Last updated August 29, 2026
CodeSights collects the minimum it needs to run a community platform: your email so you can sign in, your username so the community knows you, and anonymous usage events so we can see what is working. We do not sell data, we do not run advertising, and we do not use third-party tracking. When you delete your account, your content goes with it.
Account data. Your email address and a password (stored hashed by our authentication provider, never readable by us), or your Google account identity if you sign in with Google. Your chosen username, and optionally a GitHub profile if you add one.
Content you publish. Insights, upvotes, and attestations are public by design and appear with your username. If you apply to become a certified reviewer, your application (name, LinkedIn, optional GitHub, and background statement) is visible only to platform admins.
Usage analytics. We record events like page views, searches, downloads, votes, and sign-ins, tied to a random session identifier stored in your browser and, when you are signed in, to your account. We use this to understand how the platform is used. Analytics are private to the platform team and never shown to other users.
No advertising cookies, no third-party trackers, no tracking pixels, no fingerprinting, no selling or renting of any data to anyone. The only things stored in your browser are your session (so you stay signed in) and the random analytics identifier.
Your username, your public page, your insights, your upvote counts, and your attestations are visible to everyone, signed in or not. Your follower count is public unless you hide it in account settings. The list of who follows you is visible only to you, and who you follow is visible only to you, with one natural exception: each person you follow sees you among their own followers. Your email address is never public and is never shown to other members.
We send transactional email only: verifying your address, resetting your password, and similar account notices. No marketing lists, no newsletters you did not ask for.
Your data is processed by the infrastructure that runs the site: Supabase (database, authentication, and file storage), Netlify (website hosting), Google (only if you choose to sign in with Google), and Google Fonts (which serves the site's typefaces). Each processes only what is needed to provide its service.
You can permanently delete your account yourself from account settings. Deletion removes your profile, insights, votes, attestations, and reviewer applications. Usage analytics are kept in anonymized form: the events remain, the link to you does not.
Account data is kept for as long as your account exists. Downloaded datasets are yours; we have no visibility into what you do with a CSV after it leaves the site.
You can change your username, add or remove your GitHub profile, hide your follower count, set a new password, or delete your account entirely, all from account settings. For anything else, contact jon@codesights.com.
If this policy changes, the date at the top will reflect the latest revision. Material changes will be called out on the site.