Privacy policy
Last updated 29 August 2026
This describes what the platform collects and, just as importantly, what it is built not to collect.
1. What we collect
- Account details. Your email address, display name, and whatever your OAuth provider returns when you sign in with GitHub or Google.
- Profile content. Your handle, bio, links, and avatar, all of which you choose to make public.
- What you post. Challenges, success criteria, uploads, attempts, evidence, reviews, and disputes.
- Payment records. Amounts, currency, status, and the payment provider’s identifiers. We never see or store your full card number.
- Operational logs. Request identifiers, timing, and error information, used to reconcile payments and diagnose faults.
2. What we deliberately do not collect
Sponsors need to know their placement was seen. That does not require us to know who saw it.
Impressions and clicks are recorded as counters in hourly buckets attached to a sponsorship, not to a person. There is no visitor identifier, no cross-site tracking cookie, no device fingerprint, and no per-visitor row. The database schema has nowhere to put one.
The consequence, stated honestly: we report aggregate exposure, not verified unique humans. Any advertiser told otherwise would be told something the measurement cannot support.
We also do not collect precise location, contacts, or biometric data, and we do not buy or enrich profiles from third-party data brokers.
3. Cookies
We set one kind of cookie: a session cookie so you stay signed in. It is HTTP-only, same-site, and secure in production, which means scripts cannot read it and it is not sent to other sites.
There are no advertising or cross-site tracking cookies.
4. What is public
Challenges, success criteria, sponsor history, attempts, model and tool attribution, review outcomes, and solver handles are public. That permanence is the point of the platform: it is what makes the record meaningful over time.
Your email address is never public. A bounty boost can be made anonymous, in which case your handle is not shown alongside it.
5. Who we share with
- Payment providers (Stripe, Razorpay), to process payments and payouts. They receive what they need to charge you and are bound by their own terms.
- Cloudflare, which hosts the application, its database, and its file storage.
- Authorities, where we are legally required to, or where necessary to investigate fraud.
We do not sell your data and we do not share it for advertising.
6. How long we keep things
Financial records are kept as long as tax and accounting rules require. The public challenge record is kept indefinitely, because a solved challenge is a permanent benchmark result and removing it would falsify the history.
If you delete your account, we remove your private account details and detach your handle from public content. The content itself, and the financial record around it, remains.
7. Your choices
You can request a copy of your data, correct it, or ask us to delete your account. Contact us through your account area. Depending on where you live you may have additional statutory rights, and we will honour them.
We cannot delete a completed payment record or remove a solved challenge from the public record, for the reasons above.
8. Security
Sessions use secure HTTP-only cookies. Payment webhooks are signature-verified and every financial write is idempotent. Uploads are validated and stored under unguessable keys. Secrets, tokens, and payment credentials are never written to logs.
No system is perfect. If you find a vulnerability, report it through your account area rather than disclosing it publicly, and we will respond.
9. Changes
If we change this policy in a way that materially affects what we collect, we will announce it before it takes effect.