Policy
Privacy policy
Draft - not yet reviewed by counsel
Prepared September 20, 2026 for the planned codeplus1 consumer service, including its US launch. Effective date: [EFFECTIVE DATE]. Responsible operator/controller: [LEGAL OPERATOR NAME], [ENTITY TYPE AND JURISDICTION], at [BUSINESS MAILING ADDRESS]. Privacy contact: [PRIVACY EMAIL]. Complete these details before publication. This forward-looking draft describes contemplated categories of processing, not a representation that every listed feature or provider is active. The published notice must accurately describe the offering to which it applies.
1. Scope
This Privacy Policy explains how codeplus1 ("we," "us," or "our") collects, uses, discloses, and retains personal information through its applications, websites, hosted AI features, and related services (the "Service"). It covers account holders, visitors, people who contact us, and people whose information is included in content submitted through the Service. Actual processing depends on the features used, permissions enabled, interactions with us, and applicable law.
Processing may occur on your device, our infrastructure, and through service providers. The Service is not necessarily on-device-only, anonymous, or zero-retention. This policy is a notice, not blanket consent to every processing activity. We obtain separate consent or provide additional notices where required. A separately agreed business data-processing agreement may govern processing for an organization; it does not automatically apply to a personal account.
2. Information we collect and its sources
- Account and authentication information: identifiers, email address, display name, account settings, sign-in and verification information, and profile information made available by your chosen sign-in method. Sources include you and authentication providers. Enter credentials only into designated secure forms.
- Input and captured context: prompts, questions, screenshots or selected screen regions, visible text and code, files or project material you provide, audio you enable us to receive, transcripts, conversation context, and related metadata such as timestamps, source labels, and capture or processing status. Sources include you, your device, and integrations you authorize. Content may include other people's information, confidential material, or sensitive information visible or audible in the selected context.
- Generated and derived information: responses, solutions, summaries, transcripts, reconstructed context, inferred task requirements, revisions, feedback, and records linking a result to its input or processing attempt. These may contain personal information or inferences from the original content.
- Transaction information: purchase and subscription details, entitlements, billing contact information, transaction and invoice identifiers, payment status, refunds, and dispute or fraud information. Sources include you, purchase platforms, and payment providers. Providers generally collect full payment credentials directly; we may receive limited payment-method and transaction details needed to manage your purchase.
- Technical, usage, and security information: IP address and network information, browser and app version, device and operating-system information, session or request identifiers, feature activity, usage volumes, model-processing and cost records, errors, diagnostics, and security or authentication signals. Sources include your interactions, our infrastructure, and delivery or fraud-prevention providers. Collection does not mean every identifier is permanently retained or linked across services.
- Communications and requests: support messages and attachments, surveys or feedback, cancellation and privacy requests, consent and opt-out records, misuse reports, and relevant information supplied by complainants, payment providers, or other parties involved in a dispute. We may request proportionate information to verify authority or investigate a concern.
Enable only the sources you intend to share. Avoid including passwords, private keys, payment details, regulated health information, or other highly sensitive material in ordinary session content. If sensitive information is incidentally included, applicable protections and lawful-basis requirements still apply; our Terms do not waive our duties concerning it.
3. Capture, audio, and integrations
Features may capture, extract, transmit, or analyze context while enabled, rather than only when you explicitly request an answer. Processing can include screen images, recognized text, contextual state, audio segments, transcripts, and follow-up exchanges. Feature controls and device permissions govern access. Turning off a source stops new collection through that source, subject to normal completion of work already initiated; it does not automatically recall submitted information, end every other enabled source, or delete prior records.
Depending on the feature, content may be buffered locally, temporarily staged, or stored remotely to provide history, maintain continuity, reproduce a result, investigate errors or abuse, and support section 4's purposes. Raw media, derived text, outputs, and processing records can have different retention periods. We do not promise that all information remains on your device or that no screen or audio content is stored. Available history controls may not expose every operational record we maintain.
You are responsible for required notices and permissions from people whose information you capture or share. A device permission is not their consent. If your information appears in another user's session, contact us under section 9; we may request enough information to locate the material without disclosing that user's unrelated information. Audio processing is for the enabled feature, such as transcription or contextual assistance; voice identification, biometric enrollment, or materially different sensitive uses require additional assessment, notice, and permission where applicable.
