1. The short version
- DSAtlas tracks your coding practice from the public profiles you connect. We never ask for a coding platform password and never read the code you write.
- Your profile and leaderboard visibility start off. Nothing about you is shown to other students until you turn it on.
- There are no ads, no analytics, no tracking pixels and no third-party cookies. We do not sell or rent personal data.
- You can export your data, disconnect a platform or delete your account at any time from Settings.
- If you are under 18, a parent or guardian must agree before you use DSAtlas.
2. Who we are
DSAtlas (“DSAtlas”, “we”, “us”) runs this service and decides how and why your personal data is processed. Under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”), we are the Data Fiduciary. Where the EU or UK GDPR applies, we are the controller.
Contact us about anything in this policy at privacy@dsatlas.in. See Complaints and Grievance Officer for formal complaints.
3. What we collect
When you create an account
- Email address (required) and name (optional).
- If you sign up with email: a password, which we store only as a salted scrypt hash. We never store or see it in plain text.
- If you sign in with Google: your Google account ID, name, email address and profile photo link. We ask Google only for your basic profile and email address, and we do not keep Google access tokens.
- Whether you are 18 or older, or under 18 with a parent’s or guardian’s agreement. We ask only for that answer, never your date of birth.
- A record of each agreement you accepted: its version, its exact wording and the time.
What you choose to add
- A profile photo you upload (stored in our database, at most 150 KB), a short bio (up to 160 characters) and your public handle. The handle is generated for you and you can change it.
- College, graduation year, branch and section. All of these are optional and self-declared. We do not verify enrolment.
- Problems you mark as done or skip, and your practice-sheet progress. Manual completions are shown as self-reported and never count towards leaderboard points.
From the coding platforms you connect
When you connect LeetCode, Codeforces, GitHub or GeeksforGeeks, we store your username and profile link. We then read only information the platform makes public:
- Solved counts by difficulty and topic, and which problems you have solved.
- Submission results: the problem, the verdict (for example, accepted), the language and the time. We never read your source code.
- Contest history and ratings, your activity calendar, and on LeetCode your public ranking, badges, community statistics, display name and avatar.
- On GitHub: your public profile, links and profile README, which are used to confirm that the profile is yours.
For some platforms you can sign in to prove ownership instead of pasting a link. When you connect GitHub this way, GitHub shows you the access we ask for (read-only profile and email). We check your verified email addresses once, then discard the access token without storing it or the email list. Codeforces sign-in confirms your handle, and we do not store a Codeforces token either.
To confirm a profile is yours
- Verification codes or markers you place on your platform profile. Codes are stored only as a one-way hash, and a marker links to a DSAtlas page that shows nothing about you.
- When you click “Solve on …” for a problem we recommended: which problem and when. A solve shortly afterwards is one signal that the profile is yours. We keep these records for 30 days.
- If you ask for a manual review: the request, the outcome and any note the reviewer writes.
Generated while you use DSAtlas
- Sign-in sessions, the time you were last active (used to decide how often to refresh your profiles), which recommendations we showed you, and a log of sync attempts and errors.
- Security and audit records of important account events. Examples are connecting, verifying or disconnecting a profile, role changes and account deletion.
What we do not collect
Coding platform passwords or cookies, your source code, private profile data, payment details, precise location, contacts or advertising identifiers. Our database does not store your IP address or browser details. Our hosting provider does see them when delivering pages (see Who we share it with).
4. Why we use it
We process personal data only for the purposes below. Under the DPDP Act the basis is your consent (section 6), or a legitimate use permitted by section 7 where noted. For readers covered by the GDPR, the equivalent basis is shown in brackets.
| Purpose | Data used | Basis |
|---|---|---|
| Create your account and keep you signed in | Email, name, password hash or Google ID, sessions | Consent (contract) |
| Track your progress over time | Connected usernames, public platform data, dated snapshots | Consent (contract) |
| Compare you with your cohort and run opt-in leaderboards | Progress figures, college, batch, branch, visibility settings | Consent (contract) |
| Suggest what to solve next | Topics and problems solved, recommendations shown | Consent (contract) |
| Confirm a profile belongs to you, and stop impersonation | Markers, verification results, click-outs, review requests | Consent (legitimate interests) |
| Keep the service secure and investigate misuse | Audit records, sessions, sync logs | Legitimate use under law (legitimate interests, legal obligation) |
| Comply with the law and respond to lawful requests | Whatever the request lawfully requires | Legitimate use under law (legal obligation) |
We do not use your data for advertising, sell it, build marketing profiles, or use it to train AI models. Recommendations and rankings come from fixed, published rules. No automated decision is made about you that has legal or similarly significant effects.
5. Who can see your data
Other students
By default, nothing. Two separate switches in Settings → Privacy change that:
- Public profile (off by default). Anyone with your link can see your name or handle, photo, bio, college, branch and graduation year, connected usernames, verification status and progress. Public profiles ask search engines not to index them. Your email and section are never shown.
- Leaderboard (off by default). Signed-in students can see your name or handle, rank and points on cohort leaderboards.
With both switches off, your figures still count towards anonymous totals such as medians and your cohort’s size, but your name is not shown. Anyone who knows a handle can confirm it exists through a profile badge link. The badge shows a solved count only for public profiles.
College staff
DSAtlas may give verified staff (faculty, placement officers or college administrators) a role at their college. If you select that college, its staff can see:
- Group statistics for its students, such as counts, medians, activity and topic gaps. Groups with fewer than five connected students are hidden.
