Datenschutzrichtlinie

Last updated: 26 September 2026

Dieses Dokument ist derzeit nur auf Englisch verfügbar.

This Privacy Policy explains what personal data HolyCode ("we", "us") collects when you use holycode.org, the single sign-in at id.holycode.org and our services — HolyChat, HolyBuild, HolyAgent and related apps (together, the "Services") — how we use that data and what choices you have.

1. Who we are

HolyCode operates holycode.org and the Services. For anything related to your personal data, write to admin@holycode.org.

2. What we collect

We collect only what is needed to run the Services:

  • Account data — your e-mail address, display name and, if you sign in through a third-party provider, the user ID and avatar that provider shares. Passwords are stored only as salted hashes; passkeys never leave your device.
  • Sign-in providers — if you sign in with Google, GitHub, Apple, Yandex ID or Telegram, we receive only your basic profile: name, e-mail address, avatar and the provider’s user ID. We never see your password for that provider, and we do not post or act on your behalf there.
  • Your content — messages, projects, code, files, agent settings and other material you store in the Services.
  • Technical data — IP address, browser and device type, timestamps and security events such as sign-ins, failed attempts and two-factor challenges. Server logs are kept for security and troubleshooting.
  • Cookies — strictly necessary cookies only: a session cookie that keeps you signed in across holycode.org and its subdomains, and your language preference. We do not use advertising or cross-site tracking cookies.

3. How we use data

We use personal data to:

  • provide and operate the Services you asked for;
  • authenticate you and protect accounts — rate limits, lockouts, detection of fraud and abuse;
  • send service messages such as verification codes, security alerts and invitations (no marketing without your consent);
  • diagnose errors and keep the Services reliable;
  • comply with legal obligations.

Where the GDPR or similar laws apply, we rely on the performance of our contract with you, our legitimate interest in keeping the Services secure, your consent where we ask for it, and our legal obligations.

4. AI features

Some Services generate answers with AI models, including models run by third-party providers. Content you send to an AI feature is passed to the model provider configured for that feature solely to produce the response. We do not sell your content and do not use it for advertising.

5. Sharing

We do not sell personal data. We share it only with:

  • service providers that host our infrastructure and deliver our e-mail, bound by data-processing terms;
  • the sign-in providers listed above, when you choose to use them;
  • other members of an organisation account you join — they can see your name, e-mail address and activity inside that organisation;
  • public authorities, when the law requires it.

6. Retention

Account data is kept while your account exists and deleted within 30 days after you delete the account, unless the law requires us to keep it longer. Server logs are kept for up to 90 days. Backups are rotated within 30 days.

7. Security

All connections use TLS. Passwords are hashed, passkeys and two-factor authentication are available to every account, and access to production systems is limited to the people who need it. No system is perfectly secure — if you find a problem, tell us at admin@holycode.org.

8. Your rights

You can:

  • access, correct, export or delete your data;
  • object to or restrict processing;
  • withdraw consent at any time;
  • complain to your data-protection authority.

Write to admin@holycode.org — we answer within 30 days. You can delete your account in the account settings or by e-mail. A third-party sign-in can be unlinked in our account settings and revoked in the provider’s own settings.

9. Children

The Services are not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

10. International transfers

Our infrastructure may be located in countries other than yours. Where the law requires it, we use recognised safeguards, such as standard contractual clauses, for such transfers.

11. Changes

We will publish any new version on this page with a new date. If a change is material, we will also notify you inside the Services or by e-mail before it takes effect.

12. Contact

Questions about this policy or your data: admin@holycode.org.