// legal

Privacy Policy

Last updated · May 2026

What we collect

  • Account: your email address, managed through Clerk.
  • Billing: card and customer data, handled by Stripe. We never see your full card number.
  • Lab activity: which labs you opened, code you submitted to the grader, and the grader's test/benchmark results.
  • Session: a signed cookie that ties anonymous-trial activity to your account once you sign up.
  • Operational logs: request metadata (IP, user agent, timestamps) for security, abuse prevention, and rate limiting.

Why we collect it

  • Run the labs and grade your submissions.
  • Bill paid subscriptions and process refunds.
  • Prevent abuse (rate limiting, capacity caps).
  • Improve labs based on aggregated, anonymized usage patterns.

Who we share it with

We use a small set of trusted infrastructure providers. Each processes data only to deliver the Service to you:
  • Clerk — authentication and account management.
  • Stripe — payments and billing.
  • E2B — short-lived Linux microVM sandboxes that execute your lab code.
  • Vercel — application hosting and CDN.
  • Upstash — Redis used for per-user rate limiting.
  • Neon / managed Postgres — durable storage for user and subscription state.
We don't sell your data, and we don't share it with advertisers.

Cookies

We use two cookies:
  • A Clerk-issued auth cookie once you sign in.
  • An HMAC-signed anonymous session cookie for unauthenticated trial users, so we can rate-limit per visitor.
No third-party advertising trackers.

Retention

We keep account and subscription data while your account is active. If you delete your account, we delete personally identifiable information within thirty days, retaining only billing records and tax-relevant invoices for the period required by law.

Your rights

You can request export or deletion of your data at any time by emailing hello@crackedswe.io. If you live in the EU, UK, or California, you have rights under GDPR / UK GDPR / CCPA respectively; we honor those regardless of your location.

Security

All traffic is HTTPS. Secrets live in server-side environment variables; we never expose API keys to the browser. Code you submit is executed in isolated microVMs that are destroyed at the end of each grading run.

Children

The Service is not directed at children under 13, and we don't knowingly collect data from them.

Changes

We'll update this page if our practices change and post the new effective date at the top.

Contact

Questions? Email hello@crackedswe.io.