- Only if you turned on leaderboard visibility: your name, handle and total solved.
- Only if you ask for a manual ownership review, or someone disputes a profile you connected: your name, email address, the platform username and its profile link, so they can review it.
Choosing a college does not let it see anything else. If you leave the college blank, no staff see you at all.
DSAtlas administrators
A small number of administrators can see operational data, such as sync health and connected usernames, to run the service and resolve disputes. They are bound by confidentiality.
7. Where it is processed
The application runs in Mumbai, India. Some of our service providers, such as Google and Vercel’s global network, may process data in other countries. We transfer data only as the DPDP Act permits, and never to a country the Government of India has restricted. For readers in the EU or UK, these providers rely on recognised safeguards such as Standard Contractual Clauses.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account, profile, settings and consent records | Until you delete your account |
| Progress history and snapshots | Until you delete your account or that platform’s history. Raw copies of platform responses are cleared after 14 days |
| A disconnected platform | You choose when disconnecting: delete its history immediately, or keep it |
| Sign-in sessions | 30 days with “keep me signed in”, otherwise 12 hours. Expired sessions are deleted nightly |
| “Solve on …” click-outs | 30 days |
| Verification codes | 15–30 minutes, and stored only as a hash |
| Security and audit records, including connection events that name a platform username | 365 days from the event, even if you delete your account sooner. Indian rules require security logs to be kept for a year |
| Colleges you add to the college list | Kept. A college name is shared reference data, not personal data |
Deleted data can remain in our database provider’s backups until those backups expire on the provider’s schedule. It is not restored from them except to recover from a failure, and deletions are re-applied if that happens.
9. Your rights and how to use them
Under the DPDP Act you have the right to:
- Access a summary of your personal data and how we process it, and know who we have shared it with.
- Correct, complete or update it.
- Erase it, and withdraw consent at any time. Withdrawing is as easy as giving consent.
- Nominate someone to exercise these rights if you die or become unable to.
- Complain to us, and then to the Data Protection Board of India.
If the GDPR applies to you, you also have the rights to restrict or object to processing, and to data portability. You can complain to your local data protection authority.
Do it yourself, right away
- Settings → Account & data: download a JSON export, or delete your account.
- Settings → My Account: correct your name, photo, bio and college details.
- Settings → Connections: disconnect a platform. This stops all further reads, and you choose whether to delete its history.
- Settings → Privacy: turn the public profile and leaderboard off.
The export covers your profile, connected accounts, snapshots, topic statistics, sync history, practice progress and consent records. For anything it leaves out, such as submission-level detail, verification records or audit entries, email privacy@dsatlas.in. We will respond within the time the law requires. We may ask you to confirm your identity first, and we won’t charge you.
Withdrawing consent
Disconnect a platform to stop us reading it, or delete your account to end all processing. Withdrawing consent does not make earlier processing unlawful. We stop within a reasonable time and delete the data, except records the law requires us to keep (see How long we keep it).
10. Children
Anyone learning to code can use DSAtlas. If you are under 18, the DPDP Act treats you as a child. A parent or lawful guardian must agree to these terms and this policy on your behalf before you create an account. Sign-up asks your age first. If you answer “Under 18”, you cannot continue until you confirm that your parent or guardian has agreed. We rely on that confirmation, because we cannot check it.
We do not show advertising to anyone, and we do not track children or monitor their behaviour for advertising. Profiles start private, and visibility stays under the account’s control.
A parent or guardian can ask us to review or delete their child’s account at privacy@dsatlas.in. If we learn that a child’s account was created without that permission, we will delete it.
11. How we protect it
We protect your data with:
- HTTPS everywhere, and a strict Content Security Policy.
- Session cookies that scripts cannot read, and salted password hashes.
- Hashed verification codes.
- No stored platform access tokens, and database rules that block direct outside access.
- Staff access limited by role.
No system is perfectly secure. If a personal data breach affects you, we will tell you and the Data Protection Board of India as the DPDP Act requires. We will explain what happened and what you can do.
13. What you agree to at sign-up
Sign-up asks three separate things, and you cannot create an account until you answer all of them. None is pre-selected.
- Your age. One of: “I am 18 or older.” or “I am under 18. My parent or lawful guardian has read the Terms of Service and the Privacy Policy and agrees to my using DSAtlas.”
- The Terms and this policy. “I have read and agree to the Terms of Service and the Privacy Policy.”
- How we use your data.
I agree that DSAtlas may store the college details and coding usernames I add, read my public coding activity, and include it in cohort aggregates, which staff of a college I choose can see as group totals. My profile stays private unless I choose to share it.
Agreement version 2026-09-25-v3. Each time you connect a coding profile, you also confirm that it is yours and agree to its public activity being read (version 2026-09-25-v2). We record the exact wording, version and server time of each agreement.
14. Changes to this policy
When this policy changes, we update the effective date above. If a change affects what we collect or who can see it, we will show a notice in the app before it applies, and ask for your consent again where the law requires. Earlier agreements stay on record with their original wording.
15. Complaints and Grievance Officer
Grievance Officer, DSAtlas
Email: privacy@dsatlas.in
We acknowledge complaints within 24 hours and aim to resolve them within 15 days. If you are not satisfied with our answer, you can complain to the Data Protection Board of India.