What a tournament keeps, and who sees it.
How CodeKairo Battles handles the data that entering or hosting a tournament produces — in plain language, checked against what the site actually does. Effective 1 October 2026.
The short version
- Battles uses your CodeKairo account and adds only what a tournament needs: your registrations, check-ins, team places and the attempts you submit.
- An organizer sees your CodeKairo name, your avatar and the domain of your email address — never the address itself. While a knockout match is being played, the organizers can watch both players' code as it is typed.
- Anyone with the link can open a knockout's bracket, which shows players' usernames and avatars, and a contest's scoreboard, which shows team names. Neither page is listed in search engines.
- Your code is run by a code-execution service to judge it and is never published.
- No advertising, no analytics script, no sale of data. Write to support@codekairo.com for a copy of your data or to delete it.
1. What this covers
This policy covers CodeKairo Battles — battles.codekairo.com, the site on which colleges, clubs and companies host coding tournaments — and the parts of the CodeKairo API it uses. Battles is run by CodeKairo and signs you in with a CodeKairo account, so the account itself — your email, name, password and profile — is described in CodeKairo's privacy policy. This page covers what taking part in a tournament, or hosting one, adds to it.
We do not sell personal data, we show no advertising, and we collect only what running a tournament needs.
2. What we collect
- Your account. Battles signs you in with your CodeKairo account — email and password, Google or GitHub. It reads your username, display name, avatar, rating and email address from that account and asks for nothing more.
- Registrations. The tournaments you register for, whether the organizer approved each registration, when you checked in and the seed you were given. An invite code you type is checked against the tournament's and not kept.
- Teams. For an ICPC-style contest, the team an organizer entered you in and its name. Organizers name members by CodeKairo email or username; the list is matched to existing accounts, and the addresses in it are not stored separately.
- What you submit. Every attempt in a match or a contest: the code, the language, the verdict and the time. Each is an ordinary CodeKairo submission — that is what credits your profile — linked to the tournament it was made in. A knockout match also records each side's best number of hidden tests passed and when it was reached.
- Organizations. If you host: the organization's name, kind, website, city and description as you enter them, the accounts that manage it, and the tournaments you draft — their settings, problems, eligibility rules (allowed email domains and the invite code among them) and teams.
- Technical data. Your IP address, used for rate limiting and to stop abuse, and the errors the API runs into, with the page and browser they happened on. Battles runs no analytics or advertising script and records no page views of its own.
- Cookies and storage. A session cookie (__session) set by api.codekairo.com keeps you signed in on both sites. On battles.codekairo.com, your browser's local storage keeps your session token, your theme and how you arranged a room's panels; the open tab keeps your unsent code and whether you have already seen a match's result. There are no advertising or cross-site tracking cookies.
3. What it is used for
- Running the tournament. Checking who may enter, seeding the bracket, judging every attempt, deciding matches, ranking the scoreboard and recording where everyone finished.
- Your CodeKairo profile. Crediting accepted solves to your solved count, heatmap, streak, roadmap and XP, marking the problems you solved in a tournament, and listing your tournaments and placements on your profile.
- Organizers. Showing the people who run a tournament who registered for it, so they can check eligibility and approve entries — with the email domain in place of the address.
- Verification. Before an organization's first tournament goes public, and again after its details change, CodeKairo staff review the organization's details and the username and email of the account that created it. Changes to a public tournament are reviewed by CodeKairo staff before players see them.
- Keeping it safe. Rate limits, spotting abuse of the judge, and looking into a report about a tournament or an organizer.
- Email. Sign-in codes and password resets for your account, and reminders about a tournament you are entered in: one 24 hours and one an hour before the start, plus any its organizer or CodeKairo sends — at most five more, never two within an hour. Each reminder also appears in your CodeKairo notifications. Organizers press a button; they never see your address.
4. What an organizer sees
Organizers are the accounts that manage the organization hosting a tournament. For each registration they see your CodeKairo username (or your name, if you have no username), your avatar, the domain of your email address — college.edu, not your address — the registration's status, your check-in and your seed. For a contest, they see the teams they entered and each team's results.
