Privacy Policy
This page is a translation provided for convenience. In case of any discrepancy, the German version is the authoritative one: go to the German version
1. Controller
Responsible for the data processing on this website is:
Leonid Domahalskyy
Rude 13
24941 Flensburg
Germany
Email: leonid.domagalsky@gmail.com
Phone: 015205892880
2. Processing for registration and your account
To use Daily Coding you create a user account. In doing so we process your name, your email address and your password. The password is stored solely as a cryptographic hash (bcrypt). At no point is it available to us in plain text. To verify your email address and to reset your password we generate tokens with a limited lifetime.
The legal basis is the performance of the terms of use pursuant to Art. 6 (1) (b) GDPR.
3. Sign-in via third-party providers (OAuth)
If you sign in via GitHub or Google, we receive your email address, your name and, where applicable, your profile picture from that provider in order to create or link your account. No passwords held by the third-party providers are transmitted to us. The legal basis is your consent given by choosing the sign-in service (Art. 6 (1) (a) GDPR) as well as the performance of the contract (Art. 6 (1) (b) GDPR).
4. Usage data (challenges, ranking, streaks)
When you work on coding challenges, we store the source code you submit, the programming language you chose, the solution status and the points, leaderboard and streak data derived from them. This data is required for the core function of the platform (evaluation, leaderboard, progress). The legal basis is Art. 6 (1) (b) GDPR as well as our legitimate interest in a platform that works (Art. 6 (1) (f) GDPR).
What others can see is your name, the avatar you chose, your level, your current streak together with your streak record, and the number of challenges you have solved. That applies in the leaderboard, in the community feed and on your public profile page.
That profile page can be opened without signing in, so by people without an account with us as well. It is excluded from search engine indexing by a meta tag and is not listed in our sitemap. Your email address and the source code you submit remain invisible to other users.
5. Execution of source code
To evaluate your solutions, the code you submit is run in an isolated, self-hosted execution environment (sandbox). It runs on a server of Hetzner Online GmbH in Nuremberg, which to that extent acts as a processor (Art. 28 GDPR) on our behalf. The code is processed solely for the purpose of evaluation and is not passed on to uninvolved third parties.
6. Email delivery
To send system emails (email verification, password reset, welcome and account deletion confirmations) we use the service provider Resend (Resend, Inc.) as a processor. Your email address is transmitted to that provider in the process; delivery runs over its infrastructure in Ireland. The legal basis is Art. 6 (1) (b) and (f) GDPR.
7. Hosting and database
This website is operated at Vercel Inc.; the database is hosted at Neon in a data center in Frankfurt am Main. Both process the data named above on our behalf as processors (Art. 28 GDPR). When the website is opened, technically necessary access data (e.g. IP address, time, requested resource) is processed on the server side in order to keep operation secure and stable (Art. 6 (1) (f) GDPR). Vercel Inc. and Resend, Inc. are US companies; insofar as data is processed outside the EU/EEA, this takes place on the basis of appropriate safeguards (e.g. EU standard contractual clauses). The database and the execution environment for source code are located within the EU.
8. Audience measurement
To evaluate how the site is used we use Vercel Web Analytics from Vercel Inc. What is collected is the pages requested, the referrer, device type and country. The service works without cookies and without storing your IP address; no cross-device profiles are built. The legal basis is our legitimate interest in a statistical evaluation of usage (Art. 6 (1) (f) GDPR).
9. Error monitoring
To detect and fix technical errors we use Sentry from Functional Software, Inc. If an error occurs while the website is opened or while your request is being processed, technical details about it are transmitted to Sentry: the error message including the location in the code, the affected page or endpoint, the time, browser and operating system version as well as the language of the page. In addition, runtime data (e.g. the duration of a request) is collected on a sample basis in order to detect performance problems. The server also transmits log messages about failed operations (such as an e-mail that could not be delivered) and a daily summary of the reminder mailing; they contain technical details and internal identifiers, and e-mail addresses are removed before transmission.
Your IP address is not stored in the process, your user account is not linked to the error, and no screen recordings (session replay) are made. The data is stored in a Sentry data center within the EU; to that extent Sentry acts as a processor (Art. 28 GDPR) on our behalf. Sentry is a US company; insofar as access from outside the EU/EEA nevertheless takes place, this happens on the basis of appropriate safeguards (e.g. EU standard contractual clauses). The legal basis is our legitimate interest in the secure and error-free operation of the website (Art. 6 (1) (f) GDPR). Error reports are deleted automatically after 90 days.
10. Cookies
We use one technically necessary cookie to keep you signed in (session). This cookie is required to operate the login area; the legal basis is § 25 (2) TDDDG (German Telecommunications Digital Services Data Protection Act) as well as Art. 6 (1) (f) GDPR. We do not use tracking or marketing cookies.
11. Storage period
We store your data for as long as your account exists. You can delete your account yourself at any time in the settings; your personal data as well as the associated submissions, leaderboard and token data are deleted in the process, unless statutory retention obligations stand in the way.
12. Your rights
Within the statutory framework you have the following rights: access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) as well as objection to the processing (Art. 21 GDPR). You can withdraw a consent you have given at any time with effect for the future. A message to the contact details named above is enough to exercise these rights.
13. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD, the data protection authority of Schleswig-Holstein), Holstenstraße 98, 24103 Kiel.