Privacy Policy
- We collect what you type into the consultation form, and what we need to run sessions after that. Nothing else.
- Most of our students are under 18. The parent or guardian fills in the form and holds the account — we do not sign students up directly.
- We ask for the student's first name only. We do not need their surname, school, address, or date of birth.
- We do not sell personal information, and we do not run behavioral advertising or profile anyone for it.
- Students own the code they write, and nobody trains an AI model on it — not us, and not the AI vendors our mentors use.
- Sessions are not recorded. There is no recording of your student anywhere.
- This site sets no cookies and uses no third-party analytics. We count page views on our own server, with nothing that identifies you — so there is no consent banner, because there is nothing to consent to.
- You can ask to see, correct, or delete what we hold, at any time, by emailing support@donkeybuild.com.
Who we are
Donkey Build is a one-to-one software engineering mentoring service, operated from California and offered in the United States only.
We are responsible for the personal information described here. That means we decide what is collected and why, and we are the ones you hold responsible for it. Questions, requests, and complaints all go to support@donkeybuild.com, and a real person reads that address.
What this policy covers
This policy covers donkeybuild.com and the mentorship service itself — the consultation call, the sessions, and the code review that happens between them.
It does not cover third-party services your student may use while building, such as GitHub, a cloud provider, or an app store. Those services have their own policies and their own age requirements, and we cover that division of responsibility in section 13 of the Terms of Service.
What we collect
Everything below is either typed in by you or generated by running the service. We do not buy personal information, and we do not enrich what you give us from other sources.
- About the student
- First name, school year or grade, roughly how much they already code, a description of what they are building, what they are aiming at (university applications, a named competition, a real product), which areas they want help with, any deadline, and — optionally — a link to their repository. We do not ask for the student's email address: everything comes to you.
- About you
- Your name, your email address, your time zone and when sessions suit you, and how you heard about us.
- From running the service
- Scheduling and attendance, session notes written by the mentor, code review history, and any messages you or your student exchange with us. Sessions are not recorded — not audio, not video, not screen. What survives a session is the mentor's written notes and the review left on your student's own repository, and nothing else.
- Payment
- Nothing, today. The consultation is free and we are not yet taking payments, so we hold no billing details of any kind. When paid mentoring begins we will collect a billing name and email and a record of what was paid and when — card details will go straight to a payment processor and never reach our systems. We will name that processor here, and update this policy, before the first payment rather than after it.
- Automatically
-
Standard web server logs: IP address, browser and device type, the pages requested,
and the time of the request. Every web server keeps these; they are how a site is
operated and how abuse is stopped.
Separately, we count page views — which page, and which site linked you here. That counter holds numbers only and nothing that identifies you. See section 12.
One thing we ask of you. The box that asks what your student is building is a free-text field, so what goes into it is your choice. Please keep it to the project. It is not the place for health information, school records, or anything else sensitive about your child — we do not need it, and we would rather not hold it.
Why we collect it
- To match your student to the right mentor. This is what the project description and the "help needed" fields are for — a mobile build and an ML feature go to different people.
- To prepare for and run the consultation, and to schedule sessions in your time zone.
- To deliver the mentorship itself — session notes and review history are how a mentor picks up where the last session left off, and how anyone stepping in later can do so without your student starting over.
- To take payment and keep the accounting records we are legally required to keep.
- To keep students safe, including checking that our own safeguarding rules are being followed.
- To improve the service — which of the practice areas people actually ask for shapes what we build next. This uses aggregate counts, not individual profiles.
Students under 18
This is the section that matters most, so it is written plainly. Our students are typically in grades 9–12 and between 13 and 18 years old.
- The parent or guardian is the account holder. The consultation form asks for a parent's name and email, and the agreement is with the parent — not the student. See section 1 of the Terms of Service.
- We ask for the student's first name only. No surname, no date of birth, no home address, no school name. A first name and a grade is enough to teach someone.
- A parent can see everything we hold about their student, and can ask us to delete it, without giving a reason and without it affecting anything else.
