01Introduction
This policy explains how Codend ("Codend", "we", "us") collects, uses and protects personal data when you visit codend.dev, join the waitlist or use the Codend app at app.codend.dev (together, the "Services").
Codend is in a private beta. Some parts of the Services described below, such as running the agent on your repositories, become available as the beta opens. Where a section depends on that, we say so.
For the personal data described here, Codend is the data controller.
02Information we collect
Information you give us
- Waitlist. Your email address, the language of the site when you joined and which form you used.
- Account. Your email address and password, or the details your sign-in provider shares with us when you use Google or GitHub: your name, email address and profile picture.
- Profile and settings. Your display name, a profile picture you upload, custom instructions you write, and preferences such as language, appearance, dictation, keyboard shortcuts and notifications.
- Content you send to the agent. When the agent is available, the tasks you describe, files you attach and replies you send.
- Messages to us. Anything you include when you email us.
Information collected automatically
- Waitlist protection. When you join the waitlist we store a one-way hash of your IP address, not the address itself, to limit repeated sign-ups.
- Usage records. For each agent run: the model used, token counts, credits and the time. These power the Usage page in your settings.
- Technical data. Our hosting providers keep standard request logs such as IP address, browser type and timestamps to deliver and secure the Services.
- Site analytics. On codend.dev we use Vercel Web Analytics to count page views and see which pages, referring sites, countries and device types they come from. It works without cookies, doesn't follow you across sites and doesn't identify you. The Codend app doesn't use it.
Information from services you connect
If you connect GitHub or another integration, we receive the access the provider grants and the data needed for the tasks you ask for, such as repository contents for code changes. You choose which integrations to connect.
What we don't collect
We don't ask for sensitive data such as health or government ID information, and we don't use advertising trackers. Paid plans are not available yet, so we don't process payment details.
03How we use information
We use personal data to:
- Provide the Services: create your account, save your settings, run the tasks you request and show your usage.
- Run the waitlist: send your invite and occasional updates about Codend. Every email has a way to unsubscribe.
- Keep the Services safe: prevent abuse, spam and fraud, and debug problems.
- Improve Codend: understand which parts of the product work, using usage records rather than the content of your work.
- Meet legal obligations: respond to lawful requests and enforce our terms.
We do not use your code, repositories or the content you send to the agent to train AI models.
Legal bases
Where data protection laws such as the GDPR apply, we rely on: your consent for the waitlist and updates, which you can withdraw at any time; the performance of our contract with you to provide your account and the Services; our legitimate interests in keeping the Services secure and improving them; and legal obligations where they apply.
05Where your data is stored
Our database is hosted by Supabase in Seoul, South Korea. Our hosting and other providers may process data in the United States and other countries. When personal data moves across borders, we rely on safeguards that the law recognises, such as standard contractual clauses.
06How long we keep it
We keep personal data only as long as we need it:
| Data | How long |
|---|---|
| Waitlist email and IP hash | Until you unsubscribe, ask us to delete it, or 12 months after the public launch |
| Account, profile and settings | While your account is open, then deleted within 30 days of closing it |
| Usage records | While your account is open |
| Hosting logs | For the short periods our providers keep them |
We may keep limited data longer when the law requires it or to resolve disputes.
07Security
We protect data with encryption in transit, database rules that let each user read only their own records, credentials kept on the server, and limited access for our team. No system is perfectly secure, so if you find a vulnerability please tell us at privacy@codend.dev.
08Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy of it;
- correct data that is wrong or incomplete;
- delete your data;
- object to or restrict how we use it;
- withdraw consent, such as for waitlist emails, at any time;
- complain to your local data protection authority.
To use any of these rights, email privacy@codend.dev. We answer within 30 days and may need to confirm your identity first. You can change most settings yourself in the app, and every waitlist email lets you unsubscribe.
10Children
Codend is not meant for children under 16, and we don't knowingly collect their personal data. If you believe a child has given us data, contact us and we'll delete it.
11Changes to this policy
We'll update this policy as Codend grows. The date at the top shows the latest version. If a change is significant, we'll let you know by email or in the app before it takes effect.
12Contact us
Questions or requests about privacy go to privacy@codend.dev.