This privacy policy has been compiled to better serve those who are concerned with how their ‘Personally Identifiable Information’ (PII) is being used online. PII, as described in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read our privacy policy carefully to get a clear understanding of how we collect, use, protect, or otherwise handle your Personally Identifiable Information in accordance with our website.

Who we are

Code Maze is the controller of the personal data described in this policy.

Code Maze, Serbia
Email: [email protected]
Phone: +381 63 668032

This policy covers code-maze.com and
courses.code-maze.com.

Last updated: 20 September 2026. We will post any change on this page and update that date.

What personal information do we collect?

When ordering or registering on our site, as appropriate, you may be asked to enter your name, email address, or other details to help you with your experience.

When you use Code Maze Mentor (our in-lesson AI assistant), we also process the questions you type and the content you submit to it, along with the lesson or course you are viewing at the time.

When do we collect information?

We collect information from you when you register, place an order, subscribe to a newsletter, submit a question to Code Maze Mentor, or otherwise enter information on our site.

How do we use your information?

We may use the information we collect from you when you register, make a purchase, sign up for our newsletter, respond to a survey or marketing communication, browse the website, or use certain other site features in the following ways:

  • To provide and operate Code Maze Mentor, including generating answers to your questions.
  • To improve our website and course content in order to better serve you.
  • To respond to your customer service requests.
  • To ask for ratings and reviews of services or products.

Why we are allowed to use your data

If you are in the United Kingdom or the European Economic Area, the UK GDPR and the EU GDPR require us to
have a lawful basis for every use of your personal data. Ours are:

What we do Our lawful basis
Run your account, give you access to a course you bought, send receipts and service emails Performance of a contract with you
Take payment and keep records of the sale Contract, and a legal obligation to keep tax and accounting records
Send you marketing about courses and discounts after you have bought from us or started a
purchase
Our legitimate interest in marketing similar products to our own customers, relying on the soft
opt-in in UK PECR regulation 22(3) and its equivalents. You can refuse at any time.
Send you our newsletter when you asked for it on our website, for example in exchange for the free
ebook
Your consent, which you may withdraw at any time
Product analytics, keeping the site secure, preventing fraud and abuse Our legitimate interest in running and improving a safe service
Code Maze Mentor conversations Performance of a contract, and our legitimate interest in improving the courses and detecting
misuse

Code Maze Mentor and artificial intelligence

Code Maze Mentor is an AI-powered assistant available inside our lessons. To generate a response, the questions and content you submit to the assistant are sent to our AI provider, Anthropic, PBC (“Anthropic”), which processes them on servers located in the United States. We send this data to Anthropic solely to generate answers for you.

Anthropic acts as our service provider (subprocessor) for this feature. Under Anthropic’s commercial terms, inputs and outputs sent through its API are not used to train Anthropic’s models. We encourage you to review Anthropic’s own privacy policy for details on how it handles data on our behalf: anthropic.com/legal/privacy.

Please do not share personal, sensitive, or confidential information (such as passwords, financial details, or private data about yourself or others) in your messages to Code Maze Mentor.

Voice features (listening and speaking)

Mentor Unleashed can read answers aloud and lets you ask questions with your voice. For these features we use ElevenLabs, Inc. (“ElevenLabs”) as our service provider:

  • Listening to an answer. When you play an answer, the text of that answer is sent to ElevenLabs and converted to speech. We store the resulting audio file on our servers for up to 60 days so that replaying the same answer is instant and does not incur a further charge.
  • Asking by voice. If you use the microphone button, your browser records audio only while you are actively recording, and that recording is sent to ElevenLabs to be transcribed into text. We do not store the recording. It is discarded once transcribed. We keep only the length of the recording (to apply usage limits and to account for costs) and the transcribed text, which becomes your question and is retained with your conversation as described below.

Your browser will ask for microphone permission before any recording can take place, and nothing is captured unless you start a recording yourself. As with Anthropic, ElevenLabs acts as our service provider for these features. You can review its privacy policy here: elevenlabs.io/privacy.