- We never use a student's information for advertising — not our own, not anyone else's — and we do not build profiles for marketing.
- The service is not intended for children under 13. If we discover that we hold information about a child under 13 without verifiable parental consent, we delete it promptly.
We hold no contact details for your student at all. The consultation form does not ask for their email address or phone number, and we do not collect them later. Every message about your student goes to you, which is also what keeps the safeguarding rule in the Terms of Service — no private, off-platform contact between a mentor and a student — enforceable rather than merely promised.
Why we are allowed to hold it
Donkey Build is operated from California and offered in the United States only. We do not accept students living outside the US, so this policy is written against US federal and state privacy law rather than the European GDPR.
US law does not make us name a "lawful basis" the way European law does. The honest answer to why we hold each thing is short enough to give anyway:
- To deliver what you asked for — the consultation you requested, and the mentorship you have paid for.
- Because you told us to — the enquiry form itself, and any marketing email, which you can stop at any time.
- Because the law requires it — tax and accounting records.
- To keep the service working and safe — preventing abuse, and understanding in aggregate which parts of the service are in demand. This never extends to advertising profiles.
The California Consumer Privacy Act, as amended by the CPRA, sets thresholds — on revenue, and on how many people's data a business handles — and a service of our size is below them. We give you the rights it describes anyway. They are set out in Your rights below, and we treat them as binding on us whether or not a statute compels it. The same goes if you live in a state with its own privacy law — among them Colorado, Connecticut, Virginia, Texas, Oregon, and Montana. You get the same answer either way, and we will not ask you to prove which state law applies to you.
Who we share it with
We share the minimum necessary, with these categories of recipient:
- The mentor teaching your student, and anyone else brought in on a specific area. Mentors are bound by written confidentiality obligations and by our safeguarding rules.
- Google, for scheduling, sessions, and email — Google Calendar to book sessions, Google Meet to run them, and Google Workspace for the messages we send you.
- GitHub and Anthropic, who provide the AI tools our mentors use when reviewing code — GitHub Copilot and Claude, on business subscriptions under which neither company trains models on what we send. See "What we never do" below.
- A payment processor — not yet, because we take no payments yet. One will be named here before that changes.
- Professional advisers (accountants, lawyers) where they need it.
- Authorities, where we are legally required to disclose, or where we believe in good faith that disclosure is necessary to protect a child from harm.
If the business is ever sold or merged, customer information may transfer as part of it. We would tell you before that happened, and the buyer would be bound by this policy until it was replaced by one you were given notice of.
What we never do
- We do not sell personal information, and we do not share it for cross-context behavioral advertising — as those terms are defined under California law and its equivalents in other states. There is no advertising technology on this site at all, which is what keeps that true rather than merely intended.
- We do not use student work, code, or session notes to train machine learning models, and neither do the companies whose AI tools we use. Our mentors do use AI tools — GitHub Copilot and Claude — to help read and reason about code a student has already written. We use them only on Business, Team, or Enterprise subscriptions, the plans under which GitHub and Anthropic do not train models on what is sent to them. We never use them to write code for a student, and we never send a student's personal details to them.
- We do not publish a student's work without explicit, separate, opt-in permission, and that permission can be withdrawn.
- We do not contact students outside the agreed channels, and mentors do not hold private off-platform contact with a student. See the safeguarding clause in the Terms of Service.
- We do not keep a database of enquiries. The consultation form sends us an email and writes to nothing else. See section 9.
How long we keep it
Your enquiry lives in one inbox and nowhere else. When you send the consultation form it becomes an email to us. It is not written to a database, because we do not run one for enquiries — there is no copy in a data warehouse, no analytics record of what you typed, and no backup of a table that does not exist. If that ever changes, this section changes first and the effective date at the top of this page moves with it.
- Enquiries that do not become clients — deleted from that inbox 12 months after the last contact.
- Active clients — session notes, scheduling and review history are kept for as long as the service is running, plus 24 months afterwards.
- Financial records — as long as tax law requires, which for a California business is generally seven years.
