Privacy Policy
Last updated: July 11, 2026
Effective date: July 11, 2026
Apex Path ("we", "us", "our", "the Service") is operated by Rafael Badalov, an individual based in the Republic of Azerbaijan ("Operator"). This Privacy Policy explains what information we collect when you use Apex Path — through our mobile applications (Android via Google Play, iOS if applicable) or through our web application at apexpaths.com and related subdomains — how we use it, when we share it, and what rights you have over it.
By creating an account or using Apex Path, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
1. Who We Are and How to Contact Us
For all privacy-related requests, including access, correction, deletion, or portability of your personal data, contact us at:
Email: [email protected]
Country of operation: Republic of Azerbaijan
Data controller: Rafael Badalov (individual)
We aim to respond to all lawful requests within 30 days.
2. Information We Collect
2.1 Information You Provide Directly
- Account information. When you register, we collect your email address, chosen username, and password (stored hashed with bcrypt — we never see or store your plaintext password). If you register via Google or GitHub OAuth, we receive your email address, display name, and public profile identifier from the provider.
- Profile settings. Theme preference, timezone, preferred difficulty level, and any settings you choose.
- Onboarding responses. Answers to the initial assessment questions or the skill level you self-select if you skip the assessment.
- User-generated content. Code you write and submit for exercises, capstone project steps, or draft snippets; friend requests you send; messages in battle/raid chats (if applicable).
- Communications. If you email us for support, we retain the correspondence.
2.2 Information Collected Automatically
- Usage data. Skill progress, XP earned, streak length, sessions completed (focus and quick-solve), exercises attempted and their outcomes, project step submissions, badges earned.
- Device information. Device model, operating system version, application version, screen dimensions, locale, and (for push notifications) Expo push tokens or web push subscription tokens.
- Network information. IP address (used for rate limiting and abuse prevention), approximate location derived from IP, request timestamps.
- Diagnostic data. Crash reports, error logs, and performance metrics used to fix bugs.
- Cookies and similar technologies. On the web application, we use httpOnly cookies to keep you signed in and to remember your preferences. We do not use third-party advertising cookies. See Section 11 for details.
2.3 Information from Third-Party Services
- OAuth providers (Google, GitHub). If you sign in with Google or GitHub, they share your email, name, and profile identifier with us.
- GitHub integration (optional). If you connect a GitHub App installation to Apex Path, we receive repository metadata and commit information for the repositories you grant access to, so we can award XP for real coding activity. You can revoke this access at any time from your GitHub settings.
- Billing providers.
- Mobile subscriptions are processed by Apple App Store or Google Play; we receive purchase confirmation and subscription status from RevenueCat, our subscription management provider.
- Web subscriptions are processed by Paddle (Paddle.com Market Limited), acting as the Merchant of Record; we receive customer identifier, subscription state, and payment status from Paddle. We do not see or store your card number.
3. How We Use Your Information
We process your personal data for the following purposes:
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the Service — running your account, saving progress, verifying exercises, delivering lessons | Performance of a contract |
| Enabling social features — friends, activity feed, battles, raids | Performance of a contract |
| Processing subscriptions and billing | Performance of a contract |
| Sending transactional emails (password reset, email verification, subscription receipts) | Performance of a contract |
| Sending push notifications for gameplay events (raids, friend requests, streak reminders) | Consent — you can disable them in device settings |
| Fixing bugs, monitoring service performance, preventing abuse | Legitimate interest |
| Complying with legal obligations (tax, accounting, law-enforcement requests) | Legal obligation |
| Product improvement (analyzing aggregate usage patterns to decide what to build) | Legitimate interest |
| Marketing communications (only if you opted in) | Consent |
We do not sell your personal information. We do not use your submitted code, lesson activity, or profile information to train machine-learning models beyond providing AI-powered code review specifically for your submission (see Section 4.6).
4. Third Parties That Process Your Data
We rely on the following service providers ("processors") to run the Service. Each of them processes personal data only under our instructions and is bound by data-processing agreements.
