Privacy Policy
This policy describes what personal data Code4 collects, why, who else processes it, how long it is kept and how you can have it removed. Code4 is responsible for it.
Last updated
Scope
This Privacy Policy applies to the website at code4.space, to the hosted Code4 service and to the emails you send us. In it, "we", "us" and "our" mean Code4.
When your organization runs Code4 on its own infrastructure, the data stays on that infrastructure and your organization decides how it is handled. In that case this policy covers only what reaches us directly, such as support emails, access requests and billing details.
Our role
For the content your organization puts into the hosted service, we act on behalf of your organization, which decides what goes in and who can see it. In the terms of the GDPR, your organization is the controller and we are its processor.
For account details, billing records, access requests, support emails and the logs we keep to run and secure the service, we are the controller.
What we collect
Account data: your name, email address, organization, role and the sign-in details needed to authenticate you.
Workspace content: what your team puts into the service, including repositories, issues, code reviews, documents, chat messages, files, pipeline logs and artifacts, and the prompts and results of the AI features.
Call data: where calls are recorded, the audio, the transcript and the summary of the call, together with the names of its participants.
Usage and log data: IP address, browser and device type, pages and actions in the service, timestamps and error reports, collected by our servers as you use the service.
Billing data: the billing contact, company name and address, tax identifiers where required, and the history of payments. Card details are collected and stored by our payment processor; we see only the card type, the last four digits and the expiry date.
Access requests: when you ask us for access, the name of your organization, how many people will use Code4 and the email address or Telegram handle you give us.
Correspondence: what you write to us by email and our replies.
This website
The code4.space website sets no cookies and loads no analytics, advertising or tracking scripts. Its fonts are served from our own server.
The only thing the website stores in your browser is your scroll position, kept in the session storage of the browser tab so that a reloaded page opens where you left it. It never leaves your device and is cleared when you close the tab.
The servers that deliver the website keep standard request logs, such as IP address, browser type, time and page requested, to keep the site secure and working.
How we use it
We use personal data to provide and operate the service; to run the AI features you use; to answer access requests and support questions; to bill for subscriptions; to keep the service and its users secure and to prevent abuse; to send notices about the service, your account and changes to our terms; to fix errors and improve reliability; and to meet our legal obligations.
We do not use workspace content for advertising, we do not build advertising profiles, and we do not use your content to train AI models.
Where the GDPR applies, we rely on the performance of our contract with you or your organization, on our legitimate interests in running a secure and reliable service, on legal obligations, and on consent where the law requires it.
Who else processes it
We use a small number of service providers, each bound by a contract to process personal data only on our instructions and to protect it.
Hosting: our cloud infrastructure provider runs the servers, databases and file storage of the hosted service.
AI model providers: only what the AI features touch leaves our infrastructure. The assistant, agent runs and call summaries send their input to Anthropic, speech goes to Deepgram for transcription, and the search index is built with an OpenAI embedding model. Everything else stays in our database and our file storage. An administrator can switch the AI features off.
Payments: our payment processor, Stripe, handles card payments and keeps card details.
Email: our email provider carries the messages you send us and the notices we send you.
We may also disclose personal data when the law requires it, to protect the rights, safety and property of our users, the public or ourselves, or as part of a merger, acquisition or sale of assets, in which case the recipient remains bound by this policy.
We do not sell your data
We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are used in the California Consumer Privacy Act.
How long we keep it
Account data and workspace content are kept while your organization has an active subscription. After the subscription ends, your organization has 30 days to ask for an export, and then we delete the data from the service.
Usage and log data are kept for up to 90 days, unless we need them longer to investigate a security incident.
Billing records are kept for as long as tax and accounting laws require.
Access requests are kept until we have answered them and for up to 12 months after that, unless your organization becomes a customer. Correspondence is kept for as long as it is needed to answer you and to keep a record of the request.
Your organization can delete individual items at any time within the service, and you can ask us to delete your personal data sooner, as described below.
Security
Traffic to the website and the service is encrypted in transit. Access to content is controlled by the permission model of the service: search runs the same permission check the screens do, and access to production systems is limited to the people who need it to run the service.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.
Your rights
Depending on where you live, you may have the right to know what personal data we hold about you and to get a copy of it, to have it corrected or deleted, to receive it in a portable format, to object to or restrict certain processing, and to withdraw consent you have given.
Residents of California have the right to know, to delete and to correct personal information, and the right to opt out of its sale or sharing; since we do not sell or share it, there is nothing to opt out of. We will not treat you differently for using these rights.
To make a request, email us from the address on your account, or tell us how we can verify that the data is yours. We answer within 30 days. If the data belongs to workspace content your organization controls, we pass the request to your organization and help it respond.
If you are in the European Economic Area or the United Kingdom, you can also complain to your local data protection authority.
International transfers
We and our service providers may process personal data in the United States and in other countries whose data protection laws differ from yours. Where the law requires it, we protect those transfers with appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission.
Children
Code4 is a service for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
We may update this policy. The date at the top of this page shows when it last changed. If a change materially affects how we use your personal data, we will tell you by email or in the service before it takes effect.
Contact us
Write to support@code4.space.