Privacy Policy
Effective September 12, 2026
What We Collect
Koda collects account details you provide, learning progress, lesson answers, project code you save in the app, subscription status, promo redemption data, referral activity, device/app diagnostics, and limited analytics events used to improve onboarding, paywall conversion, and learning quality.
Who Controls Your Data
The controller of your personal information is λ©μ΄ν¬ μμ΄μ νΈ ν¨μ€νΈ (Make Agent Fast), κ²½κΈ°λ νμ±μ λνꡬ 10μ©μ¬3κΈΈ 30, 202νΈ (λ°μ‘λ), the Republic of Korea. Contact: support@dekoda.site.
Diagnostics and Error Reporting
Koda uses Sentry to receive production crash reports, error stack traces, app/browser and operating-system details, release identifiers, and a small sample of performance timing data. Koda disables Sentry session replay, screenshots, view hierarchies, console breadcrumbs, request bodies, cookies, authorization headers, and default personal information collection. Diagnostic URLs are stored without query strings or fragments. We use this information only to diagnose and improve reliability.
How We Use Data
We use data to provide the product, sync progress, unlock paid access, score lessons, personalize learning, prevent fraud and abuse, operate AI tutor features, respond to support requests, and meet legal or payment processor requirements.
Legal Bases for Processing
Where the law requires a legal basis, Koda relies on performance of the contract with you for your account, learning progress, billing, and support; on legitimate interests for security, fraud prevention, and product diagnostics; on your consent for optional analytics and marketing, which you can withdraw at any time without affecting what was processed before you withdrew it; and on legal obligation for tax and payment records.
AI Features
When you ask Koda Coach, request project review, or explain an answer, the relevant lesson/project context and your attempt may be sent to the configured AI provider. We bound those requests and cache generated educational responses where appropriate. To enforce the AI allowance, Koda records the feature used, AI provider and model, input/output token counts, cached-token counts when reported, estimated provider cost, and the monthly usage period. Koda does not expose or store provider API keys in your account.
AI Permission and Response Reports
AI help is optional and on by default. To generate help, Koda sends the relevant question, answer or code and lesson or project context to Google, Anthropic, or OpenAI, as selected by Koda. You can turn AI help off in Settings at any time; this stops future requests but cannot recall data already sent. When you change the switch, we store your choice, the disclosure version shown, and the time you made it. If you report an AI response, we collect the response text you choose to submit, reason, optional note, account identifier, language, feature, and lesson or project and item references. Reports are private, available to authorized Koda staff for safety and quality review, and deleted after 90 days or when you delete your account, whichever comes first.
Optional AI Avatars
When you choose to generate an avatar and consent, Koda sends your selected image and appearance choices to Google Gemini. Koda processes the uploaded original temporarily without saving it to our image storage. We retain generation records linked to your account, including your choices, consent version, request time, image checksum, and outcome, to operate the feature and enforce daily limits. Accepted portraits stay in your avatar library until account deletion. Unaccepted previews expire after 24 hours and are removed by the next daily cleanup run. Discarded images are removed immediately where possible; failed deletions and images belonging to deleted accounts are queued for the daily cleanup job. Accepted portraits can appear inside the signed-in app; outside the app they are served only while your profile is public. Image generation is optional and separate from AI tutor permission.
Payments
Web payments are processed by Polar. Native mobile payments are processed by Apple or Google and synchronized through RevenueCat. Koda stores the provider, membership tier, billing cadence, subscription status, renewal timing, and promo status needed to grant access, but does not store full card numbers.
Course Access
The complete catalog may be displayed so you can compare learning opportunities. Your membership tier determines which lesson and project content Koda releases to your account. Those access checks are also enforced by the database, not only by buttons in the interface.
Optional GitHub Companion
If you opt in, Koda uses a read-only GitHub App to verify one selected repository's branch, commit, pull-request, review, CI, and merge milestones. Koda stores the GitHub installation and repository identifiers, account/repository names, whether the repository is private, pull-request identifier/link, and milestone timestamps. Koda does not retain OAuth or installation tokens, source code, diffs, commit messages, review text, or comments. Revoking the connection in Koda deletes its retained evidence and uninstalls an installation when no other connected learner is using it. Shared organization installations remain available only to their other explicitly connected learners.
