Legal
Privacy Policy
Last updated: 2 July 2026 · The English-language version of this document is the authoritative version.
This Privacy Policy explains what personal information we collect when you use AceLoop — our website, apps, and services (the “Service”) — how we use and share it, and the rights and choices you have. AceLoop is operated by BRAVO BRV LIMITED, a company registered in England and Wales. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1.Who we are
AceLoop is an AI-powered coding-practice platform — a “coding gym” with hand-verified problems on a real sandboxed judge, an AI coach, AI-generated lessons and roadmaps, voice mock interviews, spaced-repetition review, and a community problem library.
The Service is owned and operated by BRAVO BRV LIMITED (“BRAVO BRV”, “we”, “us”), a limited company registered in England and Wales. BRAVO BRV LIMITED is the controller of the personal data described in this Policy.
For any privacy question, or to exercise any of your rights, contact us at [email protected].
2.Information we collect
Account & identity. When you sign up we collect your email address and a password (stored only as a secure hash by our authentication provider, Supabase — we never see or store your plain password). If you sign in with Google or Apple, we receive your name and email address from that provider (Apple lets you hide your real email). At sign-up we also record whether and when you accepted our Terms and whether you opted in to marketing email.
Profile & preferences. Your display name, unique username, interface and content language, theme and editor preferences, notification and reminder settings, and your onboarding answers (your goal, experience level, and chosen programming languages).
Learning activity. Your goals (including the free-text description you write), AI-generated roadmaps and lessons, lesson progress and evaluations, practice attempts, spaced-review schedule, streaks, XP, badges, bookmarks and personal notes, study-plan blocks, and monthly usage counters.
Code you write. Your in-progress editor drafts and every submission you run against the judge — the full source code, chosen language, verdict, tests passed, runtime, and memory usage.
AI interactions. Your messages to the AI mentor and in-problem chat, hint requests, code-review requests, “explain my mistake” requests, and the AI responses to each — stored so you can revisit them and so the features work across sessions.
Interview data. For mock interviews we store the interview configuration (role, company, duration), the text transcript of the conversation, and your scores, rubric, and written feedback. We do not record or store your audio, and camera video never leaves your device — see Microphone & camera.
Community & social content. Comments and discussions you post, solutions you choose to share (including your code and its runtime metrics), community problems you publish, shared lesson content, upvotes and votes, your leaderboard/league alias, friend connections and short “nudge” messages, and — if you enable them — your public profile (alias, headline, username) and shared roadmap links.
Billing information. Payments are processed by our payment providers. On the web, Stripe collects and processes your card details; on iOS, purchases go through Apple In-App Purchase, validated by RevenueCat. We never receive or store your card number. We store your plan, subscription status, renewal/trial dates, provider identifiers (e.g. a Stripe customer id), your credit balance, and a ledger of credit grants and spends. If you claim a student discount, we check the domain of your sign-up email (e.g. .edu / .ac) to determine eligibility.
Usage & AI-cost telemetry. For each AI action we record which feature you used, the model called, token counts, processing cost, latency, and whether the call succeeded. We use this to meter credits, keep the Service healthy, and detect abuse.
Communications. Emails and support messages you send us, your email preferences, and push-notification subscriptions (the browser push endpoint and its encryption keys, your reminder hour, and timezone offset).
Technical & log data. Like virtually every online service, our hosting and infrastructure providers (Railway, Supabase) generate short-lived server logs that can include your IP address and browser/device type. We do not run any third-party analytics, advertising, or tracking tools.
3.Microphone & camera
Microphone. Voice features (live mock interviews, the voice tutor) use your microphone only after you grant permission. During a realtime voice interview, your audio streams to our voice provider, ElevenLabs, which converts speech to text and generates the interviewer's spoken replies in real time. In the turn-based fallback, audio is transcribed and then discarded. In all cases, AceLoop stores only the text transcript — never the audio itself.
Camera. The interview room offers an optional self-view so you can practise being on camera. This video is rendered locally on your device only — it is never transmitted, recorded, or stored by us or anyone else. You can turn it off at any time.
4.How we use information
We use personal information to:
- Provide and operate the Service — run your code in the sandbox, generate lessons, roadmaps, hints and feedback, conduct mock interviews, schedule spaced review, and track your progress;
- Create and secure your account and authenticate you;
- Process subscriptions, credits, and top-ups; meter credit usage; and prevent fraud and abuse;
- Send transactional and service emails (e.g. password resets, subscription notices) and the reminders and digests you have turned on;
- Send marketing emails only if you opted in — see Marketing emails;
- Operate the community and social features you choose to use — discussions, shared solutions, the community problem library, leaderboards, leagues, friends, and public profiles;
- Monitor usage, cost, and reliability to maintain, debug, and improve the Service;
- Comply with law and enforce our Terms of Service.
5.AI processing
Core features rely on third-party AI providers. To generate lessons, roadmaps, hints, code review, complexity analysis, mistake explanations, custom problems, and interview questions and scoring, we send the relevant inputs — such as your code, your messages, and your interview responses — to large-language-model providers: OpenAI and Google (Gemini). For voice, we use OpenAI text-to-speech and ElevenLabs (realtime conversation, speech-to-text, and text-to-speech).
We access these providers through their business/API offerings. Under those providers' published API terms, content submitted via the API is not used to train their models. We do not train our own models on your personal data. We do use anonymous, aggregate signals (such as lesson ratings) to improve what the Service generates.
Automated decision-making. AI features score practice work and mock interviews and adapt your learning path. These outputs are practice feedback only — they produce no legal or similarly significant effects on you, and no decision about your account (such as suspension or billing) is made solely by automated means. AI output can be inaccurate; see the disclaimers in our Terms.