| Provider | Purpose | Data shared |
|---|---|---|
| Railway (Railway Corp., USA) | Backend hosting, PostgreSQL database, Redis cache, background jobs | All personal data stored in our backend |
| Cloudflare (Cloudflare Inc., USA) | CDN, DNS, DDoS protection, TLS termination | IP address, request metadata |
| Netlify or Vercel (Netlify Inc. / Vercel Inc., USA) | Web application hosting | Request metadata, cookies |
| RevenueCat (RevenueCat Inc., USA) | Mobile subscription management | Email, subscription identifier |
| Paddle (Paddle.com Market Limited, UK) | Web billing (Merchant of Record), tax handling | Email, name, billing address, purchase details |
| Google (Google LLC, USA) | OAuth sign-in, Google Play delivery, push notifications on Android via FCM | OAuth identifiers, push tokens |
| GitHub (GitHub Inc., USA) | OAuth sign-in, GitHub App integration | OAuth identifiers, repository access as granted |
| Resend (Resend Inc., USA) | Transactional email delivery | Email address, message content |
| Expo (Exponent, Inc., USA) | Push notification delivery for the mobile app | Device push tokens |
| Piston (Engineer Man, community-maintained) | Sandboxed code execution for the "Run" feature | Submitted code snippet only |
| Sentry (Functional Software Inc., USA) | Crash reporting and error tracking | Error stack traces, may include IP address and user identifier |
| Anthropic and/or OpenAI (Anthropic PBC / OpenAI OpCo LLC, USA) | AI code review generation | Code snippet, exercise metadata; no persistent training use |
We do not otherwise share your personal information with third parties, except:
- With your explicit consent
- To comply with legal obligations or valid legal process
- To protect the rights, property, or safety of Apex Path, our users, or the public
- In connection with a merger, acquisition, or asset sale, in which case we will notify you before your data is transferred
5. International Data Transfers
Most of our processors are based in the United States. Where personal data of users in the European Economic Area, United Kingdom, or Switzerland is transferred outside those regions, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or another lawful transfer mechanism.
6. Data Retention
- Account data is retained for as long as you have an active account, and for up to 30 days after account deletion to allow undo and comply with legitimate business or legal requirements.
- Billing records are retained for 7 years to comply with tax and accounting obligations.
- Crash and error logs are retained for 90 days.
- Anonymized, aggregated usage statistics may be retained indefinitely.
You can permanently delete your account at any time from within the app (Profile → Delete Account) or by emailing us. Deletion removes all personally identifiable information; anonymized aggregate metrics that cannot be traced back to you may be retained.
7. Your Rights
Depending on your location, you may have the following rights over your personal data:
- Access. Request a copy of the personal data we hold about you.
- Rectification. Correct inaccurate or incomplete data.
- Deletion ("right to be forgotten"). Have your data deleted, subject to legitimate business or legal exceptions.
- Restriction of processing. Ask us to pause processing under certain circumstances.
- Portability. Receive your data in a structured, machine-readable format.
- Objection. Object to processing based on our legitimate interests.
- Withdrawal of consent. Withdraw consent for any processing that relies on it (e.g. marketing emails, push notifications).
- Complaint. Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email us at [email protected]. We do not charge for these requests.
California residents (CCPA / CPRA). You have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of your personal information (we do not sell or share it in the statutory sense). You may authorize an agent to submit requests on your behalf.
8. Children
Apex Path is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13 in the United States or under the applicable minimum age of digital consent in other jurisdictions (16 in most EU member states). If you are a parent or guardian and become aware that your child has provided us with personal information without your consent, please contact us at [email protected] and we will delete the information.
Users between the applicable minimum age and 18 may use the Service with the consent of a parent or legal guardian.
9. Security
We use industry-standard measures to protect your data, including:
- TLS 1.2+ encryption for all data in transit
- Encryption at rest for our PostgreSQL database
- Passwords hashed with bcrypt (salted, 10 rounds)
- Rate limiting and abuse-prevention throttling
- Role-based access control on administrative interfaces
- Regular dependency updates and security patching
No system is perfectly secure. If we become aware of a security breach that affects your personal information, we will notify you and the relevant supervisory authority as required by applicable law.
10. Automated Decision-Making
We do not use fully automated decision-making that produces legal or similarly significant effects on you. The AI-generated code review is advisory only and is presented to you for consideration; you are always free to disagree or ignore it.
11. Cookies and Similar Technologies
The web application uses cookies for the following purposes:
- Strictly necessary cookies. Session and authentication cookies (httpOnly, secure, SameSite=Lax or Strict). These cannot be disabled.
- Preference cookies. Theme (dark/light), difficulty preference, dismissed banners. Stored in localStorage on your device.
- Analytics cookies. We may use privacy-respecting analytics (such as PostHog with anonymized identifiers). We do not use advertising cookies.
The mobile app uses secure device storage (Keychain on iOS, EncryptedSharedPreferences on Android) instead of cookies.
12. Do Not Track
We do not currently respond to Do Not Track browser signals because there is no established industry standard for interpreting them. We do not track you across other websites or applications for advertising purposes.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address on your account) or by prominent notice within the Service before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised.
14. Governing Law and Jurisdiction
This policy is governed by the laws of the Republic of Azerbaijan, without regard to conflict-of-laws principles. Any disputes will be resolved in the competent courts of the Republic of Azerbaijan, unless applicable consumer-protection law grants you the right to bring proceedings in your country of residence.
Contact for privacy questions:
Rafael Badalov
Republic of Azerbaijan