They can open a knockout match to watch it: the number of hidden tests each side has passed and, while the match is being played, each player's code as it is typed — relayed to them live, kept only in the server's memory for up to 30 minutes after the last change and never saved. Your opponent never sees your code, and the match room reminds you that the organizers can. Organizers do not see your email address, your other submissions or anything else on your CodeKairo account.
Organizers agree to use what they see only to run their tournament. What you tell an organizer outside Battles — in a form of their own, a group chat, an email — is between you and them.
5. What is public
- Public, and listed in search. A published tournament's page — its name, organizer, dates, rules, who may enter and how many places are taken — and a verified organization's page. Neither names a player or a team.
- Public to anyone with the link, not in search. A knockout's bracket, which shows each player's CodeKairo username and avatar, their seed and every match's result, and an ICPC-style contest's scoreboard, which shows team names and their results problem by problem — not the members. Both pages tell search engines not to list them.
- Private. Your email address, your code, and everything about a tournament that is still a draft, is waiting for CodeKairo to approve its changes, or belongs to an organization CodeKairo has not verified.
6. Who else handles it
These services process data on our behalf to run Battles. Each sees only what its job needs, and none may use it for anything else.
- Hosting. Cloudflare serves battles.codekairo.com from its edge network and, like any host, keeps request logs. The API, the database, the cache and their backups run on Amazon Web Services, on one server in Mumbai, India.
- Code execution. The code you submit, with the test input, is sent to Paiza.IO, a code-execution service operated from Japan, which compiles and runs it and returns the output to be judged. Nothing else about you goes with it.
- Sign-in. Google and GitHub, when you choose to sign in with them.
- Email. Brevo delivers sign-in codes, password resets and tournament reminders to the address on your account.
7. Where it lives
Your tournament data is stored in India, on the server in Mumbai described above. Code you submit is processed in Japan while it runs, and Cloudflare serves pages from the part of its network nearest you. If you use Battles from outside India, your data is transferred to India to be stored.
8. How long we keep it
Tournaments, registrations, matches, scoreboards and the attempts behind them are kept for as long as the account and the tournament exist: a result is the reason to have played, and it stays on your profile and in the tournament's record. Server logs and error reports are kept only as long as they are useful for running the service, and database backups for seven days.
Leaving a knockout before it starts deletes that registration. An organizer can remove a team they entered until the contest starts. When a CodeKairo account is deleted, its registrations, team places and tournament attempts are deleted with it; a bracket keeps its matches without naming the account. An organizer can delete a tournament that has not started, and its registrations are deleted with it. An organization and the tournaments that have run are kept until its organizers ask us to remove them.
9. What you can do
- See and correct. Your registrations and their status are on the tournaments page, your results on each tournament's page and on your CodeKairo profile. Your name, username and avatar are edited on your CodeKairo profile.
- Leave. Leave a knockout at any time before it starts, from the tournament's page. To leave a contest team, ask the organizer who entered it.
- Export or delete. Write to support@codekairo.com and we will send you a copy of your data, or delete your account and everything attached to it, after confirming it is you.
- Organizations. Organizers edit their organization's details from the host dashboard; a verified organization's changes are checked again before its tournaments are public again. Removing an organization goes through support.
- Complain. Tell us first, and we will put it right. You may also raise it with the data-protection authority where you live; for users in India, the rights under the Digital Personal Data Protection Act, 2023 apply.
10. How it is protected
Battles signs you in through CodeKairo: passwords are stored as bcrypt hashes, sessions are signed tokens that a password change or a sign-out revokes, every connection is HTTPS and requests to the API are signed. The judge runs code in an isolated sandbox, a tournament's problems stay hidden from players until it starts, and organizers see email domains rather than addresses by design.
No system is perfect. If we learn of a breach that affects you, we will tell you what happened and what we are doing about it as soon as we reasonably can.
11. Children
Battles is built for college students and working developers and is intended for people aged 18 or over. If you are under 18, take part only with the consent of a parent or guardian — and an organizer running an event for school students should make sure that consent exists. If we learn we hold an account belonging to a child without it, we will delete it.
12. When this changes
When Battles starts collecting something new, or sends data to a new service, this page changes and the date at the top moves. A change that materially affects you is announced on the site before it takes effect.
13. How to reach us
For anything about your data — a copy of it, a correction, deletion, or a question this page does not answer — write to support@codekairo.com. We reply from the same address and confirm it is you before acting on an account.