PRIVACY POLICY FOR KODION
Effective Date: June 9, 2026 Last Updated: July 13, 2026
Introduction
This Privacy Policy ("Policy") explains how International Elevators Group Company I.L.C. SARL, a company organized under the laws of Lebanon (together with its successors and assigns, "Kodion," "we," "us," or "our"), collects, uses, discloses, and safeguards information in connection with the Kodion application and the website located at https://kodion.dev (collectively, the "Service").
We are the data controller responsible for your personal information, except where this Policy or applicable law states otherwise. By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not access or use the Service.
This Policy is incorporated into and subject to our Terms of Service. Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Information We Collect
We collect the following categories of information:
(a) Information you provide directly.
- Account registration data: email address and password (stored only in hashed form). If you sign in through a third-party provider, we receive the data described in Section 5.
- Profile and preferences: display name, username, avatar image, bio, language and learning preferences, and any other details you choose to add. Some of these fields may be visible to other users when you use our social features (see Section 4A).
- Social connections: friend requests you send or receive and the friend connections you form with other users.
- User-generated content: code, text, prompts, queries, exercises, submissions, and other content you create, upload, or submit when using the Service, including content you provide to our AI features (collectively, "User Content").
- Payment-related data: when you purchase a subscription, payment is processed by our third-party payment providers (see Section 15). We do not store your full card number or financial account credentials. We may receive limited transaction data such as subscription status, plan, billing country, the last four digits of a card, and transaction identifiers.
- Cryptocurrency payment data: if you pay with cryptocurrency (USDT), payment is processed by NOWPayments. We receive transaction identifiers, payment status, and amounts, and, if you request a refund, the wallet address you provide for that refund. We never receive or store your wallet's private keys.
- Support and communications: information you provide when you contact us, respond to surveys, or otherwise communicate with us.
(b) Information collected automatically.
- Device and technical data: device type, operating system and version, app version, browser type, language settings, time zone, and similar technical identifiers.
- Usage data: features used, pages or screens viewed, actions taken, session duration, learning progress, and interaction timestamps.
- Approximate location: we may infer approximate location (such as country or region) from your IP address. We do not collect precise GPS location.
- Log and diagnostic data: IP address, crash data, performance data, and error logs (see Section 8).
- Device fingerprinting / anti-fraud signals: we collect and derive device and environment signals (such as a hashed device identifier, configuration attributes, and related characteristics) to create a probabilistic device fingerprint. We use this solely to detect and prevent fraud, abuse of free trials, duplicate or fraudulent accounts, and security threats, as further described in Sections 2 and 3.
(c) Information from third parties.
- Authentication providers (see Section 5).
- Payment and subscription providers (transaction and subscription status).
- Analytics and crash-reporting providers (see Sections 6 and 8).
We do not intentionally collect special categories of personal data (such as health, biometric, racial, religious, or political data). Please do not submit such information through the Service, including through our AI features.
2. How We Use Information
We use information for the following purposes:
- To provide and operate the Service, including creating and managing your account, delivering lessons and AI-powered features, and saving your progress.
- To process transactions, manage subscriptions, free trials, renewals, and billing.
- To personalize your learning experience and content.
- To provide optional social and competitive features, such as friends, public profiles, leaderboards, weekly tournaments (leagues), and the friend activity feed, as described in Section 4A.
- To communicate with you, including service-related messages, security alerts, and (where permitted) product updates and marketing. You may opt out of marketing at any time.
- To maintain security and prevent fraud and abuse, including using device fingerprinting to detect duplicate accounts, trial abuse, automated activity, and other prohibited or unlawful conduct.
- To display and measure advertising that supports our free tier, as described in Section 6A. Paid plans do not show third-party advertising.
- To improve and develop the Service, including analytics, diagnostics, performance monitoring, and research, using aggregated or de-identified data wherever practicable.
- To comply with legal obligations, enforce our agreements, establish, exercise, or defend legal claims, and respond to lawful requests.
We do not use your private User Content or prompts to train our own or third parties' general-purpose AI models, except as described in Section 9.
