Privacy Policy

Last updated: August 13, 2026

This policy explains what CodeTrain collects and how we use it.

Who we are

CodeTrain is operated by InferHaven LLC, a limited liability company registered in the State of Michigan, United States, trading as InferHaven. InferHaven LLC is the data controller for the personal data described here.

Postal address: InferHaven LLC, PO Box 145, Bessemer, MI 49911, United States.
Privacy contact: privacy@codetrain.ai. We do not operate a public phone line, and email is the fastest way to reach a person.

This policy is governed by the laws of the State of Michigan, United States. If you live somewhere with its own mandatory data protection law, such as the UK, the EU or California, that law still applies to you and nothing here limits the rights it gives you.

Where your code goes depends on how you use CodeTrain.
  • Free skill & the codetrain agent (local): your source code stays on your machine. Only the small prompt snippets needed for a tutoring turn are sent through our model proxy to the AI provider, or on bring-your-own-key straight from your machine to the provider, never touching our servers. We don't copy or store your repository.
  • Managed in-browser tutor: the code you submit for review and any files you attach as context are sent to our servers and on to the AI model provider, and stored in your lesson session so you can resume it and see your history. Python and JavaScript you type run in your browser; bash and PHP run in an ephemeral, network-isolated sandbox on our infrastructure.

We don't use your code or lessons to train AI models, and we only use model providers under arrangements that don't train on your prompts.

What we collect

What we do with it

To operate and secure the Service, enforce plan limits, process payments, provide support, and improve the product. We do not use your code, prompts, or lessons to train AI models, and we do not sell your personal data.

AI processing & code execution

By default your turns use Anthropic's Claude (Haiku/Sonnet) models, sent directly to Anthropic's API. If you choose one of the optional experimental models, your prompt is instead routed through our model gateway (OpenRouter) to that model's provider (for example OpenAI, Alibaba/Qwen, Z.ai, or Moonshot); the picker flags these. In every case we use arrangements that don't train on your prompts. When a lesson runs bash or PHP, your code executes in a short-lived, network-isolated container on our sandbox host and is deleted right after.

Email we send you

Some email is operational and you cannot opt out of it while you have an account: sign-in and security messages, team invitations, billing receipts, and notices about material changes to this policy or the Terms.

We may also send occasional product email to the address on your account, such as a note about a feature you have not tried or an offer. Every one of these carries an unsubscribe link and supports one-click unsubscribe in your mail client, and opting out is permanent unless you ask us to resume. Opting out of product email never affects the operational messages above or your use of the Service. We do not sell or rent your address, and we do not send you other companies' advertising. Our mailing address is PO Box 145, Bessemer, MI 49911.

Service providers

We share the minimum necessary with: Clerk (authentication), Stripe (payments), Anthropic (the default Claude models), OpenRouter (model gateway for the optional experimental models) and the providers it routes to for those (e.g. OpenAI, Google, Alibaba/Qwen, Z.ai, or Moonshot), Cloudflare (web hosting/CDN/DNS), Fly.io (API hosting), Neon (database), Oracle Cloud (the sandbox host that runs bash/PHP lessons), and Sentry (error monitoring). Each processes data under its own terms.

Cookies

We use essential cookies for authentication/session management (via Clerk). We don't use advertising trackers.

Data retention

How long each category is kept. "Life of account" means until you delete the account or ask us to.

DataKept for
Account record
(email, name)
Life of account.
Lesson history
and submitted code
Life of account, so you can resume a lesson and review what you did. Removed when the account is deleted.
Usage and meteringRetained after account deletion where we need it for accounting and tax records, with the personal identifiers removed.
Billing recordsHeld by Stripe under its own retention schedule. We store only a customer and subscription reference.
Error reportsHeld by Sentry under its retention schedule. These carry operational metadata only, never prompts, model replies or your code. See how that is enforced.
Sandbox executionNot retained. Bash and PHP run in a container that is destroyed straight after the run.
Database backupsEncrypted dumps taken twice daily and kept for 7 days, then deleted. Our database provider additionally holds a 6 hour point-in-time window. Deleted data can persist in a backup until it ages out of both.
Email suppressionIf you unsubscribe we keep that record indefinitely, including after account deletion. It exists so we cannot email you again by mistake, and deleting it would undo the thing you asked for.

Deleting your account

You can do it yourself, immediately, from Plan & billing in your account dashboard. It takes effect at once rather than entering a queue.

What is erased: your lesson history and every piece of code and writing inside it, your saved concepts and revision schedule, your profile, feedback you submitted, your API tokens and linked devices, and the identifying fields on your account record, including your name and email address.

What survives, and why: usage totals stay, because they are our accounting records, but they are detached from any identifying information and cannot be traced back to you. A one-way hash of your email address is kept so the same address cannot be used to open a new free account, which is the control that stops the free tier being reset by deleting and re-registering. If you later want to come back, email support@codetrain.ai.

Backups are not rewritten, so a copy can persist until the backup it sits in ages out on the schedule above. If you would rather we handled it, privacy@codetrain.ai still works.

Your rights

Depending on where you live (e.g. GDPR/UK GDPR, CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Email us to exercise them.

Security

We use encryption in transit, scoped access tokens, and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data. The engineering detail, including which files we refuse to read and what our error monitoring is not allowed to collect, is on the security page.

Children

The Service isn't directed to children under 16, and we don't knowingly collect their data.

Changes

We'll post updates here with a new date. Material changes may also be notified by email.

Contact

Privacy questions or data requests: privacy@codetrain.ai.