Privacy Policy
Last updated: March 13, 2026
Codalio ("Codalio," "we," "us," or "our") is dedicated to empowering developers to build, test, and deploy applications. We are committed to protecting the privacy and security of your data.
This Privacy Policy ("Policy") outlines how Codalio collects, uses, shares, and otherwise processes personal information ("Personal Data") from users ("User," "you," or "your") of our website, platform, and services (collectively, our "Services").
By using our Services, you acknowledge you have read and understood this Policy. This Policy is incorporated into our Terms of Service by reference.
1. Information We Collect
We collect Personal Data in three main ways:
A. Information You Provide Directly
When you interact with our Services, you may provide us with:
- Account Information: Your name, email address, username, password, and other contact details when you create an account.
- Payment Information: When you purchase a subscription, our third-party payment processor (e.g., Stripe) will collect your payment card details. We do not store your full payment card information.
- User Content: Any data you submit to the Services, such as code, prompts, text, configuration files, and other project information.
- Communications: Information you provide when you contact us for support, send us messages, or otherwise communicate with us.
B. Information We Collect Automatically
When you use our Services, we automatically collect:
- Log and Usage Data: Information such as your IP address, browser type, operating system, pages visited, timestamps, and error logs.
- Device Information: Information about the device you use to access the Services, such as device identifiers and operating system.
- Cookies and Tracking Technologies: We use cookies and similar technologies to operate and analyze our Services, including: Strictly Necessary Cookies (required for core functions like logging in and security); Analytics & Performance Cookies (e.g., Google Analytics); and Functional Cookies (e.g., theme or language preferences). You can manage your cookie preferences through our cookie banner or your browser settings. We honor Global Privacy Control (GPC) signals where required by law.
- Service Data & Telemetry: We collect operational metrics and telemetry (like feature usage, build events, and API calls) to monitor performance, bill for services, and improve the platform. This "Service Data" is processed by us for our own operational purposes.
C. Information We Receive from Third Parties
We may receive information about you from third-party services, such as payment processors (transaction confirmations and billing details) and third-party integrations (e.g., GitHub, Supabase, Google) when you connect them as authorized by you.
2. How We Use Your Information
We use your Personal Data to: provide and maintain the Services (including operating the platform, storing your code, processing payments, and authenticating users); communicate with you (service-related announcements, security alerts, billing invoices, customer support); improve and personalize the Services (analyze usage, fix bugs, develop new features); ensure security and fraud prevention; send marketing (product updates and offers, which you can opt out of at any time); and comply with legal obligations (record-keeping, lawful requests, enforcing our terms).
3. Legal Bases for Processing (EEA/UK/Swiss Users)
If you are in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we process your Personal Data on: Performance of a Contract (to provide the Services under our Terms of Service); Legitimate Interests (security, analytics, service improvement); Consent (for non-essential cookies, marketing—you may withdraw at any time); and Legal Obligations (laws, tax requirements, binding legal orders).
4. How We Share Your Information
We do not "sell" your Personal Data as that term is traditionally defined. We may share it with: Vendors and Sub-processors (e.g., AWS, Google Cloud, Stripe, analytics)—they are bound by contractual obligations to protect your data; Third-Party Integrations when you connect them (their use is governed by their privacy policies); Legal Requirements when we believe in good faith it's necessary to comply with law or protect safety and rights; and Business Transfers in connection with a merger, acquisition, or sale of assets.
5. Data Security
We implement industry-standard safeguards including encryption in transit (TLS) and at rest; role-based access controls and multi-factor authentication; and real-time security monitoring and logging. No system is 100% secure. We cannot guarantee the security of third-party providers, and you are responsible for keeping your account credentials confidential.
6. Data Retention
We retain your Personal Data for as long as necessary to provide the Services and fulfill the purposes in this Policy. When you terminate your account, we will delete your Personal Data within 30 days, except where required for legal compliance (e.g., billing records) or fraud prevention. Backups of your data may be retained for up to 90 days before being deleted.
7. Your Privacy Rights
Depending on your location, you may have the right to: access (request a copy of your Personal Data); correction (request correction of inaccurate or incomplete data); deletion (request deletion, subject to certain exceptions); restrict or object to processing; data portability (receive your data in machine-readable format); and withdraw consent. To exercise these rights, contact us at info@codalio.com.
A. Residents of California (CCPA): You have the right to know/access, delete, and correct your data. We do not "sell" your Personal Data. We may "share" data (as defined by the CCPA) with analytics or advertising partners; you can opt out by managing cookie settings or enabling Global Privacy Control. We do not collect "Sensitive Personal Information" beyond what's necessary for the service. We will not discriminate for exercising your CCPA rights.
B. Residents of EEA, UK, and Switzerland: You have the rights listed above and the right to lodge a complaint with your local data protection authority.
8. AI Model Training & Your Data
We do not use your private User Content (e.g., private code or prompts) to train general-purpose AI models for other customers. We may use anonymized and aggregated data, including Service Data and anonymized User Content, to improve performance and reliability, refine algorithms and train internal AI models, and produce aggregated analytics. You may have the right to opt out of having your data used for model training; contact info@codalio.com or check your account settings.
9. International Data Transfers
We are based in Canada, and your information will be processed in Canada. If we transfer Personal Data from the EEA, UK, or Switzerland, we rely on legal mechanisms such as the EU-U.S. Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs) to ensure your data is protected.
10. Children's Privacy
Our Services are not intended for individuals under 18. We do not knowingly collect Personal Data from anyone under 18. If we become aware that we have, we will take steps to delete that information.
11. Third-Party Links & Integrations
Our Services may contain links to or integrations with third-party sites (e.g., GitHub). We are not responsible for their privacy practices. We encourage you to read their privacy policies.
12. Changes to This Privacy Policy
We may update this Policy from time to time. We will notify you of material changes by posting the new Policy on this page and updating the "Last Updated" date, or by email. Your continued use after a change constitutes acceptance of the new Policy.
13. Contact Us
If you have questions, concerns, or wish to exercise your privacy rights, please contact us:
Email: info@codalio.com
