Legal

Privacy Policy

Written for the adult who owns the account first, with a short summary a young builder can read. It says what CodeDreams collects, why, who can see it, how long we keep it, and what you can do about it.

Effective August 17, 2026

1. Parent and kid summary

For young builders: use a nickname, not your full name. Never type your address, school, phone number, passwords, or secrets into a prompt, a message, a comment, a leaderboard, or an app. Publishing makes an app visible to other people. If you are in a class, your teachers can open your class projects and see how your lessons are going. Ask the adult who owns the account before you publish anything.

For parents and guardians: you can review projects, turn publishing and community features off, clear leaderboards, unpublish or delete projects, cancel billing, and delete the account. CodeDreams does not sell personal information, does not show ads, and does not train its own AI on what kids make.

For teachers and schools:a class you run gives you and your co-teachers access to your students' class projects, lesson progress, assignments, and messages. You are responsible for having your school's and parents' permission to use CodeDreams with your students.

Filters, access controls, rate limits, and human review reduce risk. None of them can catch every unsafe input or guarantee that every AI output or public interaction is appropriate. Adult supervision still matters.

2. Who this covers

This policy applies to codedreams.org, the CodeDreams builder at app.codedreams.org, published apps on codedreams.org subdomains, the AI and Learn tools, classes, Explore, cloud leaderboards, subscriptions, and support (together, the Service). “CodeDreams,” “we,” and “us” mean the operator of the Service.

The person who registers is the account holder. There are two kinds of account. A student account builds its own projects and can join a class with an invite code. A teacher account runs classes and can see the work of the students in them. Both are created with an email address and password or with Google sign-in, and both ask which grade the builder is in so the AI can talk at the right level.

A child under 13 does not own an account. At home, a parent or legal guardian creates and owns the account and supervises its use. At school, a teacher creates the class and the school authorizes the use on parents' behalf (see section 5). Explore can be viewed without an account.

3. What we collect

  • Account: email address, display name, password (stored only as a hash) or Google sign-in identifiers, grade level, account type (student or teacher), any pilot or promotion code entered, and sign-in, reset, and onboarding events. We do not ask for a date of birth, a real name, or a photo.
  • Builder content: prompts, chat messages, project names and language (JavaScript or Python), code and files, images you upload as project assets, sounds chosen from our library, version history, settings, preview screenshots, build output, error logs, sandbox state, and publish history.
  • Learning and class data: lesson progress, answers to lesson checks and exercises, how long lessons take, class memberships and the invite codes used to join, assignments, submissions, grades and feedback entered by teachers, messages between a student and their teaching team (including any project attached to a message), and roster details such as display name, last active time, and project counts.
  • Public and community content: published app titles, descriptions, web addresses, preview images, and author display names; comments, likes, and reports; moderation records; leaderboard nicknames and scores; and play counts.
  • Technical and safety:IP address, browser and device details, timestamps, request and security events, feature usage, deployment identifiers, abuse signals, and keyed digests of network addresses. A keyed digest lets us tell that two requests came from the same place, to slow leaderboard manipulation and to count each visitor's play once, without storing the address itself in that record.
  • Analytics: Google Analytics runs on both codedreams.org and app.codedreams.org. See section 9 for exactly what it collects and how to opt out.
  • Billing: plan, billing interval, free or paid status, class seat counts, renewal and cancellation dates, promotion details, Stripe customer and subscription identifiers, invoices, purchase-order and billing-address details for schools billed by invoice, and billing audit events. Stripe, not CodeDreams, handles card numbers and payment credentials.
  • Support: anything you send us by email, including attachments.

4. How we use it

  • to create, sign in, secure, and support accounts;
  • to generate and edit projects, run sandboxes and previews, save versions, publish apps, and teach lessons grounded in the account holder's own code;
  • to run classes: rosters, assignments, grading, teacher access to student work, and messages between students and teachers;
  • to provide Explore, comments, likes, reports, moderation, leaderboards, and play counts;
  • to screen prompts, generated code, and public text, enforce limits, investigate abuse, protect children and other users, and respond to reports;
  • to run subscriptions, seat billing, invoices, taxes, cancellations, refunds, and entitlements;
  • to debug, maintain, measure, and improve the Service; and
  • to comply with law, resolve disputes, and protect the rights and safety of users, CodeDreams, and others.

