Apex Coding AcademyExplore the curriculum

Privacy Policy

Effective August 15, 2026

This policy explains how Apex Coding Academy collects and uses information when you browse the site, create an account, purchase access, join an organization, complete coursework, or run hosted labs. We do not sell personal information or use student code for advertising.

Information we collect

We collect account identifiers and profile information supplied through Supabase authentication; organization membership and role information; purchase, invoice, subscription, refund, and dispute records supplied by Stripe; course enrollment, quiz, progress, certificate, API-key metadata, and hosted-lab usage; source files submitted to the hosted grader; support and email preferences; and bounded technical events such as page, lesson, conversion, error, browser, and device information. Payment card numbers are collected and processed by Stripe and are not stored by Apex.

How we use information

We use information to authenticate users, provide purchased curriculum, operate and secure isolated labs, grade submissions, enforce quotas, manage organization seats, process billing, prevent fraud and abuse, send requested transactional or educational messages, measure lesson completion and conversion, diagnose failures, meet legal obligations, and improve the academy. We do not train public or third-party AI models on student source submissions.

Hosted code and automated grading

Lab source is stored so a submission can be queued, executed, graded, audited, and supported. It is sent to an isolated execution provider with network access disabled and strict time and output limits. Server-owned expected answers remain outside the student execution environment. Do not submit production secrets, customer information, regulated data, or code you are not authorized to share.

Service providers

We use service providers acting on our instructions, including Supabase for authentication and PostgreSQL hosting, Stripe for payments, Zoho ZeptoMail for transactional email, PostHog for limited product analytics, E2B for isolated code execution, Redis infrastructure for bounded queues and coordination, and the configured hosting and content-delivery providers. These providers process information under their own security and privacy commitments. Some processing may occur outside your state or country.

Cookies and analytics

Authentication requires browser storage and cookies that keep a session secure. Product analytics are configured without automatic element capture and record defined events such as page views, checkout state, lesson tabs, lab outcomes, quiz scores, and completion. Analytics do not include submitted source code, API secrets, payment-card data, or raw grader artifacts.

Retention

We retain account and progress information while an account is active and for a reasonable recovery period afterward; billing and transaction records for the period required by tax, accounting, fraud, and legal obligations; suppression records as needed to honor opt-outs; and operational, lab, and security evidence only as long as needed for delivery, support, abuse prevention, and dispute handling. Backups expire under the production backup schedule. When deletion is required, data is removed or de-identified from active systems and expires from backups through their normal lifecycle.

Security

Controls include encrypted transport, server-only credentials, least-privilege service roles, row-level database restrictions, signature-verified webhooks, bounded request bodies, isolated lab execution, disabled lab egress, redaction, rate limits, idempotency, audit records, and restricted backup files. No system is perfectly secure; confirmed incidents are handled under the operational incident process.

Your choices and rights

You may update account information, cancel marketing email, manage billing through the customer portal, and request access, correction, export, or deletion of personal information. Applicable law may provide additional rights to restrict or object to processing or appeal a denied request. We verify identity and authority before fulfilling requests, and organization administrators may control organization-provided accounts and records.

Children

The academy is not directed to children under 16. We do not knowingly collect personal information from a child under 16. A parent or guardian who believes a child supplied information should contact us for review and deletion.

Changes and contact

Material changes will be posted with a new effective date and, when appropriate, communicated through the account email. Privacy requests and operational support inquiries may be sent to support@apexcodingacademy.com.