn them on | Profile, completed projects and scores, replays you make public | Contract |
| Run classes and show instructors their students' progress | Account, profile, learning activity, class data, replays of assigned work | Contract |
| Run assessments and show the results to the employer who invited you | Candidate name and email, assessment results and replay | Contract |
| Send assessment invites on an employer's behalf | Name and email address entered by the employer | Legitimate interests (ours and the employer's) |
| Manage your free trial and subscription | Account, subscription status | Contract |
| Send account emails: sign-in links, password resets and receipts | Email address, account, subscription status | Contract |
| Email you product updates | Email address, waitlist role | Consent (unsubscribe any time) |
| Improve projects, hints and difficulty, using statistics and de-identified samples of learner work | Learning activity | Legitimate interests |
| Answer support requests | Support emails, account | Contract or legitimate interests |
| Keep QuackCode secure and prevent abuse, including sandbox and trial abuse | Account, technical data, learning activity | Legitimate interests |
| Prevent abuse of leagues, friends, profiles, classes and assessments, such as XP cheating, offensive usernames, harassment and spam invites | Account, profile, league and friend activity, class and assessment data, technical data | Legitimate interests |
| Meet legal, tax and accounting duties | Subscription and billing records | Legal obligation |
Scroll sideways to see the whole table.
We never use your work to train third-party AI models. We don't use your information for advertising, we don't sell it, and we don't make decisions about you that have legal or similarly significant effects based only on automated processing. In Hire, scores are produced automatically, but QuackCode doesn't make hiring decisions: the employer does, and our terms don't allow employers to use QuackCode as the only basis for such decisions without human review.
6. What other people can see
Some features show your activity to other people. Your "public name" is your username if you set one, otherwise your first name.
| Feature | Who sees it | What they see | Your control |
|---|---|---|---|
| Weekly leagues | The other learners in your league group (up to 30 at your tier, Bronze to Diamond) | Your public name, the Duck you chose and your XP that week | You're placed in a league only in weeks you earn XP |
| Friends | People you connect with using a friend code | Your public name, Duck, current streak, XP this week, total XP and whether you practiced today | Remove a friend any time; this stops the sharing for both of you |
| Public profile | Anyone with the link app.quackcode.dev/u/<username> | Your name, username, Duck, when you joined, total XP, streak, league tier, the projects you finished with your best score and number of attempts, and the replays you made public | Off by default; needs a username. Turn it on or off in Settings |
| Shared replays | Anyone with the link to a replay you made public | Your scores, a timeline of what you did (edits, prompts to the Duck, check runs, hints and review flags) and snapshots of your code | Private unless you make it public. Make it private or delete it any time |
| Classes you join | The class owner (the instructor) | Your name, email address, streak, last active date and total XP, and for assigned projects: your best score and score breakdown, flags (for example accepting AI code without running checks), number of attempts and the replay of that submission | Leave the class any time. The instructor can also remove you |
| Classes you run | Students who join with your code | The class name, your public name and the assignments | Remove students, or delete the class with your account |
| Hire assessments you take | Only the employer who invited you | Your name and email as the employer entered them, your status, start and submit times, scores and the replay of the assessment | Taking an assessment is your choice. Submitted scores and status stay with the employer (see section 8) |
Scroll sideways to see the whole table.
Replays include your prompts to the Duck and snapshots of your code, so keep personal information and secrets out of them. Nobody else sees your work beyond what's listed here and in section 7.
7. Who we share it with
We use service providers that process information for us under contract and only on our instructions:
| Provider | What they do for us |
|---|---|
| Supabase | Database and sign-in (United States) |
| Vercel | Hosting the website and the app, and running server functions |
| Anthropic | Generating Duck replies |
| Resend | Sending sign-in and account emails, and assessment invites on employers' behalf |
| Stripe | Payments and billing, when paid plans are on |
| GitHub and Google | Sign-in, only if you choose to sign in with them |
Instructors and employers. If you join a class, its instructor receives the information listed in section 6 for that class. If you take an employer's assessment, that employer receives your results and the replay for that assessment, and nothing else from your account. Instructors and employers are responsible for how they use this information. Apart from this and the features in section 6, nobody else sees your work.
