Who runs the site
Code Dock is a one-person project: a developer's workshop where things get built, documented and shared. The person who runs it decides what is stored and why, and is the one you contact about your data.
This policy covers the public site, member accounts and the content management area used by the small team that writes for the site.
What we store
You can read every story and playbook without an account. Nothing below is collected about you until you create an account, except the cookies and on-device storage described at the end of this section.
Account details: your name, your email address and, if you add one, your avatar image. Your password is never stored; only a one-way hash of it is. We keep these to sign you in and to address the emails you ask for.
Sessions: each time you sign in, we record the session with a description of your device (the browser and operating system it reports) and its IP address. You can see these sessions, and end any of them, on your account's Security page. A session lasts 7 days, renewed while you use it.
Learning progress and saved items: when you are signed in, the steps you have completed in each playbook and the stories and playbooks you have saved are kept with your account, so they follow you between devices.
Audit records: sign-ins, failed sign-in attempts, account changes and editorial actions are written to an audit log, so that misuse can be investigated and changes can be traced. Each record keeps the IP address and browser it came from, and the name and email address of the account as they were at the time.
Short-lived security records: one-time links for verifying an email address (valid 1 hour), resetting a password (valid 1 hour) and confirming a new email address (valid 1 hour), and rate-limit counters keyed by your IP address or account, which only count requests over the last few minutes.
Cookies: the sign-in session cookie (strictly necessary; it holds your session, not your password), with a copy of the session details that lasts 1 minute so pages load without an extra database read. If you untick "Remember me", the session cookie ends when you close the browser. Two small flags support your synced library: cd_member hints that this device belongs to a signed-in member, so the site knows a sync is worth trying (kept 30 days); cd_signed_out records that you signed out, so the device's copy of your library is cleared on the next page load (kept 1 day). Neither contains your name or email address.
On-device storage: your browser keeps your light or dark theme choice (under "theme"), your playbook progress (codedock.progress.v1), your saved items (codedock.saved.v1) and, while you are signed in, a list of changes waiting to sync (codedock.sync.v1). This storage stays on your device; it is sent to us only to sync your library while you are signed in. Signing out clears the library keys from the device.
We do not use advertising cookies, analytics cookies, tracking pixels or third-party trackers.
Who processes it
Three services process data on the site's behalf. Each acts only on our instructions and keeps its own operational logs under its own policy.
Vercel hosts the site and stores uploaded files, including avatar images. Every page request passes through Vercel, which sees your IP address and browser details.
Neon hosts the database that holds accounts, sessions, synced learning, the audit log and the site's own analytics counts.
Resend delivers the site's emails: verification links, password resets, email-change confirmations and account notices. It receives your email address and the message.
How long it's kept
Account details, synced learning progress and saved items are kept until you delete your account. Deleting it removes them at once.
Sessions end after 7 days without use, when you sign out, or when you end them from the Security page. A one-time link stops working once it is used or expires.
When you replace or remove your avatar, or delete your account, the old image is deleted from storage within a day or two.
Audit records are kept for security and accountability. Each one keeps the IP address, browser, name and email address recorded when it was written, and it outlives an account deletion: deleting your account does not delete its audit records. They stay in the live log for 90 days, then move to monthly archive files that are kept with no expiry. Only the site's team can read them, as far as their role allows.
Your choices
You can change your name, email address and avatar on your account's Profile page, and end sessions on the Security page.
You can delete your account yourself from the Security page. It takes effect immediately and cannot be undone: your account details, sessions, synced progress and saved items are removed, and a notice is sent to your email address. Team accounts must first ask an Admin to change their role to Member.
To get a copy of the data held about you, or to ask any question about it, send a request by email to the address in the Contact section. You will get a reply by email.
Your data is not sold, rented or shared for advertising, and it is not used for advertising.
Analytics
The site counts how it is read, by itself and in aggregate, to learn what to write next. There is no third-party analytics service: the counts are kept in the same database as everything else (see Who processes it), and no new service is involved.
What is counted: page views per day and per page; which stories, playbooks, topics and collections are read; which other sites send readers (their name only, never the page) and campaign tags in a link (utm_source, utm_medium, utm_campaign); what readers search for, whether the search found anything, and which result was opened; how far into a story readers get (a quarter, half, three quarters, the end); how many readers start a playbook, reach each step and finish it; which linked resources (GitHub, notebooks, documentation) readers follow; and how fast pages load and respond on real devices.
What is never counted or kept: who you are, your account, your IP address, your browser's full details, your location, the addresses of pages that don't exist, or anything that follows you to other sites. Nothing is stored on your device for analytics: no cookie, no local storage, no identifier. Searches and campaign tags that look like an email address, a phone number or a long number are counted without their words.
How visitors are counted: to estimate how many people visited in a day without an identifier, the server combines your IP address and browser details with a random value that changes every day, and keeps only the one-way result, separately for each page. The IP address and browser details are used for that moment only and never stored (they are also used, the same way, to limit how many measurements one device can send). The daily random value is deleted at most 30 hours after its day ends, so the results can't be linked across days or back to you; the results themselves are deleted within 49 hours. The database provider's point-in-time recovery may hold deleted data for its own short restore window.
How long it's kept: daily counts for 13 months (so a month can be compared with the same month a year earlier); search queries for 90 days. Older counts are deleted automatically every day. Only Admins and Editors can see the counts, and nothing about readers is ever shown on the public site.
Your choices: if your browser sends Global Privacy Control or Do Not Track, nothing is counted at all. Blocking scripts or using an ad blocker also means nothing is counted, and the site works the same. Because nothing that needs consent is collected, there is no consent banner. Members of the site's team are never counted.
Changes to this policy
When this policy changes, the new version is published on this page and the "Last updated" date changes.
Contact
Questions, a copy of your data, or a correction: Write to hello@code-dock.dev. A person reads every message.