Draft — not yet in force. This document has 2 details still to be confirmed, shown in amber. It has not been reviewed by a lawyer and does not yet bind anyone.

Privacy Policy.

What personal data CoDuck collects, why we have it, who else sees it, how long we keep it, and what you can ask us to do with it. Written against the actual database, so where the product does not yet do something, this says so.

Effective August 13, 2026

1Who we are, and what this covers

This policy explains how CoDuck, Inc., a Delaware corporation ("CoDuck," "we," "us"), handles personal data. For this data, we are the controller — we decide why it is held and what happens to it.

It covers the CoDuck website, the application, the command-line tool, and our APIs.

It does not cover the sites you build with CoDuck. When your application collects data from its own visitors, you are the controller of that data and we are only your processor. That relationship is governed by a Data Processing Addendum, which we provide to business customers on request — email privacy@coduck.ai and we will send it. The privacy notice your visitors need is yours to write, not ours.

Questions, requests, or complaints: privacy@coduck.ai, or by post to REGISTERED POSTAL ADDRESS.

If you are in the EU or UK, our representative for the purposes of Article 27 GDPR is EU / UK ARTICLE 27 REPRESENTATIVE — appoint one, or confirm the exemption applies.

2What we collect

Account details. Your name, email address, and a hashed version of your password. If you upload an avatar, the image file. If you sign in with Google, your email address from that account.

Sign-in and security records. Every session records the IP address and browser user-agent it was created from, when it was last used, and when it ended. We keep these so that you can review and revoke your own sessions and so that we can investigate account compromise. Command-line tokens record the device name and last-used IP address the same way.

Your account activity. An append-only audit trail of sign-ins, two-factor changes, session revocations, team membership and role changes, and secret access — each with your email address, IP address, and user-agent.

Billing details. Your Stripe customer and subscription identifiers, your plan, your credit balances, and the state of your payments. We never receive your card number. Card details are entered on Stripe's own hosted checkout page and stay with Stripe.

What you create. Your prompts, your project source code, your chat history with the assistant, the environment variables and credentials you store (encrypted), and the domains and third-party accounts you connect. Some of this is personal data if you put personal data in it — that is your choice and under your control.

Generation records. For each build we keep the model used, tokens, cost, timing, and the prompt text, plus a replay of the assistant's steps. Values you set as environment variables are stripped out before that replay is stored.

Support and feedback. Anything you send us, including the free-text reason you give if you cancel.

How you found us. When you browse coduck.ai we record page path, referrer, campaign tags, device, browser, operating system, and an approximate country, region and city. The location is worked out on our own server from your IP address using a local database — the IP address itself is never written down for this purpose.

We do not knowingly collect special-category data — health, biometrics, political opinions, and so on — and you should not put it into prompts or project data without your own legal basis for doing so.

3Why we hold it, and on what basis

To provide the Service — creating your account, running generations, deploying and serving your sites, and syncing anything you connected. In GDPR terms this is performance of a contract with you.

To take payment and to keep the tax and accounting records the law requires of us — contract, and legal obligation.

To keep accounts and infrastructure secure — detecting compromised accounts, investigating abuse, rate-limiting, and bot protection on sign-up. This is our legitimate interest in running a service that is not overrun, and yours in not having your account stolen.

To support you when you write in, and to send transactional email about your account, your builds, and your billing — contract and legitimate interest.

To understand how the product is used and how people find itlegitimate interest. This is first-party and aggregate; we are looking at which pages work, not at you.

Marketing email goes only where you have opted in or where you are an existing customer and the message is about something similar — consent or legitimate interest depending on where you are. Every one has an unsubscribe link that works.

We do not use your prompts, code, or project data to train AI models, and we do not sell or share personal data for advertising. There is no advertising or cross-site tracking pixel anywhere on CoDuck.

4Who else sees it

We share personal data with the service providers that make the product work, and with nobody else except as described below. The complete, current list — what each one does and what it receives — is on our subprocessors page, which we update before a new provider starts handling customer data rather than after.

The ones that matter most for your data:

  • Anthropic — receives your prompts and project source code to perform generation, under commercial API terms that exclude training on submitted data.
  • E2B — runs your code in an isolated sandbox during a build, and receives project source while that build is running.
  • Advin Services LLC — provides the compute and storage that everything else runs on, in the United States.
  • Stripe — payments and subscriptions. Receives your billing contact details; holds your card details, which we never do.
  • Amazon Web Services — sends our transactional and lifecycle email, so it receives your email address and the content of those messages.
  • Cloudflare — bot protection on sign-up and DNS, so it sees your IP address and request metadata.
  • GitHub, Google, and Brave — only if you turn on repository sync, Google sign-in or Search Console, or when the assistant needs a web search.

We will also disclose personal data where we are legally required to, where it is necessary to establish or defend a legal claim, or to protect the rights and safety of our users or the public. If a law-enforcement request arrives that we are permitted to tell you about, we will.

If the business is sold or merges, data moves with it, and you will be told before it becomes subject to a different privacy policy.

5Where your data is processed

All platform data, all customer project data, and every deployed application run on infrastructure provided by Advin Services LLC in the United States. We do not currently offer EU data residency, and nothing of ours runs in an EU region.

That means if you are in the EU, the UK, or Switzerland, your personal data is transferred to the United States. We rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) for those transfers. Business customers who need them incorporated contractually should ask us for our Data Processing Addendum.

Some providers on our subprocessors list — Cloudflare and Google in particular — operate global edge networks, so traffic to them may be handled outside the United States.