We may also disclose information if the law requires it, to protect people's safety or our rights, or as part of a merger or sale of QuackCode, in which case this policy keeps applying to your information.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
8. How long we keep it
- Account and learning data: while your account is active. If you delete your account, we delete this data within 30 days, and it leaves our backups within a further 30 days.
- League history: up to 12 months.
- Shared replays: until you delete them or your account.
- Friends: until either of you removes the other, or deletes your account.
- Classes: until the instructor deletes the class or their account. If you leave or are removed from a class, the instructor no longer sees your progress in it.
- Assessment candidate records: kept in the employer's account until the employer deletes them, and for at most 24 months. If a candidate deletes their QuackCode account, the employer keeps the scores and status already submitted, but the replay is deleted.
- Waitlist entries: until QuackCode launches and for up to 12 months after, unless you ask us to delete yours sooner.
- Billing records: up to 7 years, for tax and accounting.
- Server and error logs: up to 90 days.
- AI request logs: up to 30 days.
- Statistics (for example, how many learners passed a check) are kept without anything that identifies you.
9. Your choices and rights
- Delete your account in the app under Settings, Account, Delete account, or by email (see Delete your account). If you have an active subscription, we cancel it when you delete your account, and you won't be charged again.
- Download your data any time in Settings, Your data. To see or correct anything else, email privacy@quackcode.dev.
- Control what others see: turn your public profile off in Settings, make a replay private or delete it, remove a friend, or leave a class, at any time.
- Cancel your subscription any time in Settings, Manage billing.
- Unsubscribe from product emails with the link in any of them. Account emails, such as sign-in links and receipts, are part of the service.
We answer requests within 30 days (45 where state law allows) and may need to confirm it's you, usually by email from the address on your account. We won't treat you differently for using your rights.
10. US state privacy rights
If you live in California or another US state with a consumer privacy law (such as Colorado, Connecticut, Virginia, Texas or Oregon), you have the right to know what personal information we collect and how we use and disclose it, to access and get a copy of it, to correct it, and to delete it. The categories we collect are listed in section 2: identifiers (such as your name, email, username, friend code, account IDs and IP address), commercial information (your subscription and billing records), internet or other electronic activity (your learning activity, league, friend, class and replay data, and technical data), professional or employment-related information (your results in an employer's assessment, if you take one), and inferences limited to your skill scores in QuackCode. We collect them from you, your browser and device, GitHub or Google if you sign in with them, Stripe for payments, and employers who invite you to an assessment. We use them for the purposes in section 5 and disclose them only as described in sections 6 and 7.
We don't sell or share personal information as those laws define it, and we don't use sensitive personal information to infer anything about you. You can use an authorized agent to make a request; we'll ask the agent for proof of your permission. If we deny a request, you can appeal by replying to our answer.
11. If you're in the EU or UK
The legal bases we rely on are listed in section 5. You also have the right to object to processing based on legitimate interests, to restrict processing, to data portability, and to withdraw consent at any time without affecting earlier processing. You can complain to your local data protection authority. We store information in the United States; where the law requires, transfers are protected by the European Commission's Standard Contractual Clauses or an equivalent safeguard.
For Hire, the employer decides to assess you and what to do with your results, while we run the assessment in QuackCode. That means the employer and QuackCode may each be responsible for your assessment data under data protection law. For questions about an employer's use of your results or its hiring decisions, contact the employer; for anything about QuackCode, contact us.
12. Age and children
You must be at least 13 to use QuackCode. If you're under 18 (or the age of majority where you live), you need a parent or guardian's permission. In the EU or UK, if you're under 16, you need a parent's consent where local law requires it. The same applies to classes and Hire. Hire assessments are only for people who are 18 or older, or of legal working age where they live. QuackCode is not directed at children under 13, and we don't knowingly collect their information. If you believe a child under 13 has given us information, email privacy@quackcode.dev and we'll delete it.
13. Security
Information is encrypted in transit, passwords are stored hashed by our sign-in provider, and access to production systems is limited to the people who need it. No system is perfectly secure; if a breach affects your information, we'll tell you and the authorities as the law requires.
14. Changes and contact
If we change this policy, we'll update the date at the top. If a change materially affects how we use your information, we'll tell you by email or in the app before it takes effect.
Privacy questions and requests: privacy@quackcode.dev. Help with the app: support@quackcode.dev. Anything else: hello@quackcode.dev.