An integration receives or supplies information according to the feature and permissions you select. Disconnecting it prevents future access through that connection but may not remove material already received. Third-party sites, employers, meeting platforms, and sign-in or payment providers also have their own privacy responsibilities and policies.
4. Purposes of processing
We use information reasonably necessary and proportionate to:
- Provide accounts, authentication, AI inference, capture and transcription, contextual continuity, outputs, history, integrations, and functions you request or enable.
- Administer purchases, renewals, allowances, credits, billing, cancellations, refunds, and disputes, including verifying delivery and preventing duplicate benefits.
- Maintain, evaluate, troubleshoot, secure, and improve the Service; investigate failures; assess output quality; plan capacity; and develop features. Model training is further addressed in section 5.
- Detect and address unauthorized access, fraud, account sharing, prohibited automation, trial or promotion abuse, security incidents, rights violations, and misuse; enforce agreements; and determine whether to restrict or end access.
- Respond to support, privacy, legal, and rights requests; verify authority; send service and security notices; and maintain compliance records.
- Comply with law and lawful process; preserve relevant evidence; establish or defend claims; protect people and property; obtain professional advice; and conduct business transactions such as a reorganization or sale.
- Send optional marketing or conduct optional research where permitted and consistent with your choices, and create aggregate or properly de-identified information.
Where law requires a legal basis, we rely as applicable on performance of our agreement for requested services; legitimate interests in security, fraud prevention, necessary administration, proportionate improvement, and defending claims after considering affected individuals' rights; compliance with legal obligations; and consent for processing requiring it. Our agreement with one user is not a universal legal basis for processing another person's information. Sensitive information and international transfers require any additional conditions applicable law imposes. Refusing information essential to a requested function may prevent that function; optional processing remains optional where required.
5. AI providers, improvement, and model training
We may send selected inputs and relevant context to AI or transcription providers to perform requested or enabled functions. Requests and responses may be processed or retained by us and those providers for delivery, security, abuse prevention, diagnostics, and purposes permitted by applicable contracts and this policy. Retention and review practices can vary by provider, endpoint, feature, and account arrangement; we do not make a blanket zero-retention or no-human-access promise.
Authorized personnel and providers may review relevant content when necessary for support, quality evaluation, troubleshooting, safety, misuse investigation, or legal obligations, subject to appropriate access restrictions and confidentiality obligations. This does not mean we routinely review every session.
We may use feedback and aggregate or properly de-identified information to improve or develop the Service and models. We maintain de-identified information in that form, do not attempt to reidentify it except to assess de-identification effectiveness where permitted, and require recipients to observe applicable restrictions. Replacing a name with an identifier does not itself make information anonymous; pseudonymous records remain protected where they can reasonably be linked to an individual.
We do not obtain an unrestricted right under this policy to train general-purpose models on identifiable private session content. If we offer such a use, we will provide a specific notice identifying its purpose and participating providers and obtain consent or another legally sufficient authorization before that use where required. A materially different use of previously collected content is not authorized merely by changing this policy. Service delivery, security review, and quality evaluation are distinct from that optional training use.
6. Processors and other recipients
We may engage providers for hosting, storage, authentication, AI inference, transcription, payments, communications, diagnostics, support, and security. Depending on the offering, these may include Supabase for authentication and data services, Anthropic for AI processing, OpenAI for transcription or other enabled AI functions, Stripe for payments, Render for hosting, Resend for communications, and Sentry for diagnostics if enabled. This is a contemplated, nonexclusive provider list for this draft; before publication it must identify the providers actually used. We may replace or add providers subject to appropriate agreements, notices, and legally required consent or transfer safeguards.
Providers receive information needed for their role under applicable contracts and law. For example, AI providers may receive session content while payment providers receive billing information. Some act as independent controllers for their own legal, fraud-prevention, or payment-network responsibilities; our Terms do not control all their independent activities.
We may also disclose relevant information:
- To authorized personnel, affiliates, contractors, professional advisers, auditors, and insurers with a legitimate need and appropriate restrictions, for the purposes described here.