Data retention for Code Maze Mentor

We retain the conversations you have with Code Maze Mentor, including your questions, the assistant’s answers, and the associated lesson or course, in order to operate the feature, improve our courses, and monitor for misuse. We retain this data for 90 days, after which it is deleted or anonymized. You may request deletion of your Code Maze Mentor conversation history by contacting us using the details at the end of this policy.

How do we protect your information?

We sell courses through this site, but we never see or store your card details: payment is completed entirely on our payment provider’s systems. We do not ask for card numbers by email or on the phone, and you should treat any message that does as fraudulent.

Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems and are required to keep the information confidential. In addition, all sensitive information you supply is encrypted via Secure Socket Layer (SSL) technology.

We implement a variety of security measures when a user enters, submits, or accesses their information to maintain the safety of your personal information.

All payment transactions are processed through a gateway provider and are not stored or processed on our servers.

Payments

Course payments are processed by Paddle (Paddle.com Market Ltd, United Kingdom) and
Lemon Squeezy (Lemon Squeezy LLC, United States), who act as merchant of record. They collect
your payment details and billing information directly; we receive only the information we need to give you
access and keep our records, such as your name, email address, billing country, and what you bought. We never
see your full card number.

See paddle.com/legal/privacy and
lemonsqueezy.com/privacy.

Do we use cookies?

Yes. Cookies are small files that a site or its service provider transfers to your computer’s hard drive through your web browser (if you allow) that enable the site’s or service provider’s systems to recognize your browser and capture and remember certain information. We use cookies to understand and remember your preferences, to keep you signed in, and to compile aggregate data about site traffic and interaction so that we can offer better site experiences and tools in the future.

We use cookies to:

  • Understand and save your preferences for future visits.
  • Compile aggregate site-traffic and interaction data to improve the site, through our analytics provider PostHog.

You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies through your browser settings. Since each browser is a little different, look at your browser’s Help menu to learn the correct way to modify your cookies. If you turn cookies off, some of the features that make your site experience more efficient may not function properly.

Analytics

We use PostHog to understand how our site and courses are used, so that we can improve them. PostHog is our service provider for product analytics and processes this data on servers located in the European Union. Analytics requests are routed through our own domain (t.code-maze.com).

Through PostHog we collect information such as the pages you view, the features and links you interact with, the site that referred you, your device and browser type, and an approximate location derived from your IP address. We use this to see which lessons and features are working, to find problems, and to decide what to build next. We do not use it to build advertising profiles, and we do not sell this data.

You can review PostHog’s privacy policy at posthog.com/privacy. Most browsers also let you send a “Do Not Track” signal or block analytics scripts; the site remains fully usable if you do.

Third-party disclosure

We do not sell, trade, or otherwise transfer your Personally Identifiable Information to outside parties unless we provide you with advance notice. This does not include our website hosting partners, our AI provider (Anthropic), and other parties who assist us in operating our website, conducting our business, or serving our users, so long as those parties agree to keep this information confidential. We may also release information when its release is appropriate to comply with the law, enforce our site policies, or protect our rights, property, or safety, or those of others.

Sending data outside the UK and EEA

Some of our providers are in the United States: Anthropic, ElevenLabs and Lemon Squeezy. Where personal data reaches them, the transfer is covered by the European Commission’s Standard
Contractual Clauses and the UK Addendum, or by the provider’s certification under the EU-US and UK-US Data
Privacy Framework, together with the safeguards in our agreements with them. PostHog processes our analytics
data on servers in the European Union, and Brevo in France.

Third-party links

Occasionally, at our discretion, we may include or offer third-party products or services on our website. These third-party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.

How long we keep things

  • Account and course access: for as long as you hold an account, and for a short period
    after you close it so we can resolve any dispute.
  • Order and payment records: as long as tax and accounting law requires, currently ten
    years.
  • Marketing list: until you unsubscribe or ask us to delete you. We also remove addresses
    that stop engaging: in September 2026 we contacted subscribers who had not opened an email in two years and
    removed those who did not respond.
  • Code Maze Mentor conversations: 90 days, as described above.
  • Voice recordings: not stored. Generated audio is kept for up to 60 days.
  • Analytics: as held by PostHog under its own retention settings.

