Privacy policy
This policy explains what HashHackCode collects when you use the HashHackCode Academy Chrome extension and the workshop site at act.hashhackcode.com, why, who can see it, and the choices you have.
Who we are
The extension and the workshop site are provided by HashHackCode. Contact us at hi@hashhackcode.com.
What we collect and why
| What | When | Why |
|---|---|---|
| Name, email address and/or phone number | When a student joins a session | To register you in that session, recognise you if you join again, and show mentors whose work they are reviewing. |
| The session passcode you type | When joining | To place you in the right session. It is stored only in a one-way (hashed) form. |
| Screenshots | Only when you press Capture | An image of the browser tab you are looking at, sent to your session’s mentors to review your task. |
| Task submissions and quiz answers | When you send them | To mark your work and show your progress in the session. |
| Group chat messages, questions to mentors and their answers | When they are sent | To deliver them to the people in your session. |
| Activity in the extension: when you were last active and which part of the drawer you have open (tasks, quiz, chat, questions, or closed) | While you are signed in | So mentors can see who is online and who may need help. |
| Mentor and staff accounts: username, display name, email, password, and the reviews and notes they write | When a mentor signs in and works in a session | To sign in and run sessions. Passwords are stored by WordPress in hashed form. |
| IP address | When someone fails to sign in | To slow down repeated wrong attempts. The counters expire after a few minutes. |
| Sign-in tokens | When you sign in | To keep you signed in. They expire after 30 days, or when you sign out. |
What the extension does not do
- It does not read the content of the pages you visit, or your browsing history.
- It does not capture a tab unless you press Capture.
- It does not show ads, use analytics or tracking tools, or sell or rent your data.
What stays in your browser
The extension keeps your sign-in token, the name and contact details you joined with, your drawer preferences (such as which tab was open and what you have already read) and whether you have hidden the # button, in Chrome’s extension storage on your device. Sign out and clear this device in the extension’s Options removes them. Uninstalling the extension removes them too.
Why the extension asks for permissions
- Active tab — to open the drawer on the page where you click the extension icon, and to capture that tab when you press Capture.
- Storage — to keep your sign-in and preferences on your device.
- Scripting — to show the drawer on the page where you click the extension icon, and in Canva and codezing.in tabs that were already open when the extension was installed or updated.
- Access to act.hashhackcode.com — the workshop server where your session’s tasks, work and messages are kept.
- Access to canva.com and codezing.in — the tools students work in during workshops. The extension uses it only to place the # button on those pages. It does not read their content, and you can hide the button at any time.
Who can see your information
- The mentors and staff running your session, and HashHackCode administrators.
- Other students in your session see your name and the messages you post in the group chat — not your contact details, screenshots, answers or private questions.
- Our hosting provider stores the data on our behalf and may not use it for anything else.
We do not share your information with anyone else, except where the law requires it.
Where it is stored and how it is protected
Your information is stored on HashHackCode’s workshop server at act.hashhackcode.com. The extension sends everything over an encrypted (HTTPS) connection, and access inside the site is limited by account roles.
How long we keep it
Session information — registrations, screenshots, submissions, answers, questions and chat — is kept with the session it belongs to. It is deleted when the organiser deletes the session or removes a student from it, or when you ask us to delete it. Sign-in tokens expire after 30 days and failed-attempt counters after a few minutes.
Children and schools
Workshops may include young students. Where a student is below the age at which they can agree to this on their own, the school or organiser that arranges the workshop is responsible for obtaining consent from a parent or guardian before the student joins. Students should only join a session with a passcode given by their mentor. If you believe a child has given us information without the consent they needed, contact us and we will delete it.
Your choices and rights
- Sign out at any time from the account menu in the drawer.
- Remove everything the extension keeps in your browser with Sign out and clear this device.
- Hide the # button at any time.
- Ask to see, correct or delete the information you sent in a session: write to hi@hashhackcode.com with the session name and the email or phone you joined with. We reply within 30 days.
Chrome Web Store user data policy
The use of information received by HashHackCode Academy adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes to this policy
If we change this policy we will update the date at the top. For significant changes we will also tell users in the extension or on this site before the change applies.
Contact
Questions or requests: hi@hashhackcode.com.