- To authorities, courts, rights holders, or other parties where reasonably necessary and legally permitted to comply with lawful process, address rights complaints, investigate abuse, protect safety, or establish, exercise, or defend claims. A private complaint does not automatically entitle someone to your complete account or session content.
- To a prospective or actual successor, acquirer, financing counterparty, or transaction adviser in a merger, investment, reorganization, insolvency, or business sale, using appropriate safeguards. Information remains subject to applicable law and relevant privacy commitments; a transaction is not unlimited permission to repurpose it.
- At your direction, through a sharing or integration feature you choose, or with valid consent.
We do not sell personal information or share it for cross-context behavioral advertising under this policy. We do not authorize advertising partners to use private session content for their own targeting. If we later introduce sale, targeted advertising, or another materially different disclosure, we will first provide applicable notices and choices, honor required opt-outs and preference signals, and obtain consent where required. This is not advance consent to that change.
7. Retention, deletion, and preservation
We retain personal information for the purposes described here, considering its nature and sensitivity, the feature used, your relationship with us, continuity and history needs, security risks, dispute and limitation periods, and legal or contractual recordkeeping obligations. Records may have different retention periods. Specific periods or controls may be stated in a feature notice or purchase terms.
- Account information and session content may remain while your account and the relevant history or service function remain active, until applicable deletion, or until no longer needed for the stated purposes. Temporary capture, staging, and processing media may be removed sooner than retained context, outputs, or audit records.
- Billing, consent, cancellation, and transaction records may remain for applicable accounting, tax, subscription-consent, fraud, and dispute requirements after closure. Where applicable, California subscription-consent verification is kept for at least three years or one year after termination, whichever is longer.
- Security, enforcement, and usage records may remain as necessary to investigate incidents, prevent account recreation or benefit abuse, demonstrate delivery, and enforce lawful restrictions. We may keep limited identifiers or pseudonymous records for these purposes; deletion does not necessarily erase every security or accounting reference.
- Relevant records may be preserved beyond ordinary schedules when required by law or reasonably necessary for an actual or reasonably anticipated dispute, investigation, or claim. Preservation is limited to the relevant purpose, reviewed as appropriate, and ended when no longer justified; it does not authorize indefinite retention of every user's private content.
- Deleted information may remain temporarily in backups, recovery copies, or pending deletion queues until their applicable lifecycle completes, with access and further use restricted. If a backup is restored, applicable deletion instructions must be reapplied. Independently retained provider records remain subject to their legal and contractual obligations.
Account deletion and cancellation of recurring billing are separate; use applicable controls or contact us to request both. A deletion request does not promise immediate erasure from every system, but we will act within the time law requires and explain exceptions. We may remove, de-identify, or restrict information rather than retain a usable account. A feature's lack of individual-session deletion does not remove statutory rights to request erasure or restriction.
Cloud deletion does not necessarily remove exported copies, integration content, local files on your device, or another organization's independent records. Deleting your codeplus1 account does not delete your separate Google, Apple, payment-provider, or other third-party account. Contact us for assistance understanding the scope of a request.
8. Cookies, local storage, and communications
We may use cookies, local storage, device storage, and similar technologies for sign-in, security, preferences, feature delivery, and diagnostics. Optional analytics or similar technologies, if introduced, are subject to choices and consent required where you live. Essential storage may be necessary for a requested function; blocking it can affect access. Browser settings and any consent or preference controls we provide can manage applicable technologies. A device's ordinary "Do Not Track" setting is distinct from a legally recognized universal opt-out signal, which we honor where required.
We may send service, billing, security, and legal communications needed to administer your relationship with us. Unsubscribe from promotional emails through the provided method or contact us. Unsubscribing does not normally stop essential operational messages. We do not condition ordinary access on optional marketing consent where prohibited.
9. Privacy requests and choices
Depending on location and law, you may request access or a copy, information about collection and disclosure, correction, deletion, portability, restriction, or an objection to certain processing. You may withdraw consent without affecting earlier lawful processing. Applicable rights may include opting out of sale, targeted advertising, or certain profiling; limiting specified uses of sensitive information; appealing a denial; and complaining to a regulator or court.