California Online Privacy Protection Act

CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require any person or company in the United States (and conceivably the world) that operates websites collecting Personally Identifiable Information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals or companies with whom it is being shared.

According to CalOPPA, we agree to the following:

  • Users can visit our site anonymously.
  • Our privacy policy link includes the word ‘Privacy’ and can easily be found on the page specified above.
  • You will be notified of any privacy policy changes on this Privacy Policy page.
  • You can change your personal information by emailing us.

How does our site handle Do Not Track signals?

We honor Do Not Track signals: we do not track, plant cookies, or use advertising when a Do Not Track (DNT) browser mechanism is in place.

Does our site allow third-party behavioral tracking?

No. We do not use third-party behavioral advertising tracking on our site.

COPPA (Children Online Privacy Protection Act)

When it comes to the collection of personal information from children under the age of 13, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, the United States’ consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online.

We do not specifically market to children under the age of 13.

Fair Information Practices

The Fair Information Practices Principles form the backbone of privacy law in the United States, and the concepts they include have played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to complying with the various privacy laws that protect personal information.

In order to be in line with Fair Information Practices, should a data breach occur, we will take the following responsive action:

  • We will notify you via email within 7 business days.
  • We will notify you via in-site notification within 7 business days.

We also agree to the Individual Redress Principle, which requires that individuals have the right to legally pursue enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or government agencies to investigate and/or prosecute non-compliance by data processors.

Emails we send you

There are two kinds, and they follow different rules.

Service emails. Receipts, access details, password resets, announcements about a course
you are enrolled in, and important notices about your account or the Service. These are part of delivering
what you bought, so you cannot unsubscribe from them while you hold an account.

Marketing emails. New courses, updates to courses you own, and discounts. You will receive
these if:

  • you asked for them, for example by signing up to the newsletter or downloading our free ebook; or
  • you bought a course from us, or began a purchase and gave us your email address. In that case we rely on
    the soft opt-in: the products we tell you about are similar to the one you were buying, and we gave you a way
    to refuse when we collected your address and in every message since.

Every marketing email has a one-click unsubscribe link. You can also stop them at any time
by replying to any of our emails or writing to
[email protected], and we will act on it promptly.
Unsubscribing from marketing never affects access to a course you have bought, and never stops your service
emails.

We use Brevo (Sendinblue SAS, France) to send both kinds of email. Brevo is our processor
and stores your email address, your name where you gave it, and records of which emails were delivered,
opened, and clicked. Its privacy policy is at
brevo.com/legal/privacypolicy. We previously used
Mailchimp; that account is closed to new sending.

For recipients in the United States, we also follow the CAN-SPAM Act: we do not use false or misleading
headers or subject lines, we identify marketing messages as such, we include a physical contact address, and
we honour unsubscribe requests promptly.

Your rights

If you are in the United Kingdom or the European Economic Area you have the right to:

  • ask what personal data we hold about you and get a copy;
  • have inaccurate data corrected;
  • have your data deleted in certain circumstances;
  • restrict or object to how we use it, including an absolute right to object to direct marketing at any
    time, for any reason;
  • receive data you gave us in a portable format;
  • withdraw consent at any time, where we rely on consent. Withdrawing it does not undo what we did
    before.

To use any of these, email [email protected]. We will
respond within one month. We will not charge you, and we will not treat you differently for asking.

If you think we have handled your data badly, please tell us first so we can put it right. You also have
the right to complain to a data protection authority: in the United Kingdom the Information Commissioner’s
Office (ico.org.uk), in the EEA the authority in the country where you live,
and in Serbia the Commissioner for Information of Public Importance and Personal Data Protection
(poverenik.rs).

Automated decisions

We do not make decisions about you by automated means that produce legal effects or similarly significant
effects. Code Maze Mentor generates answers automatically, but it makes no decisions about you.

Contacting us

If you have any questions regarding this privacy policy, please contact us using the information below.

code-maze.com
Code Maze
Serbia
[email protected]
+38163668032