Privacy Policy
Last updated: July 10, 2026
This Privacy Policy describes how CodeTeach.ai, operated by Martlet Solutions, LLC, a Texas limited liability company (“CodeTeach,” “we,” “us,” or “our”), collects, uses, and shares your information when you use our service at codeteach.ai (the “Service”).
1. Information we collect
1.1 Account information
When you sign up, we collect (via Clerk, our authentication provider):
- Your email address
- Your name (if you provide it)
- A profile picture (if you provide one or sign in via Google/GitHub)
- The authentication method you used (email, Google, GitHub)
- Your sign-in history (timestamps and IP addresses, retained by Clerk)
1.2 Content you create
When you generate assignments, we store the inputs you provide (topic, learning objectives, description, language, difficulty) and the AI- generated outputs (starter code, solution code, tests, instructions, workflow YAML). This content is associated with your account and is never shared with other users.
1.3 Bring Your Own Key (BYOK) API keys
You may use Platform AI or provide your own API key for a supported AI provider (Anthropic, OpenAI, Google, Mistral, Groq, or DeepSeek). When you choose BYOK, we forward prompts to the provider you selected using your key, and that provider bills you directly. CodeTeach does not mark up or share in charges incurred through your key.
We encrypt your API key with AES-256-GCM the moment we receive it. We never log it, never display it back to you in full after entry, and never transmit it to any party other than the AI provider you specified.
1.4 Payment information
Payments are processed by Stripe. We do NOT see or store your credit card number or banking information. We receive only:
- A Stripe customer identifier
- The amount, currency, and date of each transaction
- Confirmation that a charge succeeded or failed
Stripe’s privacy policy: stripe.com/privacy.
1.5 GitHub data
When you install our GitHub App, we receive (via the GitHub API):
- Your GitHub username
- The names of organizations and repositories the App has access to
- Permission to create and modify repositories on your behalf
We use this only to deploy assignment template repositories you explicitly request. We do not read your existing private repository contents.
1.6 Usage analytics
With your consent, we use PostHog for anonymous, pathname-only page-view analytics so we can improve the Service. CodeTeach does not send your account identifier, name, email, page query strings, referrer URL, assignment content, or form contents to PostHog. The browser SDK uses an anonymous device identifier stored locally; dynamic user, session, and UUID path segments are replaced with “[id]”. Person profiles, feature tracking, automatic event capture, error capture, and session replay are disabled. We also instruct PostHog not to enrich events from the request IP address.
1.7 Error reports
We use Sentry to capture technical errors. Reports are limited to a sanitized error type, stack trace, identifier-redacted route, runtime environment, and release identifier. We remove free-form error messages, user and job identifiers, breadcrumbs, form contents, cookies, request headers and bodies, and assignment payloads before an event can be sent.
1.8 Cookies and similar technologies
We use cookies for the following purposes. We do not use third-party advertising cookies, and we do not embed third-party tracking pixels.
- Authentication (Clerk) — required for session management. Without these the Service cannot function.
- Referral attribution(“ct.ref”) — set when you click a referral link. First-party, 30-day expiry. Used only to credit a future signup to the referrer; cleared after attribution completes.
- Product analytics (PostHog) — an anonymous device identifier stored in local storage plus pathname-only page views, and only after consent. We do not send your CodeTeach user identifier or enable automatic capture or session replay.
- Cookie consent preference— records your acceptance or rejection of non-essential cookies so we don’t prompt you again on every visit.
If you are in the EU/EEA or UK, we request your consent before setting non-essential cookies via a banner.
1.9 Referral program
If you participate in our referral program, we generate a unique referral code tied to your account and store the relationship between referrers and referred users so we can grant credits to both parties (currently 2 credits to each person on signup and 5credits to each person when the new user makes their first purchase). Referrers can view aggregated statistics about their referrals (counts of signups and first-purchase conversions) but cannot see referred users’ identities, email addresses, or activity.
2. How we use your information
- To provide the assignment generation, validation, and deployment functionality
- To process payments for credit purchases
- To support authentication and payment emails sent by Clerk and Stripe, and to send service or legal notices when required
- To respond to support requests you initiate
- To investigate and prevent abuse, fraud, or violations of our Terms
- To improve the Service through aggregate analysis of usage patterns
We do not sell your personal information to third parties. We do not use your assignment content, prompts, or solutions to train any AI model.