Use available account controls or contact [PRIVACY EMAIL]. People without accounts and authorized agents where permitted may also contact us. We may request information proportionate to the sensitivity and risk, verify authority, and protect other people's information and confidential security information. We will not demand unnecessary information or make verification an obstacle to a right that does not require it.
We respond within statutory deadlines and explain a denial or extension and available review or complaint routes where required. Where US state law gives you an appeal right, reply to our response or email the privacy contact with "Privacy appeal." Where applicable, you may then contact your state attorney general or other competent regulator. Lawful exceptions may protect others' rights, security, legal obligations, and claims. Excessive or manifestly unfounded requests may be handled as law permits with the required explanation; inconvenience or criticism alone is not abuse.
We do not unlawfully discriminate or retaliate for exercising a privacy right. A feature may become unavailable if information essential to it is deleted or necessary processing restricted. You may change device permissions, stop capture sources, disconnect integrations, and manage marketing or optional-processing choices where offered.
10. Additional US state disclosures
To the extent the California Consumer Privacy Act or another state privacy law applies, section 2 describes categories and sources, sections 4 and 5 describe purposes, section 6 describes recipients and disclosures, and section 7 describes retention criteria. Categories can include identifiers, commercial information, internet or network activity, audio/visual or electronic content, inferences, and professional or education information appearing in submitted content. Credentials and content may include statutorily sensitive information.
We process sensitive information for requested functions, security, and purposes permitted by applicable law, not to infer unrelated sensitive characteristics for advertising. We do not sell or share personal information for cross-context behavioral advertising under this policy, including information about people we know are under 16. If a change creates an applicable opt-out or limitation right, we will supply the required mechanism before that processing starts.
California residents may exercise applicable rights to know, access, correct, delete, and receive equal treatment through section 9. Agents may act with appropriate authorization. Other state residents may exercise applicable rights, including appeals and opt-outs for covered consequential profiling. AI assistance with your task does not itself mean we make a legally significant decision about you; a new feature involving such decisions requires its own assessment and disclosures. Coverage depends on statutory thresholds and exceptions; this section does not waive any right you have.
11. Security
We use administrative, technical, and organizational measures appropriate to the information and Service to reduce unauthorized access, alteration, loss, or disclosure. Authorized personnel and providers may access information for the purposes stated here. No internet transmission or storage system is completely secure. We will handle incidents and provide legally required notifications. This does not disclaim any nonwaivable security duty or remedy.
12. International processing
We and providers may process information in the United States and other countries where we or they operate, with different privacy laws. Where law requires a transfer mechanism, we use an appropriate mechanism, such as an adequacy decision, standard contractual clauses, a UK addendum or international data transfer agreement, or another lawful safeguard or exception, and assess additional required measures. Acceptance of this policy alone is not a substitute for a required mechanism. Contact [PRIVACY EMAIL] for relevant recipient-country and safeguard information or a copy of applicable safeguards, subject to necessary redactions.
If we offer the Service where a local representative, data-protection contact, specific overseas-transfer notice, or other disclosures are required, we will provide them with that offering. This US-oriented draft does not claim that every international launch requirement has already been satisfied.
13. Children
The Service is intended for adults aged 18 and over and is not directed to children. We do not knowingly collect personal information from children under 13 through their own use of the Service. If we learn we collected such information without a legally valid basis, we will take appropriate steps to delete it and restrict the account where necessary. Contact [PRIVACY EMAIL] with concerns. An age restriction does not remove our obligations when children's information appears in someone else's content.
14. Changes and contact
We may update this policy as the Service, providers, or legal requirements change. We identify the effective date and give notice of material changes through appropriate means, such as email or an in-product notice, before they apply where required. We obtain additional consent where required and will not rely on a silent or retroactive amendment to justify materially incompatible use of previously collected information.
Contact [LEGAL OPERATOR NAME], [BUSINESS MAILING ADDRESS], or [PRIVACY EMAIL] for questions and requests. Feature or regional notices may supplement this policy and identify specific differences. Personal information remains subject to applicable law regardless of ownership or licensing language.
