Codartt

Legal

Privacy Policy

This Privacy Policy explains how Codartt collects, uses, shares, stores, and protects personal data when you use Codartt.

Last updated: 2026-07-22

Who We Are

Codartt is an online showcase and discovery platform for Roblox and game developers to publish image-based creative work, browse, like, save, follow, search, report, and manage public creator profiles.

Questions or privacy requests can be sent to support@codartt.com.

Information We Collect

Account data includes email address, username, email verification status, legal consent records, and authentication data. Password authentication is handled through Supabase Auth. If you use Google sign-in, Codartt may receive your Google account email and basic profile information needed to create or log into your account.

Profile and content data includes avatar, bio, location, website URL, Discord handle if provided, public contact email if provided, post titles, descriptions, official categories or disciplines, tags, captions, project metadata, image uploads, cover selections, and media information such as object keys, file type, size, URLs, and upload confirmation metadata.

Interaction and personalization data includes likes, saves, follows, post opens, views, profile opens, creator follows, Discord-copy events, onboarding interests, interest weights, notifications, and related recommendation signals. Codartt uses Discord-copy events to understand creator intent; the event does not need to store the copied Discord handle itself.

If you purchase or attempt to purchase a Spotlight Boost, Codartt may process structured transaction information such as the local promotion reference, selected package, amount and currency, promotion status, bounded payment processor identifiers, purchase and provider timestamps, original service window, payment status, aggregate service metrics, eligibility or moderation history where relevant, policy version, bounded support records, and related refund, reversal, or dispute state. When checkout is enabled, payment information will be handled by PayPal.

Codartt financial records do not store full card or PayPal account credentials, payer funding details, full billing or shipping addresses, OAuth material, raw PayPal responses, raw webhook bodies or headers, IP addresses, user agents, or an unrestricted dispute-evidence archive.

Spotlight Boost analytics may include aggregate promoted impressions and post opens or clicks. The current Spotlight Boost analytics design does not expose viewer identity analytics to boost owners.

Safety and operations data includes reports, report reasons and details, moderation notices, warnings, suspensions, bans, admin actions, editorial or showcase labels, platform logs, IP address, user agent, session data, security signals, rate-limit signals, CSRF/admin protection signals, and temporary OAuth, PKCE, or legal-consent cookies.

Communications data may include messages you send to Codartt support, account emails, verification emails, password reset emails, and other service communications.

How We Use Information

We use information to create accounts, verify email addresses, provide Google sign-in and signup, manage sessions, record legal consent, secure accounts, operate settings, and support login, logout, password reset, and account deletion flows.

We use profile, post, media, and interaction data to publish creator profiles and posts, review posts before publication, deliver notifications, support search and discovery, personalize feeds, preserve saved and followed content, and generate public previews or SEO metadata for public pages.

We use promotion records, payment-status information, and aggregate promotion analytics to prepare, operate, measure, support, audit, and enforce Spotlight Boosts and related platform policies.

We use reports, moderation data, logs, rate-limit data, admin actions, and security signals to protect users, prevent abuse, enforce the Terms of Service and Community Guidelines, investigate safety issues, comply with legal obligations, and operate Codartt reliably.

Google Sign-In

Google sign-in is used only to authenticate users and support account creation or login. Codartt may receive your Google email address and basic profile information needed for those purposes.

Codartt does not use Google sign-in to access Gmail, Google Drive, Contacts, Calendar, or private Google files unless a future feature separately asks for consent. Codartt does not sell Google user data and uses Google sign-in data only for account operation, authentication, and security.

Public Visibility

Codartt is a public showcase platform. Public usernames, creator profiles, avatars, bios, locations, websites, Discord handles, public contact emails if provided, public posts, images, tags, disciplines, project metadata, post pages, and creator pages may be visible to other users and search engines.

If you choose to add a public contact email, it may be displayed on your public profile and public post pages so other users can contact you outside Codartt. You can remove it at any time from your profile settings.

