Privacy policy

Effective August 3, 2026 · Version 2026-08-03

Who is responsible

Code With Vibes is operated by Lupo Rosso LLC, a Texas limited liability company doing business as Code With Vibes, at 5900 Balcones Drive Ste 100, Austin, TX 78731, United States. We decide what gets collected here and why, which under GDPR and UK GDPR makes us the controller. For anything privacy-related we answer directly: privacy@codewithvibes.com.

This policy covers the marketing site, the free track, the paid course, your account, checkout, downloads, and the email we send you. It does not cover the AI providers and tools you connect to under your own accounts, which are between you and them.

What gets collected, and why

Account data. Your name, email, and sign-in identifiers, handled by our authentication provider, plus security events like sign-in attempts. We need it to give you an account at all, so the basis is performing our contract with you, and it lasts as long as your account does.

Purchase data. That you bought, what you bought, the amount, currency, billing country and address, refund and dispute status, and the Stripe identifiers that tie them together. Full card numbers go to Stripe and never reach us. We need this to deliver what you paid for and to keep the books, so the basis is our contract with you and our legal obligations, and the records are kept as long as tax and accounting law requires, which outlives your account.

Course data. Your progress, bookmarks, and settings, so the product works. Contract, and it lasts as long as your account.

Messages you send us. Support, refund requests, and privacy requests, with whatever you put in them. Kept while we deal with the request and for a reasonable period after, so we have a record of what was decided.

Product usage. Which pages and lessons get used, and first-party journey events tied to a random browser identifier. We use it to work out which parts of the course land and which do not, which is our legitimate interest in improving what we sell. Journey events and their identifiers are retained for up to one year, then deleted or aggregated.

Technical and diagnostic data. IP address, browser and device information, referring page, and error reports when something breaks. Servers and error monitoring receive this as an ordinary part of serving and debugging the site. Our legitimate interest in keeping the thing running and secure.

Marketing email. Only if you asked for it. Consent, withdrawable at any time, and we keep a suppression record after you unsubscribe so you stay unsubscribed.

None of it is used for ad targeting or cross-context behavioural advertising, and we do not sell, rent, or trade it. There is no automated decision-making that produces legal or similarly significant effects for you.

The services that run the plumbing

Clerk (authentication), Supabase (database and storage), Stripe (payments), Resend (transactional email), Sentry (error monitoring), PostHog (product analytics), Plausible (cookieless site analytics), and Vercel (hosting).

Most of them handle your information on our instructions. Some, payment providers in particular, also use limited information for their own fraud prevention, security, compliance, tax, and legal purposes, because the law requires it of them. Their own terms and privacy notices govern that part, and we cannot promise on their behalf.

Who else ever sees it

Professional advisers such as accountants and lawyers, bound by their own duties of confidence. Government bodies, courts, regulators, or law enforcement where we are legally compelled, and then only what is legally required. A successor if the business is sold, merged, or reorganised, under this same policy. We do not otherwise share your information with anyone for their own purposes.

Payments

Full payment card numbers are collected and processed by Stripe and are not stored by us. What we receive and store is the limited billing, transaction, payment status, refund, dispute, and tax information needed to complete and support a purchase, and it does reach our database, because that is how access gets granted and refunds get honoured.

Cookies and browser storage

Authentication cookies keep you signed in. They are functional and the site cannot work without them.

Two first-party analytics cookies carry random identifiers and no personal detail. cwv_anonymous_id connects page and course events from the same browser and lasts up to one year. cwv_session_id groups activity into a browser session and expires after 30 minutes of inactivity. Neither contains your name, email, search text, payment identifiers, or IP address. If you later sign in, activity from that browser can be linked to your account so we can understand the course funnel.

These analytics cookies are set when you arrive rather than after a consent prompt. Clearing cookies in your browser removes them and breaks the link, and your browser settings can block them outright. There are no ad pixels and no cross-site tracking. Full detail is on the cookie notice.

Analytics and error monitoring, specifically

PostHog runs with autocapture off, session recording off, no profiles for anonymous visitors, and the IP address dropped from stored events, so what it holds is the page and lesson events we send it deliberately. Plausible is cookieless and aggregate. Sentry records errors and diagnostics with session replay off. Query strings are scrubbed of identifiers before analytics sees them.

Your own AI providers

We do not host model inference. The exercises run against providers and local tools under your own accounts and on your own machine, and nothing in this product asks you for an API key, a prompt, a model output, or your source code. What you send a provider is governed by that provider's privacy terms, not this policy.

How long it is kept

We keep personal information only as long as it is reasonably needed for the purposes above: providing the service, keeping your access working, meeting tax and accounting obligations, preventing fraud, protecting security, resolving disputes, and holding evidence of what was agreed. The per-category periods are in the section above.

Deleting your account

You can delete your account from your account settings, or ask us at privacy@codewithvibes.com. Deleting it ends your course access, because access is tied to the account, and it is not the same thing as asking for a refund.

Deletion removes your profile, progress, bookmarks, settings, and analytics identifiers, and removes your identity from our authentication provider. Purchase and payment records are retained, because tax and accounting law requires it and because they are the evidence of what you bought. We also keep a minimal record that a deletion happened. Residual copies can persist in encrypted backups until those backups age out on their normal cycle.

Security

We use reasonable administrative, technical, and organisational safeguards designed to protect personal information: encrypted transport, limited access, row-level database policies keyed to your identity, and a dedicated authentication provider rather than something hand-rolled. No security measure or transmission method can guarantee absolute security. If a breach ever affects your data, you get notified as the law requires.

Your rights, and how to use them

Ask what we hold about you, ask for a copy in a portable form, ask for corrections, ask for deletion, object to or ask us to restrict processing we base on legitimate interests, or withdraw a consent you previously gave. Email privacy@codewithvibes.com. These are honored for everyone, not only where a statute forces it.

If you are signed in, your session verifies you. If you are not, we confirm control of the email address on the account before disclosing or deleting anything, and we will ask for no more than we need to do that. Never a government ID. We aim to respond within 30 days and will tell you if a request is genuinely complex and needs longer. If we refuse a request we will say why, and you can reply to that same address to appeal it, which a person reviews.

Exercising any of this never gets you worse service or a worse price. If you are covered by GDPR or UK GDPR you can also complain to your national data protection authority, and in the UK that is the Information Commissioner's Office. Texas residents may appeal a refused request to the Texas Attorney General. We are a US business with no establishment in the EU or UK and have not appointed a representative there.

Where it is processed

We operate from the United States and your information is processed there. Some of the services above operate globally and may process or store information in other countries. Where information moves out of the UK or the European Economic Area, we rely on the transfer terms in our agreements with those providers rather than on your consent, so withdrawing consent is not something you have to do to stop a transfer.

Children

Accounts and purchases are for adults 18 or older. The service is not directed to children and we do not knowingly collect their data. If you are a parent or guardian and believe a child created an account, email privacy@codewithvibes.com and it gets deleted.

Changes

If this policy changes, this page changes, with a new effective date and version at the top. Material changes get flagged plainly, not buried.

Contact

Privacy questions: privacy@codewithvibes.com. Legal entity: Lupo Rosso LLC d/b/a Code With Vibes, 5900 Balcones Drive Ste 100, Austin, TX 78731, United States.