Privacy Policy

Last updated: March 27, 2026

What Data We Collect

When you use Codey, we collect the following information:

  • Email address and account credentials (hashed)
  • Run briefs, task instructions, and automation settings you submit
  • Generated patches, reports, and project files
  • GitHub username and OAuth tokens (if connected)
  • Usage data: run history, credit usage, feature interactions
  • Memory preferences you set or that Codey learns from your runs
  • Payment information (processed by Stripe; we never store full card numbers)

How We Store Your Code

Code stored in your vault is retained for a maximum of 30 days after your last interaction with it. Active project code (used within the past 30 days) is stored indefinitely while your account is active. Code is stored encrypted at rest using AES-256 and transmitted over TLS 1.3.

Run and Session History

Your run briefs are stored to provide session history and to power features like memory-based personalization. We do not use your run briefs or generated output to train AI models. Run history can be viewed in your dashboard and deleted from the Settings page.

We Do Not Sell Your Data

Qira LLC does not sell, rent, or share your personal data with third parties for marketing purposes. We do not share your code, run briefs, or usage data with anyone outside of Qira LLC, except as required by law or as described in this policy.

Payment Processing

All payment processing is handled by Stripe. We store only the last four digits of your card, the card brand, and expiration date for display purposes. We never have access to your full card number, CVV, or bank account details. See Stripe's Privacy Policy for more information on how they handle your payment data.

GitHub Token Security

If you connect your GitHub account, your OAuth token is encrypted using AES-256 before storage. Tokens are scoped to the minimum permissions required (repo access). You can disconnect GitHub and revoke our access at any time from the Settings page, which immediately deletes the stored token.

Your Rights (GDPR and CCPA)

Regardless of where you are located, you have the following rights:

  • Right to access: Request a copy of all personal data we hold about you.
  • Right to correction: Update or correct inaccurate data.
  • Right to deletion: Request deletion of your account and all associated data. We will process deletion requests within 30 days.
  • Right to export: Export your code and data from the vault at any time.
  • Right to object: Opt out of non-essential data processing.

To exercise any of these rights, email privacy@codey.ai with your request. We will respond within 30 days.

Cookies and Analytics

We use essential cookies for authentication and session management. We do not use third-party advertising cookies. We use minimal, privacy-respecting analytics to understand feature usage. You can disable non-essential cookies in your browser settings.

Data Retention

Account data is retained while your account is active. After account deletion, all personal data, code, run briefs, and session history are permanently deleted within 30 days. Anonymized aggregate usage statistics may be retained indefinitely.

Changes to This Policy

We may update this policy from time to time. We will notify registered users of material changes by email. Continued use of Codey after changes constitutes acceptance.

Qira LLC · Phoenix, Arizona · Privacy questions? privacy@codey.ai