Privacy Policy
This notice explains how dStruct processes personal data and what is stored on your device. It is provided for transparency and does not constitute legal advice.
Last updated: August 2026.
Who is responsible for your data
The data controller for dStruct is Max Kayander, operating the dStruct playground at dstruct.app (and related deployments).
For privacy requests or questions, email dstruct.info@gmail.com.
What personal data we process
Depending on how you use dStruct, we may process: account identifiers and profile data from GitHub or Google sign-in (name, email, avatar URL); playground projects, test cases, and solutions you save to the cloud; optional LeetCode account metadata if you link an account; profile images uploaded to our storage; server logs and security records from hosting; and, if you consent, anonymous analytics events from Vercel.
Legal bases (GDPR)
We rely on: contract and legitimate interest to provide the service and secure accounts; consent for optional analytics and any non-essential technologies; and legal obligations where applicable. Sign-in through OAuth is necessary to use cloud save features you request.
How long we keep data
Account and cloud project data are kept while your account exists or until you delete content. Server logs are retained for a limited period for security and operations. Analytics data is processed by Vercel according to their retention policies. Local storage entries persist until you clear them or change cookie settings.
Your rights
Depending on your location, you may have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. You may also lodge a complaint with your local supervisory authority.
You can withdraw analytics consent at any time via Cookie settings in the footer (Reject non-essential). Withdrawing consent does not affect the lawfulness of processing before withdrawal.
Sub-processors and service providers
We use service providers that may process data on our behalf, including: Vercel (hosting, analytics, edge configuration), GitHub and Google (OAuth sign-in), PostgreSQL database hosting tied to our deployment, Amazon Web Services S3 (profile image uploads), and Upstash Redis (entity indexing). Their privacy policies govern how they handle data.
International transfers
Data may be processed in the United States and other countries where our providers operate. Where required, we rely on appropriate safeguards such as standard contractual clauses offered by providers.
Cookies and similar technologies
We use cookies and local storage as described below. Non-essential analytics are off by default until you consent. You can change your choice at any time using Cookie settings in the site footer.
Strictly necessary cookies
NextAuth session and CSRF cookies are required for sign-in. A LeetCode session cookie is set only if you choose to link your LeetCode account.
Preferences (local storage)
We store your locale and last playground path in local storage to improve your experience. These values stay on your device and are not used for advertising.
Analytics (optional)
With your consent, we load Vercel Analytics and Speed Insights to understand how the site is used. These scripts are disabled until you accept non-essential cookies or enable them later via Cookie settings in the footer.
Cookie and storage inventory
The table below lists cookies and comparable browser storage used by dStruct. Analytics technologies load only if you accept non-essential cookies or enable them in Cookie settings.
| Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
next-auth.session-token / __Secure-next-auth.session-token | NextAuth.js | Keep you signed in | Session or until sign-out (see cookie name in browser) | Essential |
next-auth.csrf-token | NextAuth.js | Protect sign-in forms against cross-site request forgery | Session | Essential |
LEETCODE_SESSION | dStruct | Optional LeetCode account linking and GraphQL API access | Until you unlink or clear the cookie | Functional |
dstruct-cookie-consent (local storage) | dStruct | Remember your cookie and analytics choice | Until you clear site data or change settings | Essential (consent record) |
locale (local storage) | dStruct | Remember your selected language | Until you clear site data | Preferences |
lastPlaygroundPath (local storage) | dStruct | Restore your last opened playground project | Until you clear site data | Preferences |
_va / Vercel analytics identifiers | Vercel | Anonymous usage analytics and performance insights (only after consent) | Per Vercel policy (if accepted) | Analytics (consent) |
fonts.googleapis.com (Material Icons) | Load Material Icons used in the UI | Browser cache | Third-party resource |
Code execution
By default, your code runs in the browser (Web Workers / Pyodide). Saving projects and browsing cloud content uses our backend like any web app.
California residents (CCPA/CPRA)
If you are a California resident, you may have additional rights under the CCPA/CPRA, including the right to know what personal information is collected and to opt out of certain sharing. dStruct does not sell personal information. Analytics run only with your consent. Contact us using the email below to exercise your rights.