Skip to content
</> Kodstigen
Courses Log in Sign up

Last updated 2026-09-23

Privacy policy

We collect as little as possible, use it only to make the service work, and never sell or share it for advertising. This policy explains how we process your personal data under the EU General Data Protection Regulation (GDPR) and Swedish law.

1. Data controller

The controller responsible for processing your personal data is:

23nisand
Email: Info@andnet.se

2. What data we process

  • Account details: your name (or nickname), email address and your password as a one-way hash (bcrypt). We can never see your password in plain text.
  • Discord link (optional): if you choose to log in with Discord, we store your Discord user ID. When you sign up we also receive your display name and email address from Discord, which you can edit before the account is created. We do not store your avatar, servers, messages or access token.
  • Remembered devices (optional): if you tick "Keep me logged in", we store a one-way hash of a random code together with when it was created and when it expires. The code itself only exists in a cookie on your device.
  • Learning progress: which lessons, quizzes and coding exercises you have completed and when.
  • Your exercise code: the latest version of the code you write in each coding exercise is saved to your account, so you can continue where you left off on any device. The code is only run in your own browser, in an isolated sandbox – never on our server.
  • Agreement details: which version of the terms of use you accepted and when, plus when your account was created and when you last logged in.
  • Security data: to stop password guessing we store a pseudonymised checksum (HMAC) of your IP address and the email address entered in failed login attempts. Your IP address is never stored in plain text in our database.
  • Server logs: our hosting provider may temporarily log IP addresses, timestamps and requested pages for operations and security.

We use no analytics tools, ad networks, social media buttons or external fonts. The site does not load any content from third parties.

3. Purposes and legal basis

PurposeDataLegal basis (GDPR)
Create and manage your account and let you log inAccount detailsContract, Art. 6(1)(b)
Log in with Discord if you choose toDiscord user IDContract, Art. 6(1)(b)
Keep you logged in on a device when you ask for itRemembered devicesContract, Art. 6(1)(b)
Save and show your progressLearning progressContract, Art. 6(1)(b)
Save your exercise code so you can continue laterYour exercise codeContract, Art. 6(1)(b)
Restore the service after a technical failureAll data above (in backups)Legitimate interest, Art. 6(1)(f), and our duty to ensure availability under Art. 32(1)(c)
Send a password reset link when you request oneName, emailContract, Art. 6(1)(b)
Be able to show which terms you acceptedAgreement detailsLegitimate interest, Art. 6(1)(f)
Protect the service against intrusion and abuseSecurity data, server logsLegitimate interest, Art. 6(1)(f), and our duty to secure data under Art. 32

Our legitimate interest is keeping the service and your data secure. We have concluded that this outweighs the impact on your privacy, because the data is pseudonymised and deleted quickly.

4. How long we keep data

  • Account, progress and exercise code: until you delete your account. Choosing "Reset progress" or "Reset code" deletes the saved code straight away. Accounts that have not been used for 24 months are deleted automatically.
  • Remembered devices: no more than 30 days. They are removed immediately when you log out, change your password or choose "Log out on all other devices".
  • Backups: the database is backed up every night and each backup is kept for 7 days, then deleted automatically. If you delete your account, it therefore disappears from the backups within 7 days. Backups are stored on the same protected server, outside the public web directory, and are only used to restore the service after a failure.
  • Password reset links: valid for one hour and deleted afterwards.
  • Pseudonymised login attempts: no more than 24 hours.
  • Server logs: kept by our hosting provider until the end of the current calendar month, then archived for no more than one additional month before being deleted automatically.

5. Who receives your data

We never sell your data and do not share it with advertisers. The following may process data on our behalf as a data processor, under a data processing agreement in accordance with Art. 28 GDPR:

  • Andnet Hosting – web hosting and email. The servers are located in Sweden.

Logging in with Discord

Logging in with Discord is optional – you can always use email and password instead. If you choose Discord, you are sent to Discord's website, where you log in and approve that we receive your user ID, name and email address. Discord Inc. (USA) is then an independent controller for its own processing under Discord's privacy policy. Our site loads nothing from Discord until you click the Discord button yourself. You can unlink Discord under My account.

Your data is processed within the EU/EEA and we do not transfer it to third countries. (What you share with Discord yourself is covered by Discord's terms.) We may be required to disclose data to authorities where the law requires it.

6. Your rights

Under the GDPR you have the right to:

  • access your data (Art. 15) – download it under My account,
  • rectification of inaccurate data (Art. 16) – change your name and email under My account,
  • erasure (Art. 17) – delete your account instantly under My account,
  • restriction of processing (Art. 18),
  • data portability (Art. 20) – the export uses the machine-readable JSON format,
  • object to processing based on legitimate interest (Art. 21).

Contact us at Info@andnet.se if you want to exercise a right that you cannot handle yourself in the service. We respond without undue delay and within one month at the latest.

We do not make automated decisions or carry out profiling.

7. Security

All traffic is encrypted with HTTPS. Passwords are hashed with bcrypt, the database is stored outside the public web directory, forms are protected against cross-site request forgery (CSRF) and login attempts are rate-limited. If a personal data breach were to occur, we would report it to the Swedish Authority for Privacy Protection (IMY) within 72 hours and inform you if it is likely to result in a high risk to you.

8. Children

You must be at least 13 years old to create an account. If you are under 18, we recommend reading this policy together with a parent or guardian.

9. Cookies

We only use strictly necessary cookies. Read more in our cookie policy.

10. Complaints

If you are unhappy with how we process your data, you can lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se, Box 8114, 104 20 Stockholm, Sweden, or with the supervisory authority in the EU country where you live. Please feel free to contact us first and we will try to resolve it.

11. Changes

If we change this policy in a way that affects you, we will announce it on the site before the change takes effect. The date at the top shows when the policy was last updated.

</>Kodstigen

Learn to code. No ads, no tracking.

Privacy policy Cookies Terms of use Accessibility

© 2026 23nisand