Last updated
Privacy Policy
1. Data Controller
The controller of your personal data is:
Wondel.ai sp. z o.o.Twarda 18
00-105 Warsaw, Poland
KRS: 0001029516
NIP: 5252951298
REGON: 524989057
Email: privacy@developertoolkit.ai
2. Legal Basis for Processing
We process your personal data based on:
- Contract performance (Art. 6(1)(b) GDPR) - to provide our educational services and process subscriptions
- Legal obligations (Art. 6(1)(c) GDPR) - for accounting and tax purposes
- Legitimate interests (Art. 6(1)(f) GDPR) - for service improvements, security and error monitoring, privacy-friendly audience measurement that stores nothing on your device, and product, lifecycle and marketing communications about our own services (you can opt out or object at any time)
- Consent (Art. 6(1)(a) GDPR) - for anything stored on or read from your device that is not strictly necessary, namely analytics storage and affiliate referral cookies (see Cookies Policy)
3. Information We Collect
3.1 Information You Provide
- Account Information: Name, email address, password (encrypted)
- Payment Information: Processed securely via Polar (we do not store payment card details)
- Profile Information: Optional GitHub username, company name, timezone
- Communication Data: Support requests, feedback, Discord community interactions
3.2 Information Collected Automatically
- Usage Data: Pages viewed, features used, learning progress (via PostHog)
- Technical Data: IP address (anonymized), browser type, device information
- Cookies: Session cookies, preference cookies (see Cookie Policy section)
3.3 Features Currently Available
- Access to educational content and documentation
- Learning tracks for Cursor and Claude Code
- Discord community access
- GitHub repository access for documentation
- Team seat management (Team and Enterprise plans)
- SSO with Google/GitHub (Team and Enterprise plans)
3.4 Features Coming Soon
The following features are under development and not yet collecting data:
- Team performance analytics dashboard
- Token usage tracking and optimization insights
- Custom onboarding workflows
- SSO/SCIM provisioning
- Audit logging systems
4. How We Use Your Data
- Provide access to educational content and learning materials
- Process subscriptions and manage account access
- Send important service updates and technical notices
- Improve our educational content based on usage patterns
- Provide customer support and respond to inquiries
- Comply with legal obligations (accounting, tax reporting)
- Send product, lifecycle and marketing communications about Developer Toolkit based on our legitimate interest — you can unsubscribe at any time via the link in every email
5. Data Sharing and Third Parties
We share your data only with:
5.1 Service Providers
- Polar (polar.sh): Payment processing and subscription management
- PostHog: Privacy-focused analytics (self-hosted in EU)
- Cloudflare: Content delivery and security
- GitHub: Documentation repository access
- Discord: Community platform (optional participation)
- Turso: Database hosting (EU region)
5.2 Legal Requirements
We may disclose data when required by law or to protect our rights and safety.
6. International Data Transfers
We primarily process data within the European Union. When transfers outside the EU occur (e.g., GitHub, Discord), we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Your explicit consent for specific services
7. Data Retention
- Account data: Duration of service + 30 days after cancellation
- Payment records: 5 years (legal requirement in Poland)
- Analytics data: 90 days (anonymized)
- Support communications: 2 years
- Email opt-out (unsubscribe) records: Retained to honor your choice
8. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit processing of your data
- Portability: Receive your data in a portable format
- Object: Object to certain processing activities
- Withdraw consent: Where processing is based on consent
To exercise these rights, contact us at privacy@developertoolkit.ai
9. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/SSL) and at rest
- Regular security audits and updates
- Access controls and authentication
- Employee training on data protection
- Incident response procedures
10. Cookies Policy
We ask for your consent before storing anything on your device that is not strictly necessary. You choose your categories in the cookie banner and can change them at any time via Cookie settings in the footer.
- Essential (always on, no consent required): keeping you signed in, securing forms against cross-site request forgery, remembering your light/dark theme, and counting your free articles. This category also covers error monitoring (Sentry), which stores nothing on your device and runs on our legitimate interest in keeping the service secure and available.
- Analytics (optional): we always measure page views with PostHog in a cookieless mode that stores nothing on your device and does not identify you — because nothing is stored or read on your device, this runs on our legitimate interest in improving the service rather than on consent, and you may object at any time. If you accept this category, we additionally store analytics data on your device so we can recognise a returning visitor and understand how a journey unfolds across sessions.
- Marketing (optional, off by default): loads advertising and affiliate
tools and stores their identifiers so we can measure and improve our ad campaigns.
Recipients are Google Ads, Meta
(Facebook/Instagram), LinkedIn,
Microsoft Advertising, and our affiliate provider (Affonso, via an
affonso_referralcookie kept up to 60 days). We also store the ad or partner that referred you — click identifiers (e.g.gclid,fbclid) kept for up to 90 days — so a sign-up or purchase is attributed correctly, and we send the ad platforms confirmation that a conversion happened (including a purchase value and, where you consented, a one-way hashed form of your email for matching). We never send your conversations, prompts, searches, file names, or the specific pages you view, and we do not sell your data. Nothing in this category loads until you turn it on, and your choice is versioned and time-stamped. This is the same consent that governs the affiliate program.
Withdrawing consent is as easy as giving it: open Cookie settings in the footer and save your new choice. Withdrawal does not affect the lawfulness of processing carried out beforehand. You can also block or delete cookies in your browser settings, though essential cookies are required for the service to work.
11. Children's Privacy
Our service is not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have collected such data, please contact us immediately.
12. Complaints
If you have concerns about our data processing, you have the right to lodge a complaint with:
President of the Personal Data Protection Office (UODO)ul. Stawki 2
00-193 Warsaw, Poland
Website: uodo.gov.pl
13. Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or through our service.
14. Contact Information
For any questions or requests regarding this privacy policy:
- Email: privacy@developertoolkit.ai
- Address: Wondel.ai sp. z o.o., Twarda 18, 00-105 Warsaw, Poland