3. Legal Bases for Processing (GDPR/UK GDPR)
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Creating and operating your account; providing the Service; processing payments | Performance of a contract (Art. 6(1)(b)) |
| Security, fraud and abuse prevention, device fingerprinting, service improvement, and analytics | Legitimate interests (Art. 6(1)(f)) — to keep the Service secure, functional, and improving, balanced against your rights |
| Marketing communications; non-essential cookies and similar technologies (including analytics and advertising) | Consent (Art. 6(1)(a)), where required |
| Retaining records; responding to legal requests; tax and accounting | Legal obligation (Art. 6(1)(c)) |
| Protecting vital interests or acting in the public interest, where applicable | Art. 6(1)(d)/(e) |
Where we rely on legitimate interests, you may object as described in Section 14. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
4. User Accounts
You must create an account to access certain features, including paid subscriptions. You agree to provide accurate information and to keep your credentials confidential. You are responsible for all activity under your account.
We reserve the right, at our sole discretion and to the extent permitted by law, to refuse, suspend, restrict, or terminate any account or access to the Service — with or without notice — where we reasonably believe there is fraud, abuse, a violation of our Terms, a security risk, unlawful activity, or a need to comply with legal or regulatory obligations. Termination of an account does not necessarily delete all associated data; see Sections 10 and 18.
4A. Social Features and Information Visible to Other Users
Kodion includes optional social and competitive features — friends, public profiles, leaderboards, weekly tournaments ("leagues"), and a friend activity feed. When you use these features, certain information becomes visible to other users of the Service:
- Public profile. Your username, display name, avatar image, level, total and weekly XP, learning streak, earned achievements/badges, and league history may be shown on your profile page and to other users.
- Leaderboards and tournaments. Your username, avatar, level, streak, and XP may appear on global and friends leaderboards and in weekly league standings, ranking you against other users.
- Friend connections. Other users can send you friend requests; if you accept, you become connected. Your accepted friends can see your profile and stats regardless of the visibility setting below.
- Activity feed. Notable milestones (such as leveling up, earning a badge, completing a course, reaching a streak, or a league promotion) may be shared with your friends through an activity feed. Hidden/surprise achievements are not shared.
- Search. Other users may find you by your username or display name in order to send a friend request.
Your visibility controls.
- Private profile. In Settings, you can mark your profile as private. When enabled, you are hidden from global and weekly leaderboards and your profile is not viewable by people who are not your friends. Your accepted friends can still see your profile and stats.
- A username is optional, but one is required for other users to find and add you.
- You can remove friends, decline requests, and delete your account at any time (see Sections 10 and 18).
We process this information to provide the social features you choose to use, on the basis of performance of a contract and our legitimate interests in offering an engaging, community-driven learning experience (see Section 3). Friend-activity entries and weekly leaderboard records are retained for a limited period and then automatically pruned; league history is retained to support the feature and removed after an extended period (see Section 10).
Please do not include information you wish to keep private in your username, display name, bio, or other profile fields, as these may be visible to other users.
5. Authentication and Login Providers
You may create or access your account using:
- Email and password, or
- Third-party sign-in providers — GitHub and Google, where enabled.
When you use a third-party sign-in provider, we receive certain information from that provider, which may include your name, email address, profile image, and a unique identifier, in accordance with the permissions you grant and that provider's privacy policy.
We do not receive or store your password for any third-party provider. Your use of these providers is governed by their own privacy policies, and we are not responsible for their practices.
6. Analytics
We use PostHog (PostHog EU Cloud, hosted in the European Union) as our product-analytics provider to understand how the Service is used and to improve it. PostHog may collect usage data, device data, and identifiers as described in Section 1. Analytics is loaded only after you give consent through our cookie banner, and analytics data is used in aggregated or de-identified form wherever practicable. You may withdraw consent or opt out at any time as described in Section 7.
6A. Advertising
The free tier of the Service is supported by advertising. We use Google AdSense to display advertisements to signed-in users on free plans within the application. Our public marketing, catalog, and article pages do not display third-party advertising, and paid plans remove third-party advertising entirely.
Google acts as an independent controller of the personal data it processes to serve and measure ads. When advertisements are displayed, Google and its certified advertising partners may use cookies, device identifiers, and similar technologies to serve ads, limit how often you see an ad, measure ad performance, and, depending on your settings and consent, personalize the ads you see. You can learn how Google uses this data at How Google uses information from sites or apps that use our services.
Consent. Where required by law (including in the EEA, the UK, and Switzerland), consent for the use of cookies and personal data for advertising purposes is collected through a Google-certified consent message before personalized ads are served. You can decline, choose non-personalized ads where offered, and change your choice at any time.
Your choices. You can opt out of personalized advertising through Google Ads Settings and www.aboutads.info/choices, and manage advertising cookies as described in our Cookie Policy. We honor the Global Privacy Control (GPC) browser signal as an opt-out where applicable law gives it that effect.