3. Third parties who receive your information
We rely on the following sub-processors. Each receives only the information needed for the function they perform.
| Provider | Purpose | Data shared |
|---|---|---|
| Clerk | Authentication | Email, name, sign-in metadata |
| Render | Hosting (web + database) | All data we store |
| Stripe | Payment processing | Email, amount paid, customer ID |
| GitHub (Microsoft) | Repository creation, GitHub App auth | Generated assignment files, org installation ID, GitHub username |
| E2B | Code execution sandboxes (validation only) | Starter code, solution code, tests during validation only; sandboxes are destroyed after each run |
| Anthropic | AI inference (when using Platform AI) | Prompts and assignment content needed for the selected generation or review step, including uploaded and generated artifacts |
| OpenAI | AI inference (BYOK only) | Prompts and assignment content needed for the selected generation or review step, only when you provide an OpenAI key |
| Google (Gemini) | AI inference (BYOK only) | Prompts and assignment content needed for the selected generation or review step, only when you provide a Gemini key |
| Mistral | AI inference (BYOK only) | Prompts and assignment content needed for the selected generation or review step, only when you provide a Mistral key |
| Groq | AI inference (BYOK only) | Prompts and assignment content needed for the selected generation or review step, only when you provide a Groq key |
| DeepSeek | AI inference (BYOK only) | Prompts and assignment content needed for the selected generation or review step, only when you provide a DeepSeek key |
| Inngest | Background job orchestration | Job identifiers and checkpointed step inputs/outputs, which may include generated assignment artifacts and validation logs |
| Sentry | Error monitoring | Technical error metadata, stack traces, routes, runtime environment, and release identifier; request bodies and assignment payloads are excluded by configuration |
| PostHog | Consent-gated product analytics | Anonymous device identifier and identifier-redacted pathname-only page-view events; CodeTeach user and session IDs, query strings, referrer URLs, person profiles, and session replay are excluded |
| BetterStack | Uptime monitoring | Public health-check availability and response metadata |
| Featurebase | User feedback widget | Email, name, feedback content you submit |
| Google Workspace | Inbound email (admin@codeteach.ai) | Anything users email to our @codeteach.ai addresses |
| Infisical | Secrets management (operator-side, no user data passes through) | None |
| GoDaddy | Domain registrar + authoritative DNS | DNS query metadata; no assignment or account content |
4. How long we keep your information
- Account information: until you delete your account
- Assignment content: until you delete it or your account
- BYOK API keys: until you delete them or your account
- Payment records: retained by Stripe as required for tax, accounting, fraud prevention, and payment-dispute obligations
- Local usage records and consented analytics events: no longer than 2 years from the event date
- Sanitized error reports: no longer than 90 days
- Security audit records: no longer than 2 years; resolved local security findings and webhook delivery receipts are removed after 90 days
- Sign-in metadata: no longer than 1 year, except where the authentication provider must retain records for security or legal obligations
5. Your rights
Depending on your jurisdiction, you may have the following rights with respect to your personal information:
- Access: request a copy of the information we hold about you
- Correction: ask us to correct inaccurate information
- Deletion: ask us to delete your information (we will retain only what we are legally required to keep, such as transaction records)
- Portability: receive a copy of your assignment content in a machine-readable format (the in-app Download ZIP feature provides this)
- Objection: object to processing for analytics or marketing purposes
- Withdraw consent: where processing is based on consent, withdraw it at any time using Cookie choices in the site footer
You can permanently delete your CodeTeach account from Settings. This erases your CodeTeach profile, sessions, assignment artifacts, encrypted API keys, credits, and local billing history. GitHub repositories already deployed to an account you control remain there, and Stripe retains payment records it is legally required to keep. To exercise another right or request help with deletion, contact us at admin@codeteach.ai. We will respond within 30 days.
6. Children’s privacy
CodeTeach.ai is intended for instructors aged 13 and over. We do not knowingly collect personal information directly from anyone under 13.
FERPA: when you (an instructor) deploy assignments via CodeTeach for use with students, the student work itself stays on GitHub student repositories — we do not receive student personal information, student submissions, or grades. If your institution requires a Data Processing Agreement, contact us at admin@codeteach.ai.
7. Security
We use industry-standard security practices:
- HTTPS for all traffic
- AES-256-GCM encryption for BYOK API keys at rest
- Database encryption at rest (provided by Render Postgres)
- Strict access controls on production secrets (managed via Infisical)
- Regular dependency security scanning
No system is perfectly secure. If we become aware of a security incident affecting your information, we will notify you within the timelines required by applicable law.
8. International data transfers
Our services and most of our sub-processors are located in the United States. If you access CodeTeach from outside the US, your information will be transferred to and processed in the US. We rely on Standard Contractual Clauses for transfers from the EU/UK where applicable.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date and, for material changes, notify registered users via email or an in-app notice.
10. Contact
Questions about this policy or about your information: