Privacy Policy
Last updated: September 8, 2026
This Privacy Policy explains how Codvoy ("Codvoy", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use the Codvoy platform at app.codvoy.com and this website. Codvoy is a learning platform where you take video courses, practice in a coding playground, build real websites, and earn certificates. Codvoy is operated from Ethiopia. By creating an account or using our services, you agree to the practices described in this policy.
Information You Provide to Us
When you create an account or use the platform, you may give us:
- Account details — your name, email address, phone number, and password (if you set one). You can sign in with an email and password, a phone number (verified by a one-time code we send you by SMS), or your Google account. Passwords are handled securely by Firebase Authentication and are never visible to us.
- Payment confirmation — the bank or mobile-money reference and any payment screenshot you upload when you request access to a paid course, AI credits, or other paid features.
- Content you create — the code, projects, and websites you build in the playground, along with any text, images, or files you add to them.
- Communications — messages you send us for support, along with comments, ratings, course replies, and challenge submissions you post.
Information We Collect Automatically
As you use the platform we collect:
- Usage and progress data — lessons viewed, video watch progress, exercises and quizzes completed, and features used.
- Device and technical data — device type, operating system, browser, app version, and approximate region.
- Diagnostics — crash reports and error logs used to keep the app stable.
- Notification tokens — a push-notification identifier so we can send you updates about your account and courses.
- We keep in-app analytics deliberately lightweight and sampled, and we never record your keystrokes or capture screen recordings. Our marketing websites do, however, use third-party advertising and analytics tools that involve cross-site tracking — see “Cookies, Analytics, and Advertising” below.
Guest Sessions
You can explore parts of Codvoy as an anonymous guest before signing up. Guest activity is stored under a temporary anonymous account. If you later create a full account, we merge your guest progress into it. Guest data that is never linked to an account is periodically cleared.
How We Use Your Information
We use your information to:
- Provide, maintain, and improve the platform and your experience.
- Verify manual payments and grant access to paid courses, AI credits, and other entitlements.
- Personalize content, track your progress, and issue certificates of completion.
- Run features such as XP, leaderboards, challenges, and prizes.
- Send you account, course, and support notifications.
- Detect, prevent, and address fraud, abuse, and technical problems.
Service Providers We Share Data With
We run the platform on trusted infrastructure providers that process data on our behalf. We share only what each provider needs to deliver its part of the service:
- Google Firebase (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions) — your account, app data, and uploaded files.
- Google Analytics (GA4) and BigQuery — usage analytics for the app and our websites.
- Google Ads, Meta (Facebook and Instagram), TikTok, and LinkedIn — advertising and ad-measurement partners. Our marketing websites include these partners’ pixels and tags, which collect device and cookie identifiers and page-visit events to measure how our ads perform and to show you relevant ads. Our Android app additionally includes the Meta SDK, which reports app installs, app opens, and in-app activity events together with your device’s advertising identifier to Meta, so we can measure which ads lead to app installs. See “Cookies, Analytics, and Advertising” below.
- Google Crashlytics — crash and error diagnostics.
- Firebase Cloud Messaging — push notifications.
- Resend — delivery of transactional and notification emails (for example account verification, password reset, and service updates), and delivery-status reports for those emails. Your email address and the content of the message are shared with Resend so it can send the email on our behalf.
- Cloudflare (R2 storage and CDN) — hosting and delivery of images, assets, the websites you publish, and files attached to messages you exchange with us.
- Cloudflare Email Routing — receiving email you send to our support and contact addresses so our team can read and reply to it.
- Google Gemini — AI-powered features, including the coding playground and the AI site-building assistant. In the playground, the prompts and code you submit are sent to Google to generate a response. When you use the AI site assistant to build or edit a site, the text in your site’s fields (headings, body text, item names and prices, and any name, phone number, or address you type into a field — including details about other people), your section labels, the filenames of images you upload (but not the image files themselves), the theme colors and fonts you choose, and structural details about the site are sent to Google each time the assistant works on your site; if you describe the site you want in your own words, that description is sent too. Orders, RSVPs, and visitor contact details submitted through a site you publish are never sent to Google.
- Unsplash — when you search for stock photos, your search terms are sent to Unsplash.
- Google (Sign in with Google) — when you choose to sign in with Google, Google confirms your identity and shares basic profile information such as your name and email address with us to create or access your account.
- GeezSMS (and a backup SMS provider) — delivery of one-time verification codes and account-related text messages. Your phone number and the message content are shared with the provider so it can send the SMS on our behalf.
- These providers may store data on servers outside Ethiopia (primarily on Google Cloud, Cloudflare, and Resend infrastructure).
Payments
Codvoy uses manual payment confirmation. When you pay by bank transfer or mobile money, you submit a reference or screenshot, and we grant access after verifying it. We retain payment records — with personal details minimized — for accounting, tax, and dispute-resolution purposes, even after an account is deleted. We never store full card numbers or bank login credentials.
Public and Shared Content
Some of your activity is visible to others by design:
- Certificates you earn may be verifiable through a public link.
- Comments, ratings, and challenge entries you post may be shown to other users alongside your display name.
