Today's Code (Codelog)
Effective date: April 16, 2026

Article 1 (Purpose of This Privacy Policy)
Today's Code (the "Service") values users' personal information and complies with the Personal Information Protection Act and related laws. This policy explains the items of personal information the Service collects, its purposes of use, retention periods, and users' rights.

Article 2 (Items of Personal Information Collected and Collection Methods)

1. Registration and Authentication (GitHub OAuth)
When logging in with a GitHub account, the following information is collected: GitHub username (required), profile image URL (required), email address (required), public repository information (required, for analysis purposes), GitHub access token (required, stored encrypted on-device).
GitHub access token scopes requested: read:user, user:email, public_repo, read:org

2. Information Generated While Using the Service
Career path and experience level (entered directly), preferred tech stack (entered directly), technical competency score (automatically generated through GitHub analysis), learning roadmap and quiz history (recorded automatically), learning streak, XP, and badges (gamification data, recorded automatically), team recruitment posts and application history (entered directly).

3. Collection Methods
Automatic collection through GitHub OAuth authentication; information entered directly by the user within the Service; information automatically generated while using the Service.

Article 3 (Purposes of Processing Personal Information)
Member identification and authentication management; analysis of public GitHub repositories and technical competency assessment (source code itself is not stored); generating personalized learning roadmaps and quizzes; providing the AI mentor Q&A service; managing learning status and growth history; providing team recruitment/networking features.

Article 4 (Retention and Use Period of Personal Information)
Member profile and technical competency data, learning roadmap/quiz/history data, team posts and application history: until account withdrawal.
GitHub access token: stored encrypted on-device, deleted upon withdrawal.
Upon account withdrawal, all of the above data is deleted immediately. However, where retention is required by applicable law, information is kept for the legally mandated period before destruction.

Article 5 (Provision of Personal Information to Third Parties)
The Service does not, in principle, provide users' personal information to external parties. However, the following processing is outsourced to operate the Service.
- Supabase Inc.: user authentication, database storage and management (retention period: until account withdrawal)
- GitHub Inc.: OAuth authentication, public repository lookup (retention period: until OAuth session expiry)
- Groq Inc.: AI analysis and content generation, server-side processing (retention period: discarded immediately after processing the AI request)
When processed by Groq AI, GitHub analysis data and learning context are transmitted for analysis purposes, but are not stored on Groq's servers after processing is complete.

Article 6 (Destruction of Personal Information)
The Service destroys personal information without delay once the retention period has elapsed or the processing purpose has been achieved. Electronic files are permanently deleted using methods that prevent recovery. Upon account withdrawal, the profile, learning roadmap, quiz history, analysis history, team posts, application history, and the authenticated account itself are all deleted.

Article 7 (User Rights and How to Exercise Them)
Viewing personal information: available on the in-app profile screen. Correcting personal information: use the in-app profile editing feature. Account withdrawal and deletion of personal information: processed immediately via App Settings → Delete Account. Requests to suspend processing: contact the Data Protection Officer below.

Article 8 (Measures to Ensure the Security of Personal Information)
GitHub access tokens are stored encrypted on-device via Android Keystore / iOS Keychain. All communication is encrypted via HTTPS/TLS. Supabase RLS (Row Level Security) ensures each user can access only their own data. AI API keys are kept only on the server and are never included in the client app. Only public GitHub data is accessed; private repositories cannot be accessed.

Article 9 (Special Notes on GitHub Data Processing)
Only public repositories are analyzed; private repositories are not accessed. The original repository source code is not stored on the server — after AI analysis it is converted and stored only as score data. Only metadata such as repository name, language, topics, and statistics is used for analysis.

Article 10 (Cookies and Advertising)
The Service does not use advertising networks (such as AdMob), and does not use cookies or SDKs for behavioral tracking or advertising purposes.

Article 11 (Protection of Children's Personal Information)
The Service is not directed at children under 14, and users under 14 may not register. If it is confirmed that personal information of a child under 14 has been collected, it will be deleted immediately.

Article 12 (Data Protection Officer)
Email: service.help@outlook.kr
Inquiries regarding personal information, and requests to view, correct, delete, or suspend processing, will be answered within 3 business days when sent to the email above.

Article 13 (Changes to This Privacy Policy)
This policy may be revised due to changes in law or service policy. Changes will be announced in-app or by email 7 days in advance; material changes will be announced 30 days in advance.

This privacy policy is effective as of April 16, 2026.