// LEGAL

Privacy Policy

Last updated: July 21, 2026

1. Who We Are

GitArena is an interactive Git training platform operated independently.

2. Data We Collect

We collect only what is needed to run the Service:

Account data
Email address, display name, and username — provided by you at sign-up.
Progress data
Which challenges you have completed, your XP, and daily streak count.
Payment data
Payment is processed by Stripe. We store only a boolean flag indicating whether your account has paid access. We never see or store your card details.
Usage data
Standard server logs (IP address, browser, pages visited) retained for up to 30 days for security and debugging.

3. How We Use Your Data

  • +To authenticate you and maintain your session.
  • +To save and display your challenge progress, XP, and streak.
  • +To display your username on the public leaderboard (you may choose any username).
  • +To verify paid access and deliver the product you purchased.
  • +To respond to support requests you send us.

We do not sell, rent, or share your personal data with third parties for advertising purposes.

4. Third-Party Services

Supabase
Database, authentication, and file storage. Your account data and progress are stored on Supabase infrastructure.
Stripe
Payment processing. Stripe handles all card data under their own PCI-DSS compliance. We receive only a payment confirmation.

5. Cookies & Local Storage

We use browser cookies for session management (keeping you logged in). We use localStorage to track whether you have used the free guest challenge on a device. We do not use tracking or advertising cookies.

6. Data Retention

We retain your account data and progress for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days, except where retention is required by law.

7. Your Rights

Depending on your jurisdiction you may have the right to access, correct, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, email us We will respond within 30 days.

8. Security

All data is transmitted over HTTPS. Authentication is handled by Supabase, which enforces industry-standard security practices. We follow the principle of least privilege and do not store passwords in plain text.

9. Children

The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with their data, contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Policy at any time. We will update the "Last updated" date and, for material changes, notify you via email if we have one on file. Continued use after changes constitutes acceptance.

11. Contact

Privacy questions or requests: