Legal
Privacy Policy
Last updated: July 6, 2026
1. Overview
This Privacy Policy explains how codefyio ("codefyio", "we", "us", or "our") collects, uses, discloses, and safeguards information when you use our website, desktop application, and related services (collectively, the "Service"). It applies to visitors, account holders, and anyone who signs in to the Service.
This policy is written to meet the disclosure requirements of the platforms we distribute through and integrate with, including Apple's App Store Review Guidelines, Google's Play Developer Program & API Services User Data policies, and Microsoft Store Policies, as well as applicable data protection law (GDPR, CCPA/CPRA, KVKK).
2. Information We Collect
- Account data — name, email address, and authentication identifiers when you create an account or sign in.
- Sign-in provider data — a public profile identifier, username, and email address supplied by a third-party sign-in provider (see §4), limited to what that provider shares under the scopes we request.
- Content you create — code, prompts, and project files you generate or upload while using the Service, stored only as needed to provide the feature you invoked.
- Usage & diagnostic data — feature usage, crash logs, and performance metrics, collected in aggregate to keep the Service reliable.
- Device & log data — IP address, browser or OS version, and timestamps, collected automatically for security and abuse prevention.
- Billing data — if you purchase a paid plan, payment details are collected and processed directly by our payment processor; we do not store full card numbers.
We do not knowingly collect more data than is required to provide and secure the Service.
3. How We Use Information
- To provide, maintain, and authenticate access to the Service.
- To operate features you invoke (e.g. AI code assistance) and return their results to you.
- To detect, prevent, and investigate fraud, abuse, and security incidents.
- To communicate service updates, security notices, and — only with your consent where required — product updates.
- To measure aggregate product usage so we can fix bugs and prioritize improvements.
We do not sell your personal information, and we do not use your private code or prompts to train third-party models without your explicit opt-in.
4. Signing In (GitHub, and Third-Party Sign-In)
The Service currently supports signing in with GitHub OAuth. When you use this option, we receive your public GitHub profile (username, avatar, and the email address associated with your GitHub account) to create and authenticate your codefyio account. We do not receive your GitHub password.
If we add sign-in with Google, Microsoft, or Apple in the future, any data received through those integrations will be used solely to authenticate you and operate the Service, in compliance with the Google API Services User Data Policy (including its Limited Use requirements), the Microsoft identity platform terms, and Apple's Sign in with Apple guidelines, respectively. We will never use data obtained through a sign-in provider for advertising, and we will not share it beyond what is necessary to operate the Service.
7. Data Retention
We retain account and content data for as long as your account is active. Diagnostic and log data is retained only as long as needed for security and debugging purposes, and is then deleted or aggregated. When you delete your account (see §9), we delete or anonymize your personal data within 30 days, except where retention is required by law (e.g. billing records).
8. Your Rights & Choices
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Delete your account and associated personal data.
To exercise any of these rights, contact us using the details in §14.
9. Account & Data Deletion
You can request deletion of your account and personal data at any time, in-app or by emailing us (see §14). We will verify the request, delete your account data, and confirm once complete, generally within 30 days. Deletion is permanent and cannot be undone.
10. Children's Privacy
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact us and we will delete it.
11. International Data Transfers
We may process and store data in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) to protect data transferred internationally.
12. Security
We use industry-standard technical and organizational measures — encryption in transit, access controls, and regular security review — to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
13. Changes to This Policy
We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, provide additional notice (such as an in-app notice or email).
14. Contact Us
Questions, requests, or complaints about this policy or your data can be sent to privacy@codefyio.com.