If you provide a Discord handle, other users may copy it and contact you outside Codartt. Codartt does not control external Discord communications or off-platform interactions.

Do not upload sensitive, confidential, regulated, or private information. Codartt is designed for public creative portfolio content.

Cookies

Codartt currently uses essential cookies and similar storage for authentication, Supabase auth sessions, signed app sessions, admin sessions, security, CSRF/admin protection, rate limiting, temporary OAuth and PKCE flows, temporary Google signup legal consent, and platform operation.

Codartt does not currently use advertising cookies. If non-essential analytics, advertising cookies, or similar tracking are added later, this policy may be updated and consent may be requested where required.

Sharing and Providers

Codartt uses service providers to operate the platform, including Supabase for authentication and database services, Cloudflare R2 and CDN services for media storage and delivery, Railway for hosting, Upstash Redis for rate limiting when configured, Google OAuth for sign-in, Zoho or Supabase SMTP for account emails, and PayPal as the designated payment processor when Spotlight Boost checkout is enabled.

We may also use DNS, security, infrastructure, legal, compliance, and safety providers where needed. We may disclose information if required by law, to protect users or the platform, to investigate abuse, or to enforce our legal terms.

Codartt does not sell personal data. Public content is intentionally visible as part of the platform and may be shared, linked, cached, or indexed according to the public nature of Codartt and your settings.

International Processing

Codartt uses providers that may process data in places where they operate. Depending on where you use Codartt and where providers operate, your information may be transferred to and processed in other jurisdictions.

Data protection rules vary by country. Codartt applies appropriate safeguards for its service relationships and handles user requests according to applicable law.

Retention and Deletion

Account data is generally retained while your account exists. Public content remains available until deleted, removed through moderation, or your account is deleted through supported account deletion flows.

Security logs, rate-limit data, reports, moderation records, ban records, admin logs, legal consent records, transaction records, refund and dispute state, and audit records may be retained longer where needed for safety, fraud prevention, accounting, legal compliance, dispute handling, legal holds, and platform integrity. Banned email records may be retained to prevent repeated abuse.

A deletion or privacy request does not automatically erase records that Codartt must preserve for a current payment review, dispute, chargeback, fraud investigation, accounting obligation, legal hold, or non-excludable legal duty.

Backups, search engine caches, CDN caches, public previews, and copies created by third parties may persist temporarily or outside Codartt control. Codartt does not promise immediate deletion from every backup, cache, or external index.

Your Rights and Choices

You can access and update supported account, profile, privacy, notification, Discord handle, public contact email, and post information through Codartt settings and product flows. You can delete your own posts and request account deletion through settings.

Depending on where you live, you may have rights to access, correct, delete, restrict, port, object to processing, withdraw consent, or complain to a data protection authority. These rights may depend on your jurisdiction and may be subject to legal, safety, security, and audit exceptions.

To make a privacy request, contact support@codartt.com. Codartt may need to verify your account before fulfilling a request.

Children and Minors

Codartt is not intended for children under 13 or for anyone below the minimum age required by local law. If you are under the age of majority where you live, you should use Codartt only with permission from a parent or guardian.

If a parent or guardian believes a child provided personal data to Codartt, contact support@codartt.com so we can review and take appropriate action.

Security

Codartt uses reasonable technical and organizational measures intended to protect the platform, including signed httpOnly sessions, secure cookie settings, rate limiting, upload validation, admin access controls, moderation logs, and restricted admin surfaces.

No online service can guarantee perfect security. You are responsible for keeping your account credentials secure and telling Codartt if you believe your account has been compromised.

Changes

Codartt may update this Privacy Policy as the platform, law, or provider relationships change. Material updates may be communicated through the site, email, or other appropriate means.

Contact

Questions or requests can be sent to support@codartt.com. Visit the Support page for contact details and policy links.