7. Cookies and Similar Technologies
On our website and within the Service, we and our service providers use cookies, local storage, SDKs, software development tokens, and similar technologies ("Cookies") to:
- enable essential functionality and security (strictly necessary);
- remember your preferences;
- measure and analyze usage (analytics); and
- serve and measure advertising on the free tier (advertising; see Section 6A).
Strictly necessary Cookies do not require consent. Where required by law (including in the EU/UK), we will request your consent for non-essential Cookies through a consent banner or settings control, and you may withdraw consent at any time. You can also control Cookies through your browser or device settings; disabling certain Cookies may impair functionality.
For details on the specific Cookies used, see our Cookie Policy.
8. Crash Reporting and Diagnostics
We do not currently use a dedicated third-party crash-reporting tool. Diagnostics are limited to server-side application logs held by our hosting provider (see Section 15), which may include technical data such as timestamps, request paths, IP addresses, and error messages. This data is used to maintain the stability and security of the Service and is processed on the basis of our legitimate interests. If we adopt a dedicated crash-reporting or diagnostics tool in the future, we will update this Policy and our Cookie Policy before doing so.
9. AI Features and User-Generated Content
The Service includes AI-powered features. To provide these features, content you submit — including prompts, code, text, and related inputs ("AI Inputs") — is transmitted to and processed by our third-party AI provider, Anthropic, PBC, which generates responses ("AI Outputs").
- Processing by Anthropic. AI Inputs and AI Outputs are processed by Anthropic under its applicable commercial terms and data-processing terms. Under Anthropic's commercial API terms, customer inputs and outputs are not used to train Anthropic's models by default.
- Our use. We may store AI Inputs and AI Outputs to provide the feature, maintain your history, ensure quality and safety, prevent abuse, and improve the Service. Where we use such content to improve the Service, we use de-identified or aggregated data wherever practicable.
- No model training on private content without a lawful basis. We do not sell your User Content, and we do not use your private User Content to train general-purpose AI models except where permitted by law and consistent with this Policy.
- Accuracy and reliance. AI Outputs are generated automatically and may be inaccurate, incomplete, or unsuitable for your purposes. You are solely responsible for evaluating AI Outputs before relying on them. AI Outputs do not constitute professional advice.
- Your responsibility for inputs. You must not submit unlawful content, the personal data of others without authorization, or sensitive or special-category data through AI features.
10. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, including for the duration of your account, and thereafter as required to:
- comply with legal, tax, accounting, and regulatory obligations;
- resolve disputes and enforce our agreements; and
- maintain security and prevent fraud (including retaining limited anti-fraud and device-fingerprint signals for a reasonable period).
When information is no longer needed, we will delete, anonymize, or aggregate it. Specific retention periods depend on the type of data and applicable legal requirements.
11. Data Security
We implement technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration, including encryption in transit, hashed password storage, access controls, and monitoring.
However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot and do not guarantee absolute security. You provide information at your own risk and are responsible for maintaining the confidentiality of your credentials. In the event of a personal-data breach, we will notify affected users and regulators where and as required by applicable law.
12. International Data Transfers
We operate globally, and your information may be transferred to, stored in, and processed in countries other than your own — including Lebanon, the United States, the European Union, and the locations of our service providers — which may have data-protection laws different from those in your jurisdiction.
Where we transfer personal data out of the EEA, UK, or other regions with transfer restrictions, we implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement/Addendum, or other lawful transfer mechanisms. You may request a copy of the relevant safeguards using the contact details in Section 20.
13. Children's Privacy
The Service is intended for users who are at least 13 years old. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
In jurisdictions where the minimum age for digital consent is higher than 13 (for example, up to 16 in parts of the European Union), users below that local age threshold may use the Service only with the consent of a parent or legal guardian, and we rely on you to obtain such consent where required.
If you believe a child under the applicable minimum age has provided us with personal information, please contact us (Section 20), and we will take reasonable steps to delete it.
14. Your Privacy Rights
14.1 EEA / UK (GDPR) Rights
Subject to applicable law, you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing (including processing based on legitimate interests and direct marketing); data portability; and withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.
14.2 California (CCPA/CPRA) Rights
If you are a California resident, you have the right to: know/access the categories and specific pieces of personal information collected; delete personal information; correct inaccurate information; opt out of the "sale" or "sharing" of personal information; and limit the use of sensitive personal information. You will not be discriminated against for exercising these rights.
