privacy policy

Privacy policy

Last updated September 30, 2026

kodwai scores how well you direct an AI coding agent. To do that it needs your account, the code and agent transcript from the challenges you submit, and some usage data. This page says exactly what we collect, why, who sees it, and how to get it changed or deleted.

The short version: we only upload a challenge folder you submit, never your other work. We don’t sell data or train AI on your code. Leaderboards and profiles are public; your code and transcripts aren’t.

1. Who we are

kodwai (kodwai.com, app.kodwai.com and api.kodwai.com, plus the kodwai CLI and the kodwai plugin for Claude Code, Codex and Cursor) is run by Ege Hakan Karaağaç. We are the controller of the personal data described here, except in the hiring track, where we process candidate data for the company that invited them (see section 8).

Questions, requests and complaints: hakan@kodwai.com. A person reads every message.

2. What we collect

Your account.

  • Email address, name and username. Your password is stored only as a bcrypt hash.
  • If you sign in with GitHub: your GitHub id, login, name, email and avatar URL. We ask GitHub only for read:user and user:email, and we don’t keep your GitHub access token.
  • Whether you verified your email, and whether you ticked the optional box to get product news.

Your developer profile.

  • Anything you add: bio, GitHub, X, LinkedIn and website links, skills, your preferred agent.
  • Stats the platform computes: scores, rank, Direction rating, tier, level and XP, streak, skill ratings, badges, quests, league placement.
  • If you tell us on the welcome screen how you found kodwai: the source you picked and, optionally, what you asked an AI assistant (up to 500 characters).

Your challenge submissions. When you run kodwai submit, the CLI uploads, from that challenge folder only:

  • Your code files. It skips dependencies, build output, lockfiles, binaries, anything your .gitignore excludes, and secret files such as .env and private keys.
  • The git history since the starter commit: the diff and each commit’s hash, message and date (not your git name or email).
  • Test results from running the challenge’s tests on your machine.
  • The transcript of your AI agent session for that challenge (Claude Code, Codex or Cursor), from the time the challenge started, with each message cut to a fixed length. It also includes which agent and model you used and token counts.

The CLI shows you a summary and asks before it uploads. It doesn’t read other projects, conversations from before the challenge, or your credentials. The kodwai plugin only records which agent session belongs to a challenge (a session id and a file path, on your machine). It never uploads anything on its own.

Your Anthropic API key, if you add one. It is encrypted with AES-256-GCM before it’s stored, and we show you only its last 4 characters. When you add it, we make one tiny request to Anthropic to check it works.

Feedback you send us: platform feedback, challenge ratings and comments, and our replies.

Emails we send you: a log of which message went to which address, and whether it was delivered, bounced or marked as spam.

Usage data: pages viewed, clicks on key buttons (like copying a CLI command), sign-ups, logins, errors, browser and device type, and your IP address as it reaches our analytics and error tools (section 5).

3. How we use it, and why we’re allowed to

  • To run kodwai for you (performing our contract with you): your account, starting challenges, scoring submissions, leaderboards, leagues, badges, quests and your profile.
  • To score your runs: we send the challenge, your code, test results and the agent transcript to Anthropic’s API, which judges them against the rubric (section 5).
  • To send you email: account emails such as verification and password reset (contract); a short onboarding series and replies to your feedback (our legitimate interest in helping you get started, and you can unsubscribe); product news only if you opted in (consent).
  • To improve kodwai and keep it working: analytics and error reports (legitimate interests; for Google Analytics on kodwai.com, your consent).
  • To keep kodwai fair and safe: spotting abuse, cheating and banned accounts (legitimate interests).

We don’t sell your personal data, we don’t show ads, and we don’t use your code or transcripts to train AI models. We do use scores and scoring signals, combined across runs, to calibrate and improve how kodwai scores.

4. What other people can see

kodwai is a competition, so some of it is public by design:

  • Leaderboards and event boards: your name, username, preferred agent, streak, rating, tier and scores.
  • Your public profile at app.kodwai.com/developers/your-username: name, username, bio and links, ratings and tier, stats, badges, and your scored runs (challenge, score, agent, model, time). It doesn’t show your email. Profiles are marked so search engines don’t index them.
  • Your rank card image, if you or anyone embeds it: name, username, rating, tier, rank, solved count and streak.
  • Your weekly league is visible to the other developers in it, including your avatar.
  • Share links you create for a run: your score, its breakdown, agent and model, and the run’s highlight moments. A moment can quote a short line from the judge’s evidence, which may come from your transcript or code. Anyone with the link can open it.

