
CodeSafe · Your information & rights
Privacy policy
Last updated: September 2, 2026
What we collect, why we need it, and how you can manage your information.
1. Who is responsible
CodeSafe Canada, operating under Varkelon Holdings LTD. operates CodeSafe. This policy covers our website and CodeSafe Academy learning services, including the mobile app. Where an institution provides a separate assessment service, its instructions and any service-specific privacy notice also explain that activity.
For privacy questions, access or correction requests, or a complaint, contact support@codesafeca.com and ask for the person responsible for privacy. You do not need to sign in to contact us.
2. Information we collect and use
- Account and access: name, email, account identifiers, selected trade, preferences, verification status, accepted terms versions and access entitlements, to identify your account and provide its features.
- Learning activity: answers, attempts, scores, progress and saved activity, to deliver practice, reviews and progress features across devices.
- AI Tutor: prompts, relevant learning context, replies, source references, usage counts and response reports, to answer questions, maintain conversations, apply usage limits and investigate problems.
- Support and communications: contact details, messages, attachments you provide, delivery records and preferences, for help requests, service notices and permitted marketing communications.
- Billing: customer and subscription identifiers, plan, payment status and transaction records. The payment processor collects payment details; CodeSafe does not store full card numbers or card security codes.
- Technical and security information: IP address or derived security identifiers, browser and device information, request logs, session events, page visits and diagnostics, to operate the service, measure usage, prevent abuse and investigate failures.
We collect information from you, from your use of the service and from providers handling authentication, payments and other service functions. Do not include passwords, payment details or unnecessary sensitive information in support messages or Tutor prompts.
3. Sign-in and the transition to Clerk
Where Clerk sign-in is enabled, Clerk processes credentials, email verification and authentication sessions. CodeSafe receives identity information to connect your sign-in to your CodeSafe account. Learning history, purchases and application permissions remain in our application database.
The Clerk sign-in flow sends your password to Clerk rather than to CodeSafe’s application login API. We retain existing protected authentication records during migration and recovery to preserve account continuity. Older app versions or services still using our previous sign-in flow process credentials through CodeSafe. Password changes in one system do not automatically update the other during this transition.
Use your existing CodeSafe email. We may require verification or support review before connecting records, especially for staff accounts. Changing the sign-in provider does not itself delete your CodeSafe account or purchase history.
4. Cookies, devices and guest trials
Cookies and browser storage support sign-in, session security, preferences and activity state. A guest trial creates a temporary session and records answers and scores without registration. Trial access expires; expiry does not mean every related security record is immediately deleted.
The mobile app stores authentication tokens using the operating system’s secure credential storage, keeps limited preferences and activity state on the device, and synchronizes supported learning activity with CodeSafe. Signing out clears authenticated local state; it does not delete your server account.
Where notification features are available and enabled, notification preferences and device delivery tokens support alerts. Push delivery can involve Expo, Apple and Google. You can manage permission through the app or device settings.
You can manage cookies and storage in your browser. Blocking essential storage can prevent sign-in or interrupt a trial. Vercel Web Analytics measures website usage; it does not give CodeSafe your Clerk password.
5. Providers and other disclosures
We use providers for defined service functions, including:
- Clerk for authentication where enabled.
- Vercel for website hosting and analytics, and Neon for hosted database services.
- Stripe for web payments and subscriptions.
- Resend for service email delivery.
- OpenAI for AI features. Using the Tutor sends relevant prompts and learning context to the model provider to generate a response. Avoid submitting information you do not want processed for that purpose.
Provider handling and retention depend on the service and applicable arrangements. We remain responsible for our own handling of information. Following an external website link subjects that separate interaction to the website’s own practices.
We do not sell personal information. We may disclose information at your direction, as required by law, for necessary security or dispute handling, or in a business transfer subject to applicable privacy obligations. We limit disclosures to the relevant purpose.
6. Retention and account deletion
We retain account and learning information while needed to provide the service. Retention also depends on the record’s purpose, unresolved support or billing issues, security needs and legal obligations.
Request permanent deletion in the Academy app under Account → Delete Account or on our account-deletion page. If you cannot sign in, contact support for identity verification and assistance.
Completed deletion removes supported learning and Tutor records, removes or replaces identifying profile details, disables the account and revokes access. Where a Clerk identity is connected, the flow also requests its removal. If identity or billing reconciliation fails, access remains disabled while support resolves the request; a pending request is not completed deletion.
Some records may remain where necessary: payment and accounting records, security and audit records, information needed for disputes, and support or issue reports. Removing an account link does not necessarily remove personal details included in a past message. A limited email suppression record helps us respect marketing opt-outs. Backups and provider records can remain until their applicable retention periods end. Ask support about a specific retained record or deletion request.
7. Your choices and privacy rights
You can request access, correction, deletion or information about our practices. We verify identity proportionately before releasing or changing account information and respond within applicable legal time limits. If we cannot fulfil a request, we explain the reason and available options, subject to lawful restrictions.
You may withdraw consent for optional uses, subject to legal or contractual restrictions and reasonable notice. We will explain any effect on service availability. Use the unsubscribe option in marketing email or contact support; essential account, security and transaction messages are handled separately.
If a concern remains unresolved, contact the Office of the Privacy Commissioner of Canada or the applicable privacy regulator.
8. Safeguards and international processing
We use access controls, protected authentication, encrypted connections and other technical and organizational safeguards appropriate to the information. No service can guarantee absolute security. Report suspected unauthorized access to support; never send us your password or verification code.
CodeSafe and its providers may process information outside your province or Canada, including in the United States. Information may be accessible to authorities under those jurisdictions’ laws. This policy is not a promise of Canadian-only storage.
9. Young users and policy changes
The Academy service is not intended for children under 13. If you believe a child under 13 has submitted personal information, contact us so we can investigate and take appropriate action.
We update the date when this policy changes, provide appropriate notice of material changes and seek consent where required before a new use or disclosure. Reading this policy or continuing to browse does not replace consent where affirmative consent is required.