Account and Authentication Data
Codartt stores account data such as email address, username, email verification status, legal consent records, and account status. Password authentication is handled through Supabase Auth.
If you use Google sign-in, Codartt may receive your Google email and basic profile information needed to create or log into your account. Codartt does not use Google sign-in to access Gmail, Drive, Contacts, Calendar, or private Google files.
Public Profile and Content Data
Public data may include username, avatar, bio, location, website, Discord handle, public contact email if provided, public creator page, public post pages, images, titles, descriptions, tags, discipline, project type, tools, role, captions, and post metadata.
If you choose to add a public contact email, it may be displayed on your public profile and public post pages so other users can contact you outside Codartt. You can remove it at any time from your profile settings.
Posts require admin review before publication. Public post and creator pages may be indexed by search engines, linked by other users, previewed in social contexts, cached, or copied by third parties outside Codartt control.
Media and Upload Data
Codartt stores image upload data needed to operate the platform, including object keys, file type, file size, CDN URLs, upload confirmation metadata, cover selections, crop outputs, and image records.
Codartt V1 supports JPEG, PNG, and WebP image uploads up to 20MB. SVG and video uploads are not supported.
Interaction and Personalization Data
Codartt stores likes, saves, follows, views, post opens, profile opens, creator follows, Discord-copy events, onboarding category interests, interest weights, notifications, and strong user events used for discovery and personalization.
These signals help operate the feed, search, saved posts, following surfaces, creator discovery, notifications, and recommendation features. They do not add marketplace, payment, job, messaging, or public role behavior.
Spotlight Boost and Promotion Data
If Spotlight Boosts are used or attempted, Codartt may store structured promotion records such as post and owner relationships, local promotion reference, package type, promotion status, price, currency, immutable activation window, bounded payment processor identifiers, payment status, timestamps, aggregate service metrics, eligibility or moderation history where relevant, policy version, bounded support records, and refund, reversal, or dispute state.
Financial records exclude raw PayPal responses and webhook material, credentials or tokens, payer funding details, full billing or shipping addresses, unrelated user information, IP addresses, user agents, unrestricted exports, and a permanent evidence-file archive unless a later approved process lawfully requires otherwise.
Codartt may store aggregate promotion analytics counters such as promoted impressions and post opens or clicks. Promoted impressions count times served in Discover, not unique viewers.
The Spotlight Boost MVP uses aggregate promotion counters and does not provide boost owners with viewer identity analytics.
Moderation, Reports, and Admin Data
Codartt stores reports, report reasons, optional report details, moderation notices, warnings, suspensions, bans, deleted-content records, admin actions, editorial labels, showcase labels, and platform logs.
These records may be retained to protect users, investigate abuse, enforce the Terms and Community Guidelines, preserve audit trails, support legal compliance, and prevent repeated misuse.
Session, Security, and Cookie Data
Codartt uses authentication, Supabase session, signed app session, admin session, CSRF/admin security, OAuth, PKCE, temporary legal-consent, and rate-limit data to operate and protect the platform.
Technical data may include IP address, user agent, request metadata, security signals, and logs. Codartt currently uses essential/auth/security/platform cookies only and does not use advertising cookies.
Where Data Is Processed
Codartt uses providers such as Supabase, Cloudflare R2/CDN, Railway, Upstash Redis when configured, Google OAuth, Zoho or Supabase SMTP, PayPal as the designated payment processor when Spotlight Boost checkout is enabled, and DNS, infrastructure, security, and compliance providers.
Data may be processed in countries where Codartt and its providers operate. Provider locations and legal requirements may vary.
Access, Correction, and Portability
You can access and update supported profile fields, privacy settings, notification settings, Discord handle, public contact email, and posts through Codartt product flows. You can also contact support@codartt.com for access, correction, portability, restriction, objection, deletion, consent withdrawal, or related privacy help.
Codartt may need to verify your account before completing a request and may decline or limit a request where permitted or required by law, safety, security, abuse-prevention, or audit obligations.
Deletion and What May Remain
Users can delete their own posts through supported flows and can request account deletion through settings. Account deletion removes or disconnects supported account and public content data according to Codartt product behavior.
Some information may remain after deletion, including backups, CDN caches, search engine caches, security logs, rate-limit records, legal consent records, moderation and ban records, reports involving other users, admin logs, and transaction, refund, reversal, dispute, and audit records needed for accounting, legal compliance, legal holds, fraud prevention, dispute handling, or platform safety.
Codartt cannot guarantee immediate deletion from every backup, cache, search index, public preview, or third-party copy.
Retention
Account data is generally retained while the account exists. Public content remains until deleted, removed, or the account is deleted. Security, rate-limit, report, moderation, ban, legal consent, and audit records may be retained longer where needed.
If anonymized or aggregated analytics are added later, they may be retained without identifying individual users where permitted.
Security Measures
Codartt uses measures intended to protect the platform, including signed httpOnly sessions, secure cookie settings, upload validation, rate limiting, admin access controls, moderation logs, and separation between public user accounts and internal admin accounts.
No service can guarantee perfect security. Keep your login credentials secure and contact support@codartt.com if you believe your account has been compromised.
Changes
Codartt may update this Data Handling & User Rights page as the platform, law, or provider relationships change.
Contact
Questions or requests can be sent to support@codartt.com. Visit the Support page for contact details and policy links.