Privacy Policy
We take your privacy seriously. This policy explains what data we collect, why we collect it, and how we protect it.
Version
1.0
Last Updated
May 30, 2026
Effective
Immediately
Introduction
CodeSec ("we", "us", or "our") operates the CodeSec platform, an AI-powered security scanning service for startups and developers ("Service"). This Privacy Policy describes how we collect, use, and share information about you when you use our Service.
By accessing or using CodeSec, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
Information We Collect
Account Information
When you create an account, we collect your email address, name, and authentication credentials. If you sign in via OAuth (GitHub, Google), we receive the profile data provided by that service, including your email and display name.
Waitlist Information
When you join our waitlist, we collect your email address and optionally your name and use case description. This information is used solely to contact you about product access.
Scan Data
When you run security scans, we process and temporarily store the targets you provide (URLs, API endpoints, configuration details) and the resulting scan findings. Scan results are stored according to your plan's retention period (7 days on Free, 90 days on Pro, 365 days on Team).
Usage Data
We automatically collect information about how you use the Service:
- Feature interactions and page views
- Scan counts and types
- Credit consumption and billing events
- IP address, browser type, and device information
- Referral source and UTM parameters
Analytics
We use Vercel Analytics and may use PostHog to understand product usage patterns. These tools collect anonymized behavioral data. You can opt out of analytics tracking in your account settings.
Cookies
We use essential cookies for authentication and session management, and optional analytics cookies to improve our product. See our Cookie Policy for full details.
How We Use Your Information
- Provide, operate, and improve the Service
- Process and analyze security scans on your behalf
- Send transactional emails (scan completion, alerts, billing)
- Send product updates and security advisories (opt-out available)
- Respond to support requests and inquiries
- Enforce our Terms of Service and prevent abuse
- Comply with legal obligations
- Detect and prevent fraud and security incidents
Data Storage & Third-Party Processors
We use trusted third-party services to operate CodeSec. Each processor handles your data under their own privacy policies and our data processing agreements.
Supabase
Our primary database, authentication, and file storage provider. Your account data, scan results, and reports are stored in Supabase-managed PostgreSQL databases hosted on AWS. Supabase is SOC 2 Type II compliant.
Dodo Payments
We use Dodo Payments to process subscription billing. Your payment card details are handled directly by Dodo Payments and are never stored on our servers. Dodo Payments is PCI-DSS compliant.
AI Providers
Scan analysis and AI-powered insights are powered by AI providers including Anthropic (Claude) and OpenAI. Scan data is sent to these providers for analysis and is not used to train their models per our data processing agreements. We do not send personally identifiable information to AI providers beyond what is necessary for scan analysis.
Infrastructure
Our application servers run on cloud infrastructure (Hetzner Cloud, Vercel). All data is encrypted in transit using TLS 1.3 and at rest using AES-256.
Data Sharing
We do not sell your personal data. We share information only in these cases:
- With service providers listed above who process data on our behalf
- When required by law, court order, or government request
- To protect the rights, property, or safety of CodeSec, our users, or the public
- In connection with a merger, acquisition, or sale of company assets (with notice)
- With your explicit consent
Data Retention
We retain your data as follows:
Scan Results
- Free plan: 7 days from scan completion
- Pro plan: 90 days from scan completion
- Team plan: 365 days from scan completion
Account Data
Retained for the duration of your account. Upon account deletion, your data is permanently deleted within 30 days, except where retention is required by law.
Billing Records
Transaction records are retained for 7 years to comply with financial regulations.
Security
We implement industry-standard security measures to protect your data:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Row-level security policies on all database tables
- Regular security audits and dependency scanning (dogfooding CodeSec)
- Access controls with principle of least privilege
- Multi-factor authentication for internal systems
See our Security page for our full security practices and responsible disclosure program.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
- Withdrawal of Consent: Opt out of non-essential communications
To exercise your rights, email [email protected]. For GDPR-specific rights, see our GDPR page.
International Data Transfers
CodeSec operates from and stores data in the United States and European Union. If you are located in the EEA, UK, or other regions with data transfer restrictions, your data may be transferred to the US under Standard Contractual Clauses (SCCs) or other applicable legal mechanisms.
Children's Privacy
CodeSec is not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us at [email protected] and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or in-app notification at least 30 days before they take effect. Continued use of the Service after changes constitutes acceptance of the updated policy.
Questions about this policy or your data? We respond within 2 business days.
[email protected]