Privacy Policy
Last updated: 28 July 2026
This policy explains how Challenges 3.0 processes the personal data of people using the challenges30.dev platform.
Data controller
The data controller is IT-OPES Usługi Informatyczne, NIP PL5291686297. For matters concerning personal data, contact us at .
What data we collect
Sign-in happens through your Devs 3.0 account, from which we receive basic profile data (your email address and display name). When you submit a challenge we collect the link to your public GitHub repository, if that challenge requires one, the language model provider you picked, the model name and the values of the fields that challenge asks for. The set of fields is defined by the challenge author, and we store their content together with your submission. Once a review finishes we store its result, meaning the verdict, the outcome of each criterion, the summary written by the agent and a confidence level. We do not store the contents of your repository in our database, we fetch them only for the duration of a single review.
Purpose and legal basis
We process account data to perform the service of taking part in challenges (Art. 6(1)(b) GDPR). We process submissions and review results on the same basis, because reviewing a repository is the substance of that service. We collect traffic statistics based on your consent (Art. 6(1)(a) GDPR).
Review by the Chall agent
A submitted repository is reviewed by the Chall agent. We fetch the file listing from GitHub along with the contents of the files the agent opens, within set limits, and then send them together with the challenge text to the language model provider you pick when submitting. The options are OpenAI, Anthropic and Ollama Cloud. Each of them processes the content sent to it outside the European Economic Area. The review works on a BYOK basis, meaning it uses the API key you supply with your submission. We hold that key in server memory only for the duration of a single review, we never write it to our database or logs, and we discard it when the review ends. Unlike the Devik assistant, repository contents reach the provider without personal data masking, because altering the code would distort the review. For that reason, only submit repositories that contain no personal data, secrets or keys. We additionally record the course of a review in LangSmith (LangChain, Inc.), an external observability service, in its European region. It receives the full content sent to the model, meaning repository excerpts, the challenge text and your submitted field values, along with the model's answer. This serves review quality diagnostics only. That content is not masked there, just as it is not at the model provider, so the request above about personal data, secrets and keys applies to submitted fields as well.
The public badge
A passed challenge creates a badge available by direct link to anyone who receives that link. The badge page shows your display name as it stood when you passed, along with the challenge title. The name stored on it does not change if you later change the name in your profile. After you delete your account the badge stays visible, unless you ask us to remove it.
The Devik assistant
If you use the Devik assistant available on our pages, your question is sent to Ollama Cloud, an external language model provider that processes it outside the European Economic Area. Before the question is sent we strip contact details and identifiers from it, meaning email addresses, phone numbers, national identification numbers, bank account and card numbers, IP addresses and personal names, replacing them with markers, and we restore them in the answer shown to you. This is a safeguard rather than a guarantee, because name recognition works automatically and can miss some. Please do not enter data in a conversation with the assistant that you do not want to share with us. We do not store assistant conversations in our database. Before a question is sent we ask you to pass an anti-bot check, and we limit the number of requests based on your IP address. We additionally record the course of a request in LangSmith (LangChain, Inc.), an external observability service, in its European region. It receives the question in its already masked form, with markers in place of contact details and identifiers, and the model's answer before your data is restored.
Cookies and analytics
We use cookies that are necessary to run the platform, including a sign-in session cookie and a cookie that stores your language. These necessary cookies do not require consent. The platform also uses Google Analytics 4 to measure traffic. We collect statistics only after you consent to cookies. You can withdraw consent at any time via the Manage cookies link in the footer.
Processors
Sign-in is handled by your Devs 3.0 account. Traffic measurement is provided by Google Analytics 4 (Google Ireland Limited). We fetch the contents of a submitted repository from GitHub (GitHub, Inc.). A submission is reviewed by the language model provider you pick when submitting, meaning OpenAI, Anthropic or Ollama Cloud. Devik assistant answers are generated by Ollama Cloud, an external language model provider. Our internal security service, which strips personal data before content is sent to that provider, operates under the same data controller and is not a separate recipient of data. Content sent for review and questions put to the Devik assistant are processed outside the European Economic Area. We record the course of language model calls in LangSmith (LangChain, Inc.), an external observability service, for quality diagnostics. We use its European region, so this data is stored in Europe. The provider is nonetheless a US entity, so the transfer relies on the European Commission's standard contractual clauses, incorporated in its data processing addendum. We share data with these parties solely for the described purposes.
How long we keep data
We keep submissions and review results for as long as your account exists. Deleting your account on Devs 3.0 anonymizes the account here as well, meaning we replace your email address and display name with placeholder values and revoke your sessions. Submissions then stay in the database attached to an anonymized account, together with the repository link, which usually contains your GitHub username. If you also want the submissions and badges themselves removed, write to . Identifying details in the log of administrator access to user data are stripped automatically once the set retention window passes.
Your rights
You have the right to access, rectify, erase, restrict, and port your data, and to withdraw consent. You delete your account in your Devs 3.0 account, which covers every ecosystem app. You also have the right to lodge a complaint with the supervisory authority, the President of the Personal Data Protection Office (PUODO). To exercise these rights, write to .