Privacy Policy
Last Updated: October 1, 2025
Your privacy matters. This Privacy Policy explains how 42codes collects, uses, protects, and shares your personal information. We believe in transparency and giving you control over your data.
Quick summary: We collect minimal data to provide our service, never sell your information, and give you full control to export or delete your data anytime.
1. Information We Collect
Account Information
When you create an account via Google OAuth, we collect:
- Name (first and last)
- Email address
- Google account ID (for authentication)
- Account creation date
Note: We do not store passwords. Authentication is handled securely through Google OAuth.
Assessment Data
When you take our career assessments, we store:
- Your responses to assessment questions
- Calculated scores and career blueprint results
- Completion timestamps
- Progress through the assessment
Usage Information
To improve our service, we automatically collect:
- Pages you visit on our site
- Features you use
- Time spent on the platform
- Device type and browser information
- IP address and general location (city/country level)
- Referral source (e.g., link you clicked) and UTM parameters (if present)
Payment Information
When you purchase a subscription:
- Payment details are processed by our secure payment partner
- We do not store your credit card numbers
- We receive confirmation of payment status only
2. How We Use Your Information
To Provide Our Service
- Create and manage your account
- Process your assessment responses and generate results
- Save your career blueprint and progress
- Send assessment results and recommendations
To Communicate With You
- Send account-related emails (login confirmations, updates)
- Notify you of new features and updates (if you opt in)
- Respond to your support requests
- Send important service announcements
To Improve 42codes
- Analyze usage patterns to enhance features
- Fix bugs and technical issues
- Develop new career assessment methodologies
- Understand which careers are most popular
To Ensure Security
- Detect and prevent fraud
- Protect against unauthorized access
- Enforce our Terms of Service
3. Information We Do NOT Collect
We respect your privacy. We do not:
- Store passwords (we use Google OAuth for secure authentication)
- Track you across other websites
- Collect sensitive personal data (race, religion, health, etc.)
- Require your phone number or physical address
- Access your contacts or other apps
- Use facial recognition or biometric data
4. How We Share Your Information
We never sell your personal data. Period.
We only share your information in these limited circumstances:
With Service Providers
We work with trusted partners who help us operate 42codes:
- Authentication: Google OAuth (secure login)
- Hosting: Linode (cloud infrastructure)
- CDN: Cloudflare (content delivery and security)
- Payments: Polar.sh (subscription processing)
- Email: MailerSend (transactional and marketing emails)
These partners are bound by confidentiality agreements and can only use your data to provide services to us.
For Legal Reasons
We may disclose information if required by law or to:
- Comply with legal processes (subpoenas, court orders)
- Protect our rights and property
- Prevent fraud or security threats
- Protect user safety
Business Transfers
If 42codes is acquired or merged, your information may be transferred to the new owner. We'll notify you before this happens.
With Your Consent
We'll ask your permission before sharing your data for any other purpose.
5. Cookies and Tracking
We use cookies (small text files) to:
- Keep you logged in
- Remember your preferences
- Understand how you use our site
Types of Cookies We Use
- Essential: Required for the site to function (login sessions)
- Functional: Remember your settings and choices
- Analytics: First-party analytics events (no third-party ad tracking) that help us improve the user experience
You can control cookies through your browser settings, but disabling essential cookies may limit functionality.
6. Data Security
We take security seriously and implement industry-standard protections:
- Encrypted connections (HTTPS/TLS)
- Google OAuth authentication (no passwords stored)
- Secure cloud infrastructure
- Regular security audits
- Limited employee access to data
However: No system is 100% secure. While we do our best to protect your data, we cannot guarantee absolute security.
7. Your Privacy Rights
Access Your Data
You can view all your account information and assessment results in your profile dashboard.
Export Your Data
Download your assessment results as PDF or CSV (available soon).
Update Your Information
Edit your account details anytime through your profile settings.
Delete Your Account
Request account deletion through your settings. We'll permanently delete your data within 30 days, except:
- Financial records (kept for 7 years per legal requirements)
- Anonymized usage statistics
Opt Out of Marketing
Unsubscribe from promotional emails using the link at the bottom of any marketing email, or update preferences in your account settings.
Additional Rights (GDPR/CCPA)
If you're in the EU, California, or other covered jurisdictions, you have additional rights:
- Request a copy of all data we hold about you
- Correct inaccurate information
- Object to certain data processing
- Restrict how we use your data
- Data portability (receive your data in a standard format)
To exercise these rights, email [email protected]
8. Data Retention
We keep your information for as long as your account is active. After deletion:
- Assessment data: Deleted within 30 days
- Account information: Deleted within 30 days
- Backup copies: Removed within 90 days
- Financial records: Retained for 7 years (legal requirement)
- Anonymized analytics: Retained indefinitely (cannot identify you)
9. Children's Privacy
42codes is not intended for children under 16. We do not knowingly collect information from users under 16.
If we discover that a child under 16 has created an account, we will delete it immediately. Parents who believe their child has provided us with information should contact [email protected]
10. International Data Transfers
42codes is based in the United States. If you access our service from outside the US, your information may be transferred to, stored, and processed in the United States.
We comply with applicable data protection laws and use standard contractual clauses for international transfers.
11. Third-Party Links
Our site may link to external websites (career resources, articles, etc.). This Privacy Policy does not apply to third-party sites. We're not responsible for their privacy practices.
12. Changes to This Policy
We may update this Privacy Policy as our service evolves or laws change. Significant changes will be announced via:
- Email to registered users
- Notice on our homepage
- In-app notification
We'll update the "Last Updated" date at the top. Continued use after changes means you accept the updated policy.
13. Contact Us About Privacy
Questions, concerns, or requests about your privacy?
- Email: [email protected]
We'll respond to privacy requests within 30 days.