larp-code privacy policy
Version PRIV-032-v1 · Last updated August 16, 2026
larp-code is a two-person NeetCode 150 accountability companion for adults. This public policy is available without signing in.
What we collect
We collect a verified email address, a required non-unique display name, account status, essential account timestamps, and the timestamp and version of your consent. When you use pairing and Challenges, we collect the Invitation terms, Challenge membership and lifecycle, problem identifiers from the pinned list, self-attested Solve and Solve Correction records, totals, and the derived pace and Grovekin condition needed to operate the shared experience. These Challenge fields are visible to the two Members in that Challenge.
The extension keeps a short-lived authenticated provider session and unfinished form drafts in device-local chrome.storage.local. It does not use chrome.storage.sync for account or Challenge data. Session and pending-command records are cleared on sign-out or successful deletion; an unfinished draft is cleared when its account is deleted.
We do not collect a birth date, password, username, alternate recovery contact, browsing history, page contents, contacts, precise location, advertising identifiers, analytics events, LeetCode credentials, source code, screenshots, or submission URLs. larp-code never fetches, scrapes, previews, or injects into NeetCode or LeetCode pages.
Why we use it
Member Data is used only to authenticate Members, operate and synchronize the shared Challenge and Pet experience, secure the service, and diagnose failures. We do not advertise, sell, profile, or use Member Data for unrelated enrichment or model training. Transactional email is limited to sign-in, Invitation, and account-security notices; the product sends no reminders, marketing, or tracking pixels.
Access and retention
You can read your own email and display name. Your email is your sole sign-in and recovery authority; we do not offer passwords, email changes, alternate recovery, or manual account transfer. You may sign out from the extension or permanently delete your Member Account after a fresh email confirmation. Deletion immediately ends shared commitments and replaces your identity with “Deleted Member” in a partner-visible terminal Challenge record.
Terminal Invitation details are logically unavailable after 30 days, and terminal Challenge records after 12 months, even if physical cleanup is delayed. Repository diagnostic records are retained for up to 30 days and security/audit metadata for up to 90 days; provider-managed backup copies are retained for no more than 30 days. The repository-owned retention ledger stores only these windows, never a usable credential or Challenge content. Uninstalling clears local data but does not delete the server Member Account.
Service providers and security
Supabase provides the hosted Postgres database, authentication, realtime transport, and edge-function infrastructure. The configured transactional-mail provider (Resend in production; Mailpit only in local development) delivers one-time codes and permitted operational notices. Chrome provides the device-local extension storage. Production communication uses encrypted HTTPS/WSS and least-privilege access. Diagnostic and security records contain no authentication tokens, OTPs, email addresses, Solve content, complete Snapshots, partner progress, or Pet state.
Human support access is disabled by default. A maintainer may access the minimum account or operational record needed for a Member-requested privacy response, security incident, legal obligation, or outage diagnosis; such access is least-privileged and logged. No support route can reveal an OTP, provider session, or reusable credential.
Contact
For a privacy question or deletion request, use the public larp-code support route. Do not post an email code, session token, source code, or private Challenge details in a public issue.