1. Who we are
Codzee is operated by Codzee LLC, a Wyoming limited liability company, at 30 N Gould St Ste N, Sheridan, Wyoming 82801, USA (“Codzee”, “we”, “us”). This policy covers the codzee.io website, the Codzee dashboard, and the Codzee GitHub App (together, the “Service”). For any privacy question or request, contact support@codzee.io.
2. Our role: controller and processor
When an organization installs Codzee, the code, pull requests and information about its team members that we process on its behalf are Customer Data. For Customer Data, the organization is the controller and Codzee acts as its processor (or “service provider”): we use it only to provide the Service as the organization instructs. If you are a member of an organization that uses Codzee and have a request about Customer Data, we will direct it to that organization and help it respond.
For information about the people who sign in, pay, or contact us (account, billing and website information), Codzee is the controller.
3. Information we collect
From GitHub sign-in
Your GitHub username, name, avatar, email address, GitHub user ID and the organizations you belong to. Sign-in also grants read access to repositories you can see, which we use only to show you the repositories and activity you have access to. See our Security page for the exact permissions.
From the GitHub App (Customer Data)
- Code changes we review. We read each pull request’s changes and the surrounding code needed to review them. We process this to produce a review and do not keep copies of your repositories.
- What we keep to show review history: repository names and visibility, pull request titles and numbers, file paths, author and reviewer usernames, activity counts and timestamps, and the review itself: summaries, comments and findings. Review comments can quote short code excerpts and suggested fixes.
- Repository memory: patterns learned from comments your team dismisses, so reviews stop repeating them, and your review settings.
Team, billing and integrations
- Email addresses and roles of teammates you invite.
- Your plan, subscription status and Stripe customer ID. Card details are collected and stored by Stripe; we never see or store them.
- If you connect Slack: the workspace ID and name, and an access token that we store encrypted.
Usage, security and trial records
- How many reviews and Ask Codzee questions your organization uses, and their processing cost. We do not store the text of Ask Codzee questions or answers.
- Server logs, including IP addresses and request details, used for security and debugging.
- The GitHub user ID of the person who started each free trial, so that each person and each repository gets one trial.
- Anything you send us when you contact support, and the email you enter to open the demo, if you choose to.
4. How we use information, and our legal bases
For people in the European Economic Area, the United Kingdom or Switzerland, we rely on these legal bases:
- To provide the Service: reviewing pull requests, routing reviewers, the dashboard and reports (performance of our contract with you or your organization).
- To bill you and keep financial records (contract, and our legal obligations).
- To prevent fraud and abuse, including enforcing one free trial per person and repository (our legitimate interest in protecting the Service).
- To keep the Service secure and fix problems (legitimate interests).
- To support you when you contact us (contract and legitimate interests).
- To improve the Service using aggregated, de-identified usage metrics such as review counts and costs (legitimate interests).
- To comply with the law (legal obligation).
We do not use Customer Data to train AI models, we do not sell personal information, and we do not use it for advertising.
5. AI processing
To review a pull request or answer an Ask Codzee question, we send the relevant code changes and context to Anthropic’s API. Under Anthropic’s commercial terms, data sent through its API is not used to train its models. Anthropic may retain inputs and outputs for a limited period under its own policies, for example for trust and safety, after which they are deleted.
6. Service providers (subprocessors)
We share information only with these providers, and only as needed to run the Service, under contracts that require them to protect it:
| Provider | What they do for us | Location |
|---|---|---|
| Anthropic | AI models that review code changes and answer Ask Codzee questions | United States |
| GitHub | Source of repositories and pull requests; sign-in | United States |
| Stripe | Payments and subscriptions | United States |
| Resend | Sending team invitation emails | United States |
| Railway | Hosting the review service | United States |
| Vercel | Hosting the website and dashboard | United States |
| Neon | Database hosting | United States |
| Slack | Notifications, only if you connect a Slack workspace | United States |
We may also disclose information to members of your own organization through the dashboard, when required by law or to protect rights and safety, with your consent, or to a successor in a merger or acquisition, in which case we will notify you and this policy will continue to apply.
7. Cookies
We use only cookies that are strictly necessary: an encrypted session cookie that keeps you signed in, and security cookies that protect sign-in. Your browser may also store preferences such as the color theme. We do not use analytics, advertising or tracking cookies.
8. Where information is stored, and international transfers
We and our providers store and process information in the United States. When we transfer personal information from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and their UK and Swiss equivalents where required.
9. How long we keep information
- We keep your organization’s data while its account exists, including after you uninstall the GitHub App, so a reinstall continues where you left off.
- You can delete a repository’s review data at any time from the dashboard.
- To delete your whole account, email support@codzee.io. We complete deletion within 30 days. Deleted data leaves our database backups as they roll over on their normal cycle.
- We keep billing and tax records for as long as the law requires, and server logs for a limited period.
10. Security
We protect information with encryption in transit, encryption at rest by our database provider, encrypted storage of integration tokens, and access limited to the people who need it. Our Security page explains this in detail.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict some processing, and to withdraw consent where we rely on it. To exercise these rights, email support@codzee.io. We will verify your request and respond within the time the law requires. For Customer Data, we will refer your request to the organization that controls it and help it respond.
If you are in the European Economic Area, the United Kingdom or Switzerland, you also have the right to complain to your local data protection authority. We would appreciate the chance to address your concern first.
12. Additional information for California residents
In the last 12 months we collected these categories of personal information: identifiers (such as name, username, email and IP address), commercial information (plan and subscription records), internet or network activity (usage and server logs), and professional information (organization and team membership). We collect them from you, from GitHub, and from your organization, for the purposes described in section 4.
We do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics about you. You have the right to know, delete and correct your personal information, and we will not discriminate against you for exercising these rights. An authorized agent may make a request for you with your written permission. To make a request, email support@codzee.io.
13. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
14. Changes to this policy
We will post any changes on this page and update the effective date. For material changes, we will notify account owners by email or in the dashboard at least 30 days before they take effect.
15. Contact
Codzee LLC
30 N Gould St Ste N, Sheridan, Wyoming 82801, USA
support@codzee.io