Privacy Policy
This policy explains what CtrlDogma collects, why, who we share it with, and what control you have over it. It applies to ctrldogma.com and every part of the service.
Information you give us
- Account details — your email address and a username. Authentication is handled by Supabase Auth; your password is stored and verified by Supabase and is never visible to us.
- Profile details you choose to add — name, country, institution, a short bio, gender, phone number, and GitHub/LinkedIn handles. All of these are optional; the account works without them.
- Code you write — every submission, along with the problem, language, verdict and timestamp.
Information we generate
- Progress data — solved problems, track completions, CD Score, activity dates, and when you were last active.
- Integrity signals — a one-way hash of submitted code and automated checks that detect hardcoded answers or attempts to probe hidden test data. These exist to keep the leaderboard and certificates meaningful.
- Subscription and payment records — which plan you bought, when, the amount, and the Razorpay order/payment reference.
Payments — we never see your card details
Payments are processed by Razorpay. Card numbers, UPI PINs, CVVs and net-banking credentials are collected by Razorpay's own secure checkout and never reach CtrlDogma's servers. We store only the order reference, payment reference, amount, and status — enough to prove a payment happened and to process a refund, and nothing more.
Code execution
To run and grade your code, we send the code and its test input to a sandboxed execution engine. We use a self-hosted engine for most runs, and third-party engines (Judge0, JDoodle) as fallbacks when it is unavailable. Only the code and the input are sent — never your name, email or account identifier.
GitHub Sync (optional)
If you connect GitHub Sync, we store an access token so we can push your
accepted solutions to your own repository. That token is
encrypted at rest and is never displayed anywhere in the
site or its admin interface. We request the narrowest scope that works
(public_repo) — enough to create and write to your solutions
repository, and nothing else. You can disconnect at any time from your
profile, and revoking access on GitHub's side also works immediately. Files
already pushed stay in your repository — they're yours.
What is public
Some information is public by design, so you can share your progress:
- Your public profile page at a unique link — showing your username, any profile details you filled in, your stats, activity, and certificates you've claimed.
- The leaderboard, showing your username and score. You can remove yourself from it at any time from your profile settings.
- Certificates you claim — each has a public verification page showing your display name and the track completed. That is the point of a certificate: someone else has to be able to check it.
Your email address, phone number and payment records are never shown publicly.
Cookies and analytics
We use essential cookies to keep you signed in and to protect forms against cross-site request forgery. Your theme preference (light/dark) is stored in your browser, not on our servers.
We use PostHog for product analytics — which pages and features get used, so we know what to improve. This sets analytics cookies and records your account identifier against those events. We do not use advertising cookies, and we do not sell data to anyone.
IP addresses
We use your IP address transiently to rate-limit sign-in and checkout attempts, which protects accounts against password guessing and payment fraud. These are held briefly in a short-lived cache and are not stored in our database.
Who we share data with
We do not sell your data and we do not share it for advertising. It is shared only with the integrated services CtrlDogma needs in order to run — such as authentication, hosting, payment processing, code execution and analytics — and in each case only to the extent that service needs to do its job. We may also disclose information where required by law.
How long we keep it
Account and progress data is kept while your account exists. Payment and subscription records are kept even after a subscription ends, because we need them for accounting, tax and dispute-resolution purposes. If you delete your account, we remove your personal data but may retain minimal transaction records where the law requires it.
Your choices and rights
- Update — edit your profile at any time from your account settings.
- Hide from the leaderboard — a single toggle in your profile.
- Disconnect GitHub Sync — one click, at any time.
- Access or delete your data — email us and we'll action it. Deletion removes your account, submissions and profile.
Note that deleting your account does not retract certificates you already shared publicly, or remove files already pushed to your own GitHub repository — both live outside our control by then.
Security
The site is served over HTTPS. GitHub access tokens are encrypted at rest. Passwords are handled entirely by Supabase Auth and never stored by us. No system is perfectly secure, but we take reasonable measures and fix problems promptly when they're found.
Children
CtrlDogma is not directed at children under 13, and we don't knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with an updated date at the top of this page.
Contact
Questions about this policy, or to request access or deletion of your data: support@ctrldogma.com. See also our Contact page.