Your code, full transcript, test output and email are never public.

5. Who we share it with

We use these providers to run kodwai. They process data for us under their own security and privacy terms:

  • Turso (database, hosted on AWS in Ireland, EU): everything described in section 2.
  • Railway (hosts our API) and Vercel (hosts kodwai.com and app.kodwai.com): the traffic that passes through them.
  • Anthropic (Claude API): the challenge, your code, test results and agent transcript, sent for scoring. If you added your own Anthropic key, the request is made with your key under your agreement with Anthropic.
  • Resend (email delivery, EU region): your email address, name and the email’s content.
  • PostHog (product analytics, US): usage events from both sites and our API. When you sign up or log in, we link events to your account id, email and name, so we can understand how people use kodwai.
  • Google Analytics (web analytics): page views on kodwai.com and app.kodwai.com.
  • Sentry (error monitoring, US): details of errors in our API, including the request and your IP address.
  • GitHub, only if you sign in with it.

We also use AI tools, including Anthropic’s Claude, to help us read and triage the feedback you send and draft replies. A person checks every reply before it goes out.

We’ll share data if the law requires it, or to protect kodwai and its users from fraud or abuse. If kodwai is ever sold or merged, your data would move with it, and we’d tell you first.

6. Cookies and local storage

  • kodwai.com remembers your cookie choice. Google Analytics stores its cookies only if you accept; otherwise it runs in a cookieless mode. PostHog analytics runs on the site and keeps an id in a first-party cookie and local storage.
  • app.kodwai.com keeps your sign-in token and small preferences (like dismissed banners) in your browser’s local storage. Google Analytics and PostHog run there too and set their own cookies.
  • The CLI keeps your sign-in token in ~/.kodwai/config.json on your computer (readable only by your user) and remembers that you accepted its data notice.

You can clear cookies and local storage in your browser at any time; you’ll be signed out of the app.

7. How long we keep it

  • Your account, profile and submissions: for as long as your account exists, until you delete a submission, or until you ask us to delete your account.
  • Sign-in tokens expire after 7 days; CLI sign-in codes after 10 minutes; password reset links after 1 hour.
  • Email delivery logs and feedback: as long as your account exists.
  • Analytics and error data: for the retention period set in PostHog, Google Analytics and Sentry.

When we delete your account, we remove it from our database within 30 days. Copies in our providers’ backups expire on their own schedules.

8. Hiring track: candidates and companies

When a company invites you to an interview session on kodwai, we process your name, email, the session’s code, file changes, agent activity and scores on that company’s behalf, to show them to the company. Your requests to Claude during the session go through kodwai using the company’s Anthropic key; we record the cost, not the request contents. The company decides how it uses your results, so ask them about their own policy. You can also write to us and we’ll pass your request on.

9. Your choices and rights

In the product, any time:

  • Edit your profile and username; change your password.
  • Delete any of your submissions (kodwai delete <id> or from the run’s page).
  • Remove your Anthropic key.
  • Unsubscribe from onboarding and product emails with the link in any of them. Account emails, such as password resets, still arrive.
  • Decline Google Analytics cookies on kodwai.com.

By email (hakan@kodwai.com): ask for a copy of your data, a correction (including your name or email), deletion of your whole account, or to object to or restrict how we use your data. We answer within 30 days.

If you’re in the EU, the UK or a country with similar laws, these are your rights under data protection law, and you can also complain to your local data protection authority. We’d appreciate the chance to fix it first.

10. International transfers

Our database and email provider are in the EU. Some providers (Anthropic, PostHog, Sentry, Google, Vercel and Railway) process data in the United States or elsewhere. Where the law requires it, these transfers rely on the providers’ standard contractual clauses or an equivalent safeguard.

11. Security

Everything travels over HTTPS. Passwords are hashed, and Anthropic API keys are encrypted before storage. The CLI leaves secret files out of submissions and keeps its token file private to your user. No system is perfectly secure: if you find a problem, please email hakan@kodwai.com. If a breach affects your data, we’ll tell you and the authorities as the law requires.

12. Children

kodwai is not for anyone under 16. Please don’t sign up if you’re younger. If we learn a child under 16 has an account, we’ll delete it.

13. Changes to this policy

When we change how we handle personal data, we’ll update this page and its date. For significant changes, we’ll also tell you by email or in the app before they take effect.