Privacy Policy

Last updated: 9 October 2026

Who we are

Awesome 42 is a non-commercial platform built by 42 students as part of the ft_transcendence project. It is operated by the project team listed in the repository README. This policy explains what personal data we collect, why we collect it, how long we keep it and which rights you have under the General Data Protection Regulation (GDPR).

What we collect

When you register with an email address we store your email, a display name and a password hash (argon2id). We never store your password in clear text. If you sign in with your 42 account we receive, with your consent, your public intra profile: login, display name, avatar, campus, coalition, cursus and validated projects. We store a snapshot of that profile to power features such as channels, peer search, leaderboards and the verified level shown to companies on the jobs board.

We also store the content you create on the platform: messages, channel memberships, friend requests, event registrations, game results and replays, code submitted to the arena, resources, questions, answers, votes, marketplace listings and job applications. Uploaded files (avatars, listing photos, attachments) are stored in our object storage.

For security and abuse prevention we keep server logs with IP address, user agent, request path and timestamp, and an audit log of sensitive actions (login, password change, role change, moderation decisions).

How we use it

Your data is used only to operate the platform: authenticate you, display your profile to other members, match you with players and peers, compute rankings, send notifications you opted into and let companies review the applications you decided to submit. We do not sell your data and we do not share it with third parties other than the 42 intra API (to read your profile) and, if you enable it, the Telegram or Discord webhooks you configure yourself. Optional AI features (assistant, moderation, recommendations) run on models hosted inside the platform; no data leaves our servers for that purpose.

Cookies

We use strictly necessary cookies only: an httpOnly session cookie and a refresh token cookie to keep you signed in, and a CSRF token. Usage statistics come from Umami, a self-hosted, cookieless tool that stores no personal data and never leaves our servers. Product analytics come from PostHog Cloud EU in cookieless mode: no cookies, no local storage, no person profiles. No cookie banner is required.

Retention

Account data is kept while your account exists. Server logs are kept for 30 days and audit logs for one year. When you delete your account, your profile, intra snapshot, files and private messages are removed; content you posted publicly (resources, answers) is anonymised rather than deleted so that threads remain coherent. Backups are rotated within 30 days.

Your rights

You can access, rectify, export (JSON) and permanently delete your data at any time from your account settings, without asking anyone. You may also object to or restrict processing and withdraw consent for the intra import; doing so disables the features that depend on it. You can lodge a complaint with your national data protection authority.

Security

All traffic is served over HTTPS. Passwords are hashed with argon2id, two-factor authentication is available, sessions are short-lived with rotating refresh tokens, and code submitted to the arena runs in an isolated sandbox with no network access.

Contact

For any privacy request or question, open an issue in the project repository or contact the team at the address listed in the README. We answer within 30 days.