This policy describes how LevelUpCode processes users' personal data, in accordance with Regulation (EU) 2016/679 (GDPR).
1. Data controller
The data controller is Samuele Celletti, who can be contacted for any request regarding personal data at privacy@levelupcode.org.
2. Data we collect
We collect: email and password (in encrypted form) for the account; display name and language, if provided; usage data (progress, XP, completed challenges, lessons read, badges, certificates); in case of a subscription, billing data is handled by the payment provider (Stripe), and we only store the subscription status.
3. Purposes and legal basis
We process data to: provide the service and manage the account (performance of the contract); handle payments (performance of the contract and legal obligations); improve the platform (legitimate interest). We do not sell your data to third parties.
4. Retention
Data is kept as long as the account is active. By deleting the account (from the Account page), the associated personal data is erased.
5. Your rights
You have the right of access, rectification, erasure, portability and restriction of processing. You can download your data and delete your account directly from the Account page, or write to us.
6. Security
Passwords are stored using hashing; traffic is encrypted (HTTPS); database backups are performed periodically and encrypted at rest.
7. Recipients and sub-processors
To provide the service we rely on third-party providers that process data on our behalf as processors (art. 28 GDPR). With each of them a data processing agreement (DPA) is in place (or being signed); for transfers to third countries, the Standard Contractual Clauses (SCC) approved by the EU Commission apply.
- Stripe — payment and subscription handling. Stripe Payments Europe (EU); any extra-EU transfers covered by SCC.
- Resend — sending transactional emails (account verification, password reset, notifications). US-based provider; transfer covered by SCC.
- Anthropic — AI assistant and content-generation features. US-based provider; transfer covered by SCC. The text you enter in the relevant features may be sent to the models.
- Google — authentication via Google account (OAuth login), for those who choose this option. US-based provider; transfer covered by SCC.
- Sentry — technical monitoring of application errors (to diagnose malfunctions). Technical error data, with personal data disabled by default; infrastructure located in the European Union (Germany).
- Hosting provider — servers and database on which the platform runs (infrastructure located in the European Union).
We do not sell or transfer your personal data for third-party marketing purposes.