Codie Privacy Policy
Effective and last updated: August 11, 2026
1. Who We Are and What This Notice Covers
Codie operates a marketplace for ready-made software, customization services, GitHub-connected quality review, publication maintenance, and optional runtime monitoring for web and mobile applications. This notice applies to Codie websites, accounts, marketplace services, quality-control services, monitoring, support, chatbot, and related administrative tools.
For privacy questions or requests, contact Codie through our Contact page or email sales@codiemarket.com. Depending on the service, Codie may act as a controller for account and marketplace data and as a processor or service provider for application telemetry submitted by a customer.
2. Information We Collect
- Account and identity data: name, email, hashed password, role, verification records, contact and address information, preferences, authentication and session records.
- Marketplace activity: products, submissions, applications, carts, collections, likes, reviews, licenses, purchases, customization requests, support communications, files and activity history.
- Payment and finance data: order and payment status, provider references, invoices, manual-payment evidence, refunds, disputes, payouts, proceeds, fraud-review evidence, accounting and audit records. Payment credentials are generally handled by payment providers rather than stored as card details by Codie.
- GitHub connection data: installation and account identity, selected repositories, repository identifiers, branches, commit identifiers, push events, access state and permission records.
- Quality-review data: temporarily retrieved source files and repository structure, dependency and code observations, findings, evidence, scores, reports, scan logs, configuration snapshots, processing costs and staff-review decisions.
- Runtime-monitoring data: error messages, stack frames, breadcrumbs, request paths and safe context, pseudonymous affected-user identifiers, tags, package information, traces, transactions, performance measurements, Web Vitals, release health, source maps, environments, releases and commit identifiers.
- AI and chatbot data: prompts, messages, bounded source or incident context, generated explanations, evidence, remediation proposals, proposed patches, feedback, model/provider metadata, usage and cost information.
- Device and usage data: browser/device information, IP-derived security information, page and feature interactions, referring/affiliate information, event URLs, cookies and similar storage.
3. GitHub-Connected Quality Lifecycle
When you connect GitHub, you authorize Codie to access only the repositories and branches you select. Codie may retrieve and temporarily clone an exact source revision, analyze it, store quality evidence and historical reports, respond to relevant changes, and support reviewed marketplace publication or ongoing maintenance. Revoking repository access stops future retrieval and monitoring, but historical reports and audit records may remain under the retention criteria below.
Routine quality review is advisory and may include false positives or false negatives. It is not a certification, legal opinion, penetration test, or guarantee that every defect will be found. Staff or authorized reviewers may inspect relevant evidence and selected source context when needed for review, support, security, or dispute handling.
4. Runtime Monitoring and Your End Users
For applications that you configure for monitoring, Codie can receive runtime errors and performance information and present normalized reports, affected-user counts, release context and alerts. Privacy-first defaults exclude session replay and are designed to scrub cookies, authorization headers, request bodies, query strings, IP addresses and direct identifiers. However, your SDK configuration and the content your application sends can affect what is collected, so you must not send secrets, payment credentials, health information or other sensitive data unless you have separately confirmed a lawful and supported configuration.
You are responsible for notifying your application’s end users, selecting a lawful basis, honoring their rights, configuring sampling and data fields appropriately, and verifying each web origin you monitor. Mobile and server applications use separately authorized relay credentials.
5. AI Assistance and Proposed Changes
Codie may send bounded, privacy-scrubbed chatbot, source, issue, trace and release context to external AI-processing services to generate explanations, investigations or remediation drafts. We may store the submitted snapshot, result, evidence, limitations, usage and cost metadata so the report is reproducible and auditable.
AI output can be incomplete or incorrect and must be reviewed and tested. A remediation proposal does not change your repository. Creating a draft change requires a separate permission grant, current access, an exact base revision, automated checks and your explicit confirmation. Codie does not automatically merge or deploy a proposed change.
6. How We Use Information
- Provide accounts, marketplace delivery, licenses, customization, quality review, monitoring, alerts, support and AI-assisted features.