Where the law requires a legal basis, we rely on performing our contract with you, consent (including a parent's or school's authorization where required), legal obligations, and our legitimate interests in providing, securing, and improving the Service. We never use personal information for advertising and never sell it.

5. Children under 13

At home:a parent or legal guardian creates and owns the account, accepts these policies, confirms the email address, and supervises the child. A paid checkout by that adult is further evidence of their authorization. The parent can review the child's projects and public activity, stop further collection by stopping use, unpublish or delete projects, clear leaderboards, and delete the account.

At school:a teacher who invites students into a class confirms that their school has authorized CodeDreams for those students and has obtained any parental permission the school requires. In that setting the school acts on parents' behalf, and we use student information only to provide the Service to the school and never for any commercial purpose of our own. Parents can ask the school, or us, to see or delete their child's information.

We ask for no more than the feature needs and do not condition a child's use on giving us more. If we learn that we hold a child's information without the required authorization, we will restrict the account and delete the information or obtain valid permission. Tell us right away if you believe this has happened.

6. Classes and teachers

A class is run by an owner teacher and up to two co-teachers. Every teacher on the class can see the roster, open and edit any project built inside the class as if it were their own, read each student's lesson progress and pace, set and grade assignments, and message any student. Messages are private threads between one student and the class's teaching team; students do not see each other's threads. Students can see their teachers' names and their classmates' display names, but never their emails.

Projects a student builds inside a class belong to the class workspace. If a teacher removes a student from the roster, that student's class projects are deleted with the seat; personal projects outside the class are untouched. If a student leaves on their own, their class projects stay attached to their account and reappear if they rejoin. When a class ends or its subscription lapses, class projects are unpublished and kept as drafts.

Grades and feedback live inside the class and are visible to the student and the teaching team. CodeDreams is not a system of record for a school; export anything you need before deleting a class.

7. AI and sandboxes

When you build, chat, ask for a lesson, or hit an error, we send the prompt, relevant conversation history, the relevant project files, selected logs, and technical context to our AI model provider, currently OpenAI, through its business API. Under those API terms the provider does not use our inputs or outputs to train its models and may keep them for a short period for abuse monitoring. Your project also runs in an isolated cloud sandbox and, when published, on hosting infrastructure; both are operated by our infrastructure providers on our behalf.

Automated systems scan prompts, generated code, and public text before it is saved or published. People at CodeDreams may look at limited content when needed for support, safety, security, or legal reasons. We do not train our own models on builder content and do not use it for advertising. This is still a good reason for young builders never to put real names, personal details, or secrets in a prompt or a project.

8. Publishing, Explore, and leaderboards

Publishing is optional and puts the app at a codedreams.org web address anyone can open. Public apps can be copied, linked, indexed, embedded, or screenshotted by others. An app can be public in Explore or unlisted; unlisted means it is not listed or indexed by us, not that it is private from anyone with the link. The owner decides whether comments and likes are on.

Comments, likes, display names, leaderboard nicknames and scores, and play counts are visible to other people. Public text is screened, and may be blocked, held for review, hidden, or removed. Anyone can report a comment; reports and moderation records are not public. Leaderboard entries carry only a nickname and a score. Unpublishing or deleting removes what we control; it cannot recall copies already made by other people, browsers, search engines, or archives.

9. Analytics and cookies

We use Google Analytics on both codedreams.org and app.codedreams.org so we can see how people find CodeDreams and where they get stuck. It sets cookies (such as _ga) and collects pages visited, approximate location, device and browser details, and referral source. When an account is created or a plan is bought, we also send those events to Google Analytics from our server, tagged with the account's internal ID so the two halves of the same visit line up. That ID is an opaque string, never an email address, and no builder content, project data, or student work is ever sent to Google Analytics.

We do not use analytics for advertising, do not run third-party ad or retargeting tags, and do not sell or share analytics data for behavioural advertising. To opt out, block cookies for our sites in your browser, use a content blocker, or install Google's Analytics opt-out extension; the Service works the same without it. Aside from analytics, we set only the cookies needed to keep you signed in and to protect forms.

