Privacy Policy
This policy explains what CodeTrain ("we", operated by Inferhaven) collects and how we use it.
- Free skill & the
codetrainagent (local): your source code stays on your machine. Only the small prompt snippets needed for a tutoring turn are sent through our model proxy to the AI provider — or, on bring-your-own-key, straight from your machine to the provider, never touching our servers. We don't copy or store your repository. - Managed in-browser tutor: the code you submit for review and any files you attach as context are sent to our servers and on to the AI model provider, and stored in your lesson session so you can resume it and see your history. Python and JavaScript you type run in your browser; bash and PHP run in an ephemeral, network-isolated sandbox on our infrastructure.
We don't use your code or lessons to train AI models, and we only use model providers under arrangements that don't train on your prompts.
What we collect
- Account data — via our auth provider (Clerk): your email, name, and (if you sign in with GitHub/Google) basic profile info.
- Usage & metering — session counts, model token usage and cost, plan and entitlement state, so we can enforce limits and show your usage.
- Billing — handled by Stripe. We store a customer/subscription reference; we never see or store your full card number.
- Lesson content (managed in-browser tutor) — the code you submit, notes and questions you write, and any files you attach as context. We send these to the AI model to generate feedback and store them in your session so you can resume it and review your history.
- Prompt data — sent to the AI model provider to generate a tutoring response, under arrangements that do not train on your prompts.
- Support communications — if you email us.
What we do with it
To operate and secure the Service, enforce plan limits, process payments, provide support, and improve the product. We do not use your code, prompts, or lessons to train AI models, and we do not sell your personal data.
AI processing & code execution
By default your turns use Anthropic's Claude (Haiku/Sonnet) models, sent directly to Anthropic's API. If you choose one of the optional "testing" models, your prompt is instead routed through our model gateway (OpenRouter) to that model's provider (for example OpenAI, Alibaba/Qwen, Z.ai, or Moonshot); the picker flags these. In every case we use arrangements that don't train on your prompts. When a lesson runs bash or PHP, your code executes in a short-lived, network-isolated container on our sandbox host and is deleted right after.
Service providers
We share the minimum necessary with: Clerk (authentication), Stripe (payments), Anthropic (the default Claude models), OpenRouter (model gateway for the optional testing models) and the providers it routes to for those (e.g. OpenAI, Alibaba/Qwen, Z.ai, or Moonshot), Cloudflare (web hosting/CDN/DNS), Fly.io (API hosting), Neon (database), Oracle Cloud (the sandbox host that runs bash/PHP lessons), and Sentry (error monitoring). Each processes data under its own terms.
Cookies
We use essential cookies for authentication/session management (via Clerk). We don't use advertising trackers.
Data retention
We keep account and usage data while your account is active and as needed for legal, accounting, and security purposes. Your lesson history — including code you submitted to the managed tutor — is kept while your account is active so you can resume and review it; deleting your account removes it. You can request deletion (below).
Your rights
Depending on where you live (e.g. GDPR/UK GDPR, CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Email us to exercise them.
Security
We use encryption in transit, scoped access tokens, and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data.
Children
The Service isn't directed to children under 16, and we don't knowingly collect their data.
Changes
We'll post updates here with a new date. Material changes may also be notified by email.
Contact
Privacy questions or data requests: [email protected].