Privacy Policy

Last updated: July 5, 2026

This policy explains what CodeTrain ("we", operated by Inferhaven) collects and how we use it.

Where your code goes depends on how you use CodeTrain.
  • Free skill & the codetrain agent (local): your source code stays on your machine. Only the small prompt snippets needed for a tutoring turn are sent through our model proxy to the AI provider — or, on bring-your-own-key, straight from your machine to the provider, never touching our servers. We don't copy or store your repository.
  • Managed in-browser tutor: the code you submit for review and any files you attach as context are sent to our servers and on to the AI model provider, and stored in your lesson session so you can resume it and see your history. Python and JavaScript you type run in your browser; bash and PHP run in an ephemeral, network-isolated sandbox on our infrastructure.

We don't use your code or lessons to train AI models, and we only use model providers under arrangements that don't train on your prompts.

What we collect

What we do with it

To operate and secure the Service, enforce plan limits, process payments, provide support, and improve the product. We do not use your code, prompts, or lessons to train AI models, and we do not sell your personal data.

AI processing & code execution

By default your turns use Anthropic's Claude (Haiku/Sonnet) models, sent directly to Anthropic's API. If you choose one of the optional "testing" models, your prompt is instead routed through our model gateway (OpenRouter) to that model's provider (for example OpenAI, Alibaba/Qwen, Z.ai, or Moonshot); the picker flags these. In every case we use arrangements that don't train on your prompts. When a lesson runs bash or PHP, your code executes in a short-lived, network-isolated container on our sandbox host and is deleted right after.

Service providers

We share the minimum necessary with: Clerk (authentication), Stripe (payments), Anthropic (the default Claude models), OpenRouter (model gateway for the optional testing models) and the providers it routes to for those (e.g. OpenAI, Alibaba/Qwen, Z.ai, or Moonshot), Cloudflare (web hosting/CDN/DNS), Fly.io (API hosting), Neon (database), Oracle Cloud (the sandbox host that runs bash/PHP lessons), and Sentry (error monitoring). Each processes data under its own terms.

Cookies

We use essential cookies for authentication/session management (via Clerk). We don't use advertising trackers.

Data retention

We keep account and usage data while your account is active and as needed for legal, accounting, and security purposes. Your lesson history — including code you submitted to the managed tutor — is kept while your account is active so you can resume and review it; deleting your account removes it. You can request deletion (below).

Your rights

Depending on where you live (e.g. GDPR/UK GDPR, CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Email us to exercise them.

Security

We use encryption in transit, scoped access tokens, and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data.

Children

The Service isn't directed to children under 16, and we don't knowingly collect their data.

Changes

We'll post updates here with a new date. Material changes may also be notified by email.

Contact

Privacy questions or data requests: [email protected].