- Websites you publish are served publicly on the internet and can be viewed by anyone who has the link.
Orders and Enquiries From Published Sites
Some sites published with Codvoy — a shop catalog or a restaurant menu, for example — let a visitor send the site owner an order or an enquiry. An order is a contact request, not a payment: no money changes hands on the platform and the visitor does not create an account. When a visitor places one, we collect and store on the site owner's behalf:
- The name and phone number the visitor enters, a delivery address if they choose delivery, the products or items and quantities they selected, and any note they add.
- These details are shown to the site owner inside the app, and to anyone the owner chooses to give access to. Where the owner switches on a staff dashboard for their site, that means anyone holding the dashboard passcode link can see the orders, including each buyer’s name, phone number and delivery address. The owner controls that passcode and can change it at any time.
- We delete these order records automatically: after 90 days for a shop catalog, and after 30 days for a restaurant menu. A site owner who needs an order for longer must copy the details out before then.
- Once we pass the details to the site owner, the owner decides how they are used and is responsible for handling them lawfully. If a visitor wants their order details removed sooner, the site owner can delete the record, or the visitor can contact us.
- If a site owner switches on order alerts, we send an SMS to the contact phone number they entered, naming the site and how many new orders are waiting. That message never contains a buyer’s name, phone number, or address, and it is delivered by the SMS provider listed above.
Contact and Payment Details on a Published Site
If you publish a shop or a menu with Codvoy, you can add your own contact details (phone, WhatsApp, Telegram) and payment-account details — for example a bank or mobile-money account name and number — so buyers can reach you and pay you directly. These are part of the site you publish, so they are served publicly on the internet to anyone who opens the site or places an order. Publish only account details you are willing to make public: we do not process, hold, or verify any payment made to them. You can change or remove them at any time from the app. If you delete your account, we remove them from your shop’s live catalog data — but any contact details you typed into the site’s own pages (a contact section, or a Contact page) stay part of the published page, which remains online unless you unpublish the site first.
Communications and Support Records
To provide support and keep an accurate record, we store the emails and SMS messages we exchange with you — including any files attached — together with which member of our team sent or handled each one. We keep these communication records for about two years. Verification codes we send by SMS are never stored in readable form, and the short-lived internal copy used to send them is deleted within a few days. If you work with us as an agent, a member of our sales team may also record brief notes about their contact with you — for example that a call took place, its outcome, and when to follow up — along with which of our staff you are assigned to and what your account owes the platform. These notes are internal, visible only to that staff member and our administrators, and are kept for as long as your agent account is active. We also keep records of commission earned and paid, including bank transfer references, for accounting purposes.
Cookies, Analytics, and Advertising
We use cookies and local storage to keep you signed in, remember your preferences, and understand how the platform is used. In addition, our marketing websites use analytics and advertising cookies and pixels:
- Analytics — Google Analytics (GA4) helps us understand, in aggregate, how visitors find and use our websites.
- Advertising cookies and pixels — we and our advertising partners (Google Ads, Meta, TikTok, and LinkedIn) set cookies and similar technologies on our marketing websites to measure the performance of our ads and to show you relevant ads on those partners’ platforms. These partners may link this data with other information they hold about you under their own privacy policies.
- Your choices — you can clear or block cookies in your browser settings (some features, such as staying signed in, may stop working). You can also opt out of personalized advertising directly with the networks: Google Ads Settings (adssettings.google.com, which also covers DoubleClick), Meta’s Ad Preferences, TikTok’s Ads settings, LinkedIn’s advertising preferences, and industry opt-out tools such as youradchoices.com.
Data Retention
We keep your personal information for as long as your account is active or as needed to provide the service. Orders submitted through a site you publish are deleted automatically — after 90 days for a shop catalog and after 30 days for a restaurant menu; other submissions, such as RSVPs and enquiries, are kept until you or the site owner delete them. When you delete your account, we remove or anonymize your personal data as described below, except for records we are legally or operationally required to retain (such as financial records).
Your Rights and Choices
You can:
- Access and update your profile information from within the app.
- Delete your account from the app settings (available to learners and customers). This permanently removes your private data, anonymizes content you shared publicly, and unlinks or removes your published sites. Financial records are retained with personal details stripped. Staff and agent accounts are closed by contacting us so any outstanding work can be handed over first.
- Turn notifications off from your device settings.
- Contact us to ask about the personal data we hold about you.
Children
Codvoy is intended for users aged 13 and older. If you are under the age of majority in your country, you should use Codvoy only with the involvement of a parent or guardian. We do not knowingly collect personal information from children under 13; if you believe a child has provided us their information, contact us and we will remove it.
Security
We use industry-standard measures — including encrypted connections and access-controlled infrastructure — to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Changes to This Policy
We may update this Privacy Policy as the platform evolves. We will revise the “Last updated” date above and, for significant changes, provide a more prominent notice. Continued use after an update means you accept the revised policy.
Language
This policy is provided in English, Amharic, and Afaan Oromoo. If there is any conflict between the versions, the English version governs.
Contact Us
If you have questions about this Privacy Policy or your data, contact us by email at contact@codvoy.com or on Telegram at t.me/codvoy.