We do not "sell" your personal information for money. However, when third-party advertising is active on the free tier (Section 6A), the disclosure of identifiers and internet-activity data to our advertising partner may constitute "sharing" for cross-context behavioral advertising as defined under the CPRA. You can opt out of such sharing at any time: use the cookie and advertising controls described in Sections 6A and 7, enable the Global Privacy Control (GPC) signal in your browser (which we honor as an opt-out), or contact us using the details in Section 20. We do not knowingly sell or share the personal information of consumers under 16 years of age. The categories of personal information we collect, the sources, purposes, and disclosures are described in Sections 1, 2, and 15.
14.3 Other U.S. State Rights
Residents of states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah, Texas, and others) may have rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of certain processing. We honor these rights as required by applicable law.
14.4 How to Exercise Your Rights
To exercise any right, contact us using the details in Section 20. We will verify your identity before fulfilling your request and will respond within the timeframes required by law. You may use an authorized agent where permitted. These rights are subject to legal exceptions and limitations.
15. Third-Party Services
The Service relies on third-party service providers acting as processors or independent controllers, which may include:
- Authentication (optional sign-in providers): GitHub, Inc. and Google LLC
- AI processing: Anthropic, PBC
- Payments (web): Paddle (Merchant of Record)
- Payments (cryptocurrency): NOWPayments (USDT payment processing; Kodion is the seller of record)
- Payments (mobile): not currently offered — if mobile subscriptions launch, they will be billed through Apple In-App Purchase / Google Play Billing and this Policy will be updated
- Advertising: Google LLC (Google AdSense; free tier, in-app only; Google acts as an independent controller; see Section 6A)
- Hosting and infrastructure: Vercel, Inc. (application hosting and edge network) and Neon, Inc. (PostgreSQL database hosting, EU region)
- Analytics: PostHog, Inc. (PostHog EU Cloud — loaded only after consent)
- Crash reporting: none currently used (see Section 8)
- Email: Resend, Inc. (transactional email — verification, password reset, and account messages)
- Push notifications: none — notifications are delivered in-app only
- Security and anti-abuse: Cloudflare, Inc. (Turnstile bot protection) and Upstash, Inc. (rate limiting)
Each third-party service is governed by its own privacy policy and terms. We are not responsible for the privacy practices, content, or security of third-party services, websites, or applications, including those linked from the Service. Your interactions with third parties are solely between you and the relevant third party. We encourage you to review their policies before using them.
16. Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or other corporate transaction — including the planned transfer of the Service to a newly formed entity — your information may be transferred as part of that transaction. We will ensure any successor remains bound by commitments consistent with this Policy or will notify you of any material changes as required by law.
17. Law Enforcement and Legal Requests
We may access, preserve, and disclose your information to law enforcement, government authorities, courts, or other third parties where we reasonably believe doing so is necessary to: comply with applicable law, regulation, legal process, or an enforceable governmental request; enforce our Terms; detect, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of Kodion, our users, or the public. Where legally permitted, we will use reasonable efforts to notify affected users.
18. Data Deletion Requests
You may request deletion of your account and associated personal information at any time by:
- using the in-app/website account deletion control, where available; or
- contacting us at privacy@kodion.dev.
Upon a verified request, we will delete or anonymize your personal information, except information we are required or permitted to retain for legal, tax, security, fraud-prevention, or legitimate-business purposes as described in Section 10. Deletion may take a reasonable period to propagate across our systems and backups. Note that content you shared publicly or with third parties may persist outside our control.
You can delete your account directly in the app at any time: Settings → Danger Zone → Delete Account (https://kodion.dev/settings).
19. Changes to This Policy
We may modify this Policy from time to time to reflect changes in our practices, technology, legal requirements, or the transition of the Service to a new operating entity. When we make material changes, we will update the "Last Updated" date and provide notice through the Service or by other reasonable means as required by law. Your continued use of the Service after the effective date of the revised Policy constitutes acceptance of the changes, to the extent permitted by law. We encourage you to review this Policy periodically.
We also reserve the right to modify, suspend, or discontinue any part of the Service at any time, with or without notice, to the extent permitted by law.
20. Contact Information
For questions, requests, or complaints regarding this Policy or your personal information, contact us at:
International Elevators Group Company I.L.C. SARL Attn: Privacy Bonjus Street, Fanar Lebanon Email: privacy@kodion.dev