6.Lawful bases (UK GDPR)
Under the UK GDPR, we rely on the following lawful bases:
- Contract (Art. 6(1)(b)) — to provide the Service you sign up for: your account, running code, generating lessons and interviews, community features you use, and billing.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud and abuse, meter usage and cost, debug, and improve the product, balanced against your rights and expectations.
- Consent (Art. 6(1)(a)) — for marketing email, microphone and camera access, and push notifications. You can withdraw consent at any time, as easily as you gave it.
- Legal obligation (Art. 6(1)(c)) — to comply with applicable law, such as tax and accounting record-keeping.
We do not process special-category data, and we ask you not to include it in content you submit.
8.Our service providers (sub-processors)
We rely on the following providers, who process personal data only to provide services to us:
- Supabase — authentication, database, and secure storage (all account and app data);
- Railway — application hosting and infrastructure;
- OpenAI — language-model processing for AI features, and text-to-speech (your prompts, code, and interview responses);
- Google (Gemini) — language-model processing for AI features (same categories as OpenAI);
- ElevenLabs — realtime voice conversation, speech-to-text, and text-to-speech for interviews and voice features (your microphone audio and transcripts);
- Stripe — web payment processing and billing portal (your email, plan, and payment details, which Stripe holds);
- Apple — In-App Purchase on iOS/iPadOS, and RevenueCat — validating and managing those purchases (your account id and purchase status);
- Resend — transactional, reminder, digest, and (where you opted in) marketing email delivery (your email address and name);
- Code-execution sandbox — your submitted code and inputs are compiled and run in an isolated sandbox environment (self-hosted, or a managed judge service) to produce verdicts.
The specific providers may change as the Service evolves; we keep this list current in this Policy.
9.Community content is public
Some parts of AceLoop are community spaces. If you post a comment or discussion, share a solution, publish a community problem, share a roadmap link, join a leaderboard or league, or enable a public profile, that content — together with the author name or alias shown on it — is visible to other users (and, for shared roadmap links and public profiles, to anyone with the link). Think before you post: don't include personal data you wouldn't want public.
Leaderboards and leagues display a self-chosen alias (anonymous by default), never your email. You can leave a leaderboard at any time, delete your own comments, and disable your public profile or shared links whenever you like.
11.Marketing emails
In line with the UK's Privacy and Electronic Communications Regulations (PECR), we send marketing email — product updates, tips, and offers — only with your consent, which you can give at sign-up or in your settings. We record when you consent so we can evidence it.
You can withdraw consent at any time via the unsubscribe link in every marketing email or from your account settings, and we will stop promptly. Transactional and service emails (password resets, billing notices, reminders you turned on) are not marketing and are unaffected.
12.Data retention & deletion
We keep your personal information for as long as your account is active and as needed to provide the Service. We retain certain records longer where the law requires it (for example, billing and tax records) or where necessary to resolve disputes and enforce agreements. Infrastructure logs are short-lived.
When your account is deleted, your personal data — profile, learning history, code, AI conversations, interview transcripts, comments and discussions, social connections, and settings — is deleted. Two narrow exceptions apply:
- Community problems you published remain in the shared library but are anonymized — the link to your account is removed, because other users' practice depends on them;
- Records we must keep by law (e.g. payment and tax records held with our payment providers) are retained for the legally required period.
To delete your account, contact us at [email protected] from your account email and we will action it within 30 days (usually much sooner). We are building in-app self-service deletion; until it ships, email is the deletion channel.
13.Your rights
Under the UK GDPR you have the right to:
- Access your personal data (a “subject access request”);
- Rectify inaccurate or incomplete data;
- Erase your data (“right to be forgotten”);
- Restrict or object to processing, including processing based on legitimate interests;
- Data portability — receive the data you provided in a structured, commonly used, machine-readable format;
- Withdraw consent at any time, where processing is based on consent.
You can update your profile, preferences, and consents in your account settings. For anything else — access, export, correction, deletion, objection — email [email protected]. We will verify your request and respond within one month, as UK GDPR requires. You will never be charged for exercising your rights, and we will never discriminate against you for doing so.
If you are outside the UK, you may have equivalent rights under your local law (for example, the EU GDPR or the California CCPA/CPRA); we honour those too. We do not sell or “share” personal information as those terms are defined in California law.
14.Security
We protect your data with industry-standard measures: encryption in transit (HTTPS everywhere), passwords stored only as salted hashes by our authentication provider, database row-level security so each account can only ever read its own rows, encrypted secret storage, signature-verified payment webhooks, and access controls on administrative functions. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security — but if we become aware of a personal-data breach that risks your rights, we will notify you and the Information Commissioner's Office (ICO) as required by law.
15.International transfers
Some of our service providers process data outside the UK, principally in the United States (for example OpenAI, Google, ElevenLabs, Stripe, and Resend). Where personal data leaves the UK, we rely on safeguards recognised under UK law: the UK Extension to the EU-US Data Privacy Framework (for certified providers), the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and UK adequacy regulations, as applicable to each provider.
16.Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you are under 18, please use AceLoop with the involvement of a parent or guardian. If you believe a child under 13 has created an account, contact [email protected] and we will delete it.
17.Changes to this policy
We may update this Policy from time to time as the Service and the law evolve. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app or by email before the changes take effect. Your continued use of the Service after an update means you accept the revised Policy.
18.Contact us & complaints
Questions, requests, or concerns about this Policy or your data: email [email protected]. We will do our best to resolve any concern quickly.
You also have the right to lodge a complaint with the UK supervisory authority: the Information Commissioner's Office (ICO) — ico.org.uk, or by phone on 0303 123 1113. If you are in the EEA, you may complain to your local data-protection authority instead.