- Session recordings — there are none. We do not record sessions, so no recording of your student exists to keep, to request, or to delete.
When a retention period ends we delete the information or irreversibly anonymize it. Anonymized counts — how many enquiries mentioned mobile, for example — may be kept indefinitely, because they are no longer about anyone.
How we protect it
The site is served over HTTPS. Access to enquiry and session data is limited to the people who need it: the mentor teaching your student, and whoever is running operations. Everyone with access is bound by written confidentiality obligations.
The strongest protection here is not a security control, it is a decision: we do not keep a database of enquiries. Data that was never collected cannot be breached, subpoenaed, mislaid by a supplier, or found by whoever buys the company. That is why the consultation form writes to an inbox and stops there.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your information, California law requires us to tell you in the most expedient time possible and without unreasonable delay — and we will, in plain language, saying what was taken and what you should do about it. Where a breach affects more than the number of California residents the law sets as a threshold, we also notify the California Attorney General.
Your rights
Wherever you live, you can ask us to:
- Show you what we hold about you and your student.
- Correct anything that is wrong.
- Delete it, subject to records we are legally required to keep.
- Export it in a portable format.
- Stop a particular use, including withdrawing consent to marketing.
Email support@donkeybuild.com. We will acknowledge your request within 10 days and answer it within 45 days — the timetable the CCPA sets, which we hold ourselves to as a matter of policy. If a request is genuinely complicated we may take one further 45 days, and we will tell you before we do rather than let the deadline pass quietly. We will not charge you for asking, and we will not make the service worse because you did. If you are unhappy with our response you can complain to the California Attorney General, or to the California Privacy Protection Agency.
Cookies, and how we count visits
This site sets no cookies at all. Not analytics cookies, not advertising cookies, not a cookie to remember what you decided about cookies. Nothing is written to your device by this site, which is why there is no consent banner on it: there is nothing to ask you for.
We used to plan on Google Analytics. We removed it. It set cookies that lasted two years, it sent your visit to an advertising company, and it required a banner interrupting every parent on arrival — all so we could learn how many people read this page. We can learn that a much cheaper way.
What we count instead
When you open a page, your browser sends us two facts: which page it is, and which site linked you here, if any. We add one to a counter for each and that is the end of it. No third party is involved — the counter is our own, running on our own server.
Nothing identifying travels with that message. There is no cookie, no stored identifier, and no fingerprint, so two visits from you are indistinguishable from visits by two different people. That is a property of how it is built, not a promise about how we behave: we could not tell your visits apart if we wanted to, and we could not reconstruct it later, because what we keep is a number rather than a list.
The referring address is reduced to a bare host name — google.com, not the
full link, which can contain whatever someone typed into a search box.
Do Not Track, and Global Privacy Control
Some browsers send a Do Not Track or Global Privacy Control signal, meaning you do not want to be tracked across websites. We honor both — if your browser sends either, we do not count your visit at all.
We could reasonably argue those signals do not apply to a counter that identifies nobody. We honor them anyway, because a promise that only holds when it costs nothing is not worth writing down.
Server logs
Separately from the counter, our web server keeps standard logs — including IP addresses — as described in section 3. Every website has these; they are how a server is operated and how abuse is stopped. They are not joined to the visit counter, and they are not used to build any profile of you.
Where your data is held
We are a US business serving US families, and your information is held in the United States — in Google Workspace, which is where enquiries, scheduling and correspondence live. Because we do not accept students living outside the US, there is no cross-border transfer to protect, and no mechanism such as Standard Contractual Clauses for us to rely on. If that ever changes, this section changes with it, and we will tell you before it does rather than after.
Visit counts never leave our own server, because the counter is ours rather than a third party's. That is the simplest way to avoid the question entirely.
Changes to this policy
If we change this policy we will update the date at the top and, where the change actually affects you, email you about it before it takes effect. We will not make a material change quietly and rely on you re-reading the page.
Contact us
support@donkeybuild.com — for anything on this page, including access and deletion requests.
Email is the only channel we ask you to use, and it is the fastest one — it reaches a person rather than a queue.