10. Payments

Stripe provides checkout, card handling, recurring billing, invoices, taxes, fraud prevention, and the billing portal, and receives billing and payment details directly. We receive the identifiers and status we need to attach a subscription to an account or class and enforce the plan. Schools billed by purchase order share billing contact and address details with us and Stripe so an invoice can be issued.

We keep payment and subscription records to run the subscription, prevent unauthorized purchases by children, handle support and refunds, keep accounts, and document parental or school authorization.

11. Who we share with

We share only what is reasonably necessary, and never for advertising:

  • Providers working for us: database, authentication, and file storage (Supabase); hosting, sandboxes, and published-app deployment (Vercel); payments (Stripe); AI models (OpenAI); analytics and optional sign-in (Google); and email delivery, logging, and security services. Each is bound to use the information only to provide its service to us.
  • The public, when the account holder publishes or posts;
  • Teachers and schools, for students in their classes as described in section 6, and parents or guardians entitled to control an account;
  • Authorities and others when required by law or reasonably necessary to prevent harm, investigate abuse or fraud, enforce agreements, or protect rights; and
  • A successor in a financing, merger, acquisition, reorganization, or sale, under confidentiality and this policy.

We do not sell personal information or share it for cross-context behavioural advertising. If that ever changed, we would update this policy and obtain any consent required for children first.

12. How long we keep it

  • Accounts and projects: while the account exists. Deleting a project removes its files, versions, sandbox, and published copy from our live systems. Deleting the account removes the profile, owned projects, files, published apps, and deployments; a class subscription the account paid for passes to a remaining co-teacher rather than being cancelled.
  • Class data: class projects are deleted when a teacher removes the student or deletes the class; grades, submissions, and messages go with the class.
  • Leaderboards: until the owner clears the board, resets its key, deletes the project, or we remove entries for safety.
  • Comments: until deleted by the author or owner, or removed by moderation.
  • Play-count records: the per-visitor digest used to count a play once is deleted after 24 hours; only the total is kept.
  • Operational logs: builder activity events for 90 days, usage events for 180 days, payment-event records for 90 days, then deleted.
  • Billing, tax, fraud, safety-report, and legal records: for as long as required by law or reasonably necessary, restricted from ordinary product use.

Provider backups and caches clear on their normal rotation schedules. When a purpose ends, we delete, de-identify, or isolate the information. We do not keep children's personal information indefinitely.

13. Your rights and controls

In the product you can change your display name, grade, and password; decide whether to publish and whether comments and likes are on; clear or reset a leaderboard; unpublish or delete projects; leave a class; manage or cancel billing; and delete the account. Parents can do all of this for a child using their account. Teachers can remove students, delete classes, and manage seats.

Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to processing of your information, to receive a portable copy, to withdraw consent, to appeal a decision, and to complain to a privacy regulator. California residents may ask what categories and specific pieces of personal information we hold and to whom they were disclosed. We do not sell or share personal information for behavioural advertising, so there is no sale or share opt-out to exercise.

Send requests to support@codedreams.org. We verify that you control the account before disclosing or deleting anything, and we never penalize anyone for exercising a privacy right.

14. Security and where data lives

We use measures designed for the sensitivity of the information: row-level database authorization, restricted service credentials, content and code screening, database constraints, rate limits, audit records, encrypted transport, isolated sandboxes, payment-provider isolation, and incident response. No internet service can promise perfect security; if a breach affects you, we will notify you as the law requires.

CodeDreams operates from Canada, and our providers process information in Canada, the United States, and other countries where they operate. Where the law requires it, we use recognized transfer safeguards.

15. Changes

We will update this policy as the Service or the law changes and post the new effective date here. For a material change, especially one involving children's information, we will give additional notice or seek renewed consent where required.

16. Contact

Privacy, parent, school, deletion, or safety requests: support@codedreams.org. Ask for the Privacy Lead. Legal operator and mailing details are available from support for formal notices.

Please also read the Terms of Service and the Refund & Cancellation Policy.