We name the country and not the city on purpose. Our own network measurements suggest particular US cities, but that is inference rather than something our hosting provider has confirmed in writing, and this is not a document to put inferences in.

6How long we keep it

A job runs once a day and deletes data past the windows below. These are the real defaults, and the sweep genuinely runs — it is not a policy we wrote and never implemented.

  • Debug traces — 7 days. Only collected if you switch verbose debugging on.
  • Sign-in sessions — deleted 30 days after they expire.
  • Visitor analytics for your deployed sites — raw page views 90 days. Hourly aggregate counts are kept as the long-term record.
  • Error reports — 90 days, after which only the grouped summary remains.
  • Generation replays — the step-by-step assistant transcript is erased after 90 days. The build's cost and timing record is kept.
  • Email delivery records — 365 days.
  • Audit trail — 730 days.

What has no automatic expiry, stated plainly: your account and its contents for as long as it is open; your projects, chat history, and generation prompts; form submissions collected by your deployed sites; our own website analytics; and feedback you have sent us. These are kept until you or we delete them.

After you cancel, your sites serve for 30 days, then sleep. Nothing is deleted at that point — your projects and their data stay so that resubscribing restores them.

We then keep that data indefinitely, until you ask us to delete it. There is no expiry date on a cancelled account and no scheduled deletion: your projects, their databases and their contents simply remain. We are telling you this rather than quoting a tidy number because the number would not be true — nothing deletes them but a request.

Deletion is on request, and the request is handled by a person. There is no button for it. Email privacy@coduck.ai from your account address and we will erase your account and tear down its sites and databases. We will do it within 30 days of being asked.

Deleting a project removes its container, its entire database (including any accounts and data your application stored), its analytics, form submissions, email records, domains and connections. Some engineering records — the generation history for that project, including prompt text, plus deploy attempts and error reports — are not removed by that action today.

Where we are required to keep something for tax, accounting or legal-claim reasons, we keep it for as long as that requires, and no longer.

7Your rights, and how to use them

Depending on where you live, you have some or all of the following rights: to access your data, to have it corrected, to have it deleted, to restrict or object to how we use it, to portability, and to withdraw consent where consent is what we relied on. If you are in California, you also have the right not to be discriminated against for exercising them — and we do not sell or share personal data, so there is nothing to opt out of on that front.

What you can do yourself, right now: change your name, email and password; review every active session and revoke any of them; read your own audit trail; turn two-factor authentication on; remove your avatar; and delete any individual project.

Account deletion and full data export are handled by hand today. There is no button that does it — email privacy@coduck.ai from your account address and a person will do it, including tearing down your sites and databases. We would rather tell you that than describe a self-service flow we have not built. Building it is on the roadmap.

We respond within 30 days. We may ask you to confirm who you are first, which for a request from your account's own email address is usually just a reply.

You can complain to your data protection authority if you think we have got this wrong. In the EU that is the authority where you live; in the UK it is the Information Commissioner's Office. We would appreciate the chance to fix it first.

8Cookies and what we store in your browser

There is no cookie banner on CoDuck, because we do not set the kind of cookie that needs one. There are no advertising cookies, no cross-site tracking pixels, and no third-party analytics service — no Google Analytics, no Meta pixel, no session recording.

What we actually set:

  • `cduck_anon` — a first-party cookie lasting one year, holding a random identifier so we can tell repeat visits apart in our own analytics. Mirrored into local storage.
  • `cduck_session` and `cduck_first_touch` — browser storage recording the current visit and the page you first arrived on.
  • Your sign-in token — stored in your browser's local storage, not a cookie, and sent with each request to prove who you are.
  • Interface state — draft prompts, which tab you had open, cached chat history, and similar conveniences.
  • Cloudflare Turnstile — loaded on the sign-up page only, to tell humans from bots.

Clearing your browser storage signs you out and resets the analytics identifier. Nothing breaks permanently.

One honest engineering note: holding the sign-in token in local storage rather than a hardened cookie makes it reachable by any script that manages to run on the page. Moving it to an HTTP-only cookie is a known, documented, and intended improvement that has not shipped yet. It is listed as an open finding in the security pack we share with customers who ask.

9How we protect it

Secrets you store — environment variables, database credentials, connected-account tokens, and two-factor seeds — are encrypted with AES-256-GCM, each value bound to the record it belongs to so a ciphertext cannot be moved between records. Passwords are hashed with bcrypt and cannot be read by anyone, including us. API keys and recovery codes are stored only as hashes.

Every public endpoint is TLS 1.2 or 1.3 only. Each deployed project runs in its own container as a non-root user against its own database with its own credentials.

Our security page describes this in more detail, including what is still in progress. For an enterprise review we share a fuller pack that also lists our current open findings and the plan for each — we would rather hand you those than have you find them.

No system is perfectly secure. If you find a vulnerability, please tell us at security@coduck.ai — we aim to acknowledge within two business days.

10Children

CoDuck is not intended for children under 13, and we do not knowingly collect their personal data. We do not currently ask for a date of birth at sign-up, so this rests on the age you confirm by accepting our Terms of Service.

If you believe a child under 13 has given us personal data, email privacy@coduck.ai and we will delete it.

11Changes to this policy

When we change this policy materially we will update the effective date at the top and tell you by email or in the product before the change takes effect.

Earlier versions are available on request — a privacy policy that quietly rewrites its own history is not worth much.

Questions about this document? Email legal@coduck.ai. This version is effective August 13, 2026 and replaces any earlier version at coduck.ai/privacy.