Public Profile
Your Koda profile is private by default: nothing about your account is visible outside the app until you turn on the public profile switch in Settings β Privacy. While that switch is on, anyone who has your profile link can see your username, display name, avatar, level, total XP, current and longest streak, league tier, the number of lessons you have completed, the achievements you have earned, and the date you joined. Two further switches in the same place decide whether the page also lists your completed projects (title, preview and any live link you added β never your saved source code) and your unrevoked certificates (verification link and project count). Your email address, year of birth, lesson answers, and AI conversations are never published. Koda asks search engines not to index these pages, but a public page can be opened by anyone with the link and we cannot guarantee that no search engine or archive copies it. Turning a switch off in Settings β Privacy removes that content from the page straight away; copies already cached elsewhere can take longer to disappear.
Sharing
We share data with service providers needed to run Koda, including hosting, database, analytics, AI, email/authentication, and payment providers. We do not sell personal information.
Optional Android Advertising Measurement
Android users can separately opt in to Meta advertising measurement. The Meta SDK receives app activation, registration and first lesson completion events, an anonymous installation identifier, and associated device and network information, to measure and improve Facebook and Instagram advertising. RevenueCat uses this identifier to share verified trial, subscription and renewal events, even when the app is closed. We do not deliberately send code, answers, email addresses, phone numbers or Google advertising IDs to this integration. Product analytics consent does not enable advertising measurement. You can withdraw in Advertising measurement or Privacy settings. Device event collection stops when you turn the choice off; stopping future billing-event sharing requires successful internet synchronization. Previously sent events cannot be recalled. Meta and RevenueCat process this data in the United States and other countries under their applicable privacy policies; you may contact support@dekoda.site about access, deletion or withdrawal. This integration is disabled on iOS.
Service Providers
Koda runs on a named set of providers, and each receives only what its job needs. Supabase provides the database and authentication, hosted on Amazon Web Services. Vercel hosts the web app. Sentry receives crash and error reports, configured to exclude personal information. Polar processes web payments as merchant of record. RevenueCat synchronizes the subscriptions bought in Apple's App Store and Google Play, which those stores process. AI features send the relevant lesson or project context together with your attempt or question to the AI provider the Koda team has selected β Anthropic, Google, or OpenAI. These providers operate in the United States and other countries, so using Koda involves an international transfer of the data described above.
International Transfers
Your data is stored and processed by the providers named above in the countries where they operate, which may be outside the country you live in. Where such a transfer needs a safeguard, it rests on the standard contractual clauses those providers publish, or on an adequacy decision where one covers the destination country. You can ask us at support@dekoda.site which safeguard applies to a particular provider.
Choices
You can change profile details and language in settings. You can delete your account from settings; deletion removes your profile and learning data from active product systems, subject to legal, security, and payment record retention. Optional GitHub connection data is deleted immediately when you revoke it in Koda or delete your Koda account. Account deletion first removes that account's provider access path and retained identifiers. Detailed deletion instructions are available at dekoda.site/delete-account.
How Long We Keep Data
Account and learning-progress data is kept for as long as the account exists and is removed from active product systems when you delete the account, as described at dekoda.site/delete-account. Billing and tax records are kept for as long as tax and payment law requires. Diagnostic error events are kept for no longer than 90 days. AI usage records and cached educational responses are kept as described in the AI Features section, and the AI usage records held against your account are removed when the account is deleted.
Your Rights
Depending on where you live, you can ask for access to your personal information, ask us to correct or delete it, ask for a portable copy, ask us to restrict processing, object to processing, and withdraw a consent you gave. Use Settings to change profile details or delete the account, follow the instructions at dekoda.site/delete-account, or write to support@dekoda.site. We answer within 30 days, and sooner where local law requires it β a request about personal information from a member in Korea is answered within the 10-day period Korean law sets.
Complaints
Please write to support@dekoda.site first so that we can put the problem right. You can also complain to the data-protection authority of the country where you live. In Korea, you can contact the Personal Information Protection Commission, or the privacy report centre operated by the Korea Internet & Security Agency at privacy.kisa.or.kr or on 118.
Age Requirement
Koda is for learners aged 14 and over. Sign-up asks for your year of birth and refuses an account to anyone younger. Koda is not directed at children under 14 and does not knowingly collect their personal information. If you believe a younger child has created an account, write to support@dekoda.site and we will delete it.
Contact
Questions can be sent to support@dekoda.site.