- Process and reconcile payments, refunds, disputes, payouts and required financial records.
- Authenticate users, enforce permissions, prevent fraud and abuse, investigate incidents, back up approved evidence and maintain audit history.
- Improve reliability, usability, content, search discovery and service performance.
- Communicate service, review, monitoring, billing, security and legal notices.
- Comply with law, enforce agreements and protect Codie, users and third parties.
Where applicable, processing may rely on contract, legitimate interests, consent, or legal obligations. The available basis depends on the service, user relationship and local law.
7. Staff Access and Human Review
Access is limited according to role and purpose. Support personnel may access account and troubleshooting context; administrators may manage service and security operations; finance and fraud reviewers may inspect payment evidence; quality and human reviewers may inspect submissions and supporting source evidence; authorized chat reviewers may inspect conversations when support or safety requires it; and security or legal personnel may access records needed for incidents, claims or compliance. Sensitive actions are restricted and audited where the relevant workflow provides audit records.
8. Sharing and Service Providers
We disclose only information needed for the relevant purpose to categories of recipients such as hosting, database, storage, content delivery, email and authentication services; GitHub; payment and manual-payment providers; runtime monitoring and diagnostics services; AI and embedding-processing services; analytics and advertising services where consent permits; approved customization professionals; professional advisers; and authorities where legally required.
These providers may process data in other countries and may have their own terms. Codie uses contractual, access and technical safeguards appropriate to the service and applicable law, but no transfer or security method is risk-free.
9. Cookies, Analytics, Advertising and Consent
Essential storage supports authentication, security, cart and preference functions. Analytics, affiliate and advertising technologies may process device, browser, referral, page, product, checkout or purchase events and pseudonymous identifiers. Where consent is required, non-essential tracking should operate only after consent and can be withdrawn through available settings or browser controls. Withdrawal does not affect prior lawful processing.
10. Retention and Deletion
We retain information only while reasonably needed for the service, account or project state, security and fraud prevention, dispute resolution, legal obligations, accounting, audit, backups and establishment or defense of claims. The criteria differ by category:
- Temporary repository clones and transient workspaces are removed after the relevant operation, subject to failure recovery.
- Quality evidence, publication history, GitHub access history and administrative audits may remain to preserve review integrity and security history.
- Runtime event samples, aggregates, releases and source maps are retained according to project status, monitoring needs, storage limits and deletion workflows.
- Chat and AI snapshots remain while needed for conversation/report history, support, safety, audit and user-request handling.
- Financial, refund, dispute, payout, license and tax/accounting records may be retained for legal and reconciliation requirements.
- Provider and backup deletion can take additional time after Codie disables access. Deleted projects may retain a limited tombstone and immutable audit evidence.
An account or project deletion request does not require deletion of records that Codie must retain for legal, financial, security, fraud, dispute or audit purposes.
11. Your Choices and Rights
Subject to applicable local law, you may request access, correction, deletion, portability, objection or restriction; withdraw consent; change marketing or monitoring-email preferences; disconnect GitHub; revoke monitored origins; delete chats or projects; and complain to an appropriate authority. Codie may verify your identity and may deny or limit a request where an exception applies. Use the Contact page to submit a request.
12. Security and Your Responsibilities
Codie uses measures such as encrypted transport, role-based controls, repository scoping, bounded isolated analysis, secret redaction, audit evidence and controlled provider credentials. No system is completely secure. Protect your credentials, configure connected repositories and telemetry carefully, review proposed changes, maintain backups and report suspected misuse promptly.
13. International Processing, Children and Changes
Information may be processed where Codie or its service providers operate, subject to safeguards required by applicable law. Codie is not directed to children under 16. Contact us if you believe a child provided information. We may update this notice when services or legal requirements change; material changes may also be communicated in-product or by email.
14. Contact
For privacy questions or requests, use our Contact page or email sales@codiemarket.com.