Privacy
Last updated 2026-09-25
What we store
Your email address, your name if you give one, and a password hash (never the password itself). If you sign in with GitHub or Google we store the account link, not your credentials.
Everything you produce while practising: your answers, your submitted code, the grades, the rubric results and the spaced-repetition schedule derived from them.
Operational records: model-call metadata (a hash of the prompt, latency, token counts and cost), rate-limit counters and error logs.
What we do not store
Card numbers. Payments go through Stripe, which holds the card details; we keep only a customer identifier and the plan status.
The content of your prompts in our cost records: we store a hash, not the text.
Who sees it
Your answers are visible to you. Support and admin staff can see an attempt when you dispute its grade, because a person reviews every dispute.
Answers are sent to Anthropic's API for grading. They are processed to produce a grade and are not used by us for anything else.
A share badge shows only your score and track percentages. It never contains question text or your answers.
Your control
You can export everything we hold about you as JSON from the account page, at any time.
You can delete your account from the same page. Deletion is immediate and permanent: sessions, answers, grades and schedules go with it.
Cookies
One session cookie keeps you signed in, and one preference stores your light or dark theme choice. There is no advertising or cross-site tracking.
Contact
Questions about your data: privacy@buildstep.org.