Privacy policy
What we collect, why, and what you can do about it.
This policy covers decembercode.tech. It is written from what the product actually does, not from a template.
1. What we collect
- Account
- Your email address and, if you set one, a password (stored only as a hash by our authentication provider). If you sign in with Google, Google gives us your email, name and profile picture URL. We never see your Google password.
- Profile
- Your name, and optionally your college and graduation year, which you can edit on your profile.
- Your work in the product
- Diagnostics you start and finish, the answers you give, the time you take, practice sessions, mock tests, readiness scores and the roadmap built from them. This is the product; without it there is nothing to diagnose.
- Payments
- If you subscribe, Razorpay processes the payment. We store the Razorpay customer and subscription identifiers, the plan, its status and period dates, and a record of each payment (amount, status, Razorpay payment id) so we can show receipts and activate your plan. We never receive or store your card number, UPI PIN or bank credentials.
- Email preferences
- Whether you have opted out of product email. Sign-in and receipt emails are always sent because the service needs them.
- The anonymous “try 3 questions” flow
- No account, nothing tied to you. A signed cookie on your device counts your tries for the day, and, as a backstop, we store a hash of your IP address that changes every day and cannot be turned back into the address. The raw IP is never stored.
- How you arrived
- The first page you landed on, the site that referred you (its domain only) and any referral code in the link, kept for 30 days in a cookie and saved to your profile if you create an account — so we can tell which channels bring students who actually use the product.
- Technical logs and analytics
- Our hosting provider keeps standard request logs (URL, time, status, approximate region) for reliability and security. We use privacy-respecting page analytics that does not set cookies. If we enable Google Analytics, it sets its own cookies to count visits and sessions; we do not send it your name, email or answers.
2. Why we use it
- To run the service for you: sign you in, score your sittings, build your roadmap, show your progress, activate your plan.
- To send the emails the service needs (sign-in links, receipts) and, unless you opt out, a small number of product emails.
- To keep the service safe: rate limits, abuse prevention, fixing errors.
- To understand and improve the product, and to publish general findings about placement readiness — only ever in anonymised, aggregated form (for example “the topics final-year students most often get wrong”), never in a way that identifies you, your college, or your scores.
We do not sell your data, and we do not share your scores or answers with employers, colleges or anyone else.
3. Who processes it for us
- Supabase — database and authentication (your account, profile, answers and scores). Access to answers and results is restricted to your own session and to the server; nobody can read another student’s data.
- Vercel — hosting, request logs and cookieless page analytics.
- Razorpay — payments and subscriptions, under its own privacy policy.
- Resend — delivery of sign-in and product email.
- Google — sign-in with Google if you choose it; Google Analytics only if we enable it.
These providers may store data on servers outside India. We choose them for their security practices and use only what the service needs.
4. Cookies
sb-…— your sign-in session (set by Supabase; required while you are signed in).dc_try— counts anonymous tries for the day; signed so it cannot be edited; expires within 36 hours.dc_landing— the first page and referrer that brought you here; 30 days.- Google Analytics cookies (
_ga,_ga_…) — only if we enable Google Analytics.
You can clear cookies in your browser at any time; you will be signed out and the anonymous try count resets.
5. How long we keep it
For as long as your account exists, so your history and readiness trend keep working. If you ask us to delete your account we delete or irreversibly anonymise your personal data within 30 days, except payment records we must keep for accounting and tax purposes. Anonymised aggregates cannot be linked back to you and may be kept.
6. Your rights and choices
- See and correct your profile on your profile page; change or set your password there.
- Opt out of product email from your profile or the unsubscribe link in any product email.
- Ask for a copy of your data, a correction we cannot make on the profile page, or deletion of your account by writing to support@decembercode.tech from the account’s email address. The same address handles any privacy complaint or grievance; we aim to respond within two working days and to resolve it within the time the law allows.
7. Security
Everything travels over HTTPS. Data access is enforced at the database with row-level rules, so a signed-in student can read only their own records; billing and anonymous-try tables are readable only by the server. Payment details never touch our servers.
8. Children
December Code is for college students and graduates and is not directed at children under 13. If you are under 18, use it with a parent or guardian’s consent.
9. Changes
When this policy changes we update the date at the top; for changes that affect how we use your data we tell you by email first. Questions: support@decembercode.tech. See also Terms of service and Contact.