LEGAL · PRIVACY
Privacy, in plain English.
What we collect, why we collect it and the controls you have — with a plain-English summary next to every section.
privacy-policy.md
read-only
version
v3.1
effective
Sep 1, 2026
last updated
Sep 1, 2026
reading time
9 min
owner
privacy@codecraft.dev
TL;DR
The short version
§01
Who we are
CodeCraft Technologies (“CodeCraft”, “we”, “us”) provides AI-assisted code generation through our website, CLI, editor extensions and API (together, the “Services”).
This policy explains how we process personal data when you use the Services or visit codecraft.dev. For customer workspaces, we act as a processor on behalf of our customers; for our website and accounts, we act as a controller.
Plain English
This covers our website, CLI, editor extensions and API.
§02
Information we collect
We collect account information you give us (name, email, company and billing details), usage data (features used, device and browser details, approximate location from your IP address) and the messages you send to support.
When you use the Services, prompts and code are processed transiently to generate a response. They are not stored.
Plain English
Account details, usage analytics and support messages. Your code is processed, not collected.
schema · personal_data
field
purpose
retention
Sign-in and service emails
Life of account
Personalisation and support
Life of account
Payments, processed by Stripe
7 years (tax law)
Product analytics
13 months
Generating your response
Not stored · 0 s
Answering your questions
24 months
§03
How we use information
We use personal data to provide, secure and improve the Services; to process payments; to communicate with you about your account and product updates and, with your consent, marketing; to prevent fraud and abuse; and to meet our legal obligations.
We do not use customer prompts or code to train AI models.
Plain English
To run and improve CodeCraft — never to train models on your code.
§04
Sharing & sub-processors
We share personal data only with service providers who process it on our behalf under written data processing agreements — for example hosting, payments and email delivery — when required by law, or as part of a merger or acquisition.
We never sell personal data.
Plain English
Only with vendors who help us run the service. We never sell data.
§05
Data retention
We keep account data for as long as your account is active and delete it within 30 days of account deletion, unless we must keep specific records longer for legal, tax or accounting reasons.
Prompts and code are discarded as soon as a response is returned.
Plain English
Account data while you’re a customer. Your code: zero seconds.
§06
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to restrict or object to certain processing, and to withdraw consent at any time.
You can exercise most rights yourself from your account settings or the CLI, or by emailing privacy@codecraft.dev. We respond within 30 days.
Plain English
Access, correct, export or delete — most of it self-serve.
§07
International transfers
We process data in the United States and the European Union. Paid workspaces can choose EU data residency.
When personal data is transferred out of the EU, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and additional technical safeguards.
Plain English
EU data can stay in the EU. Other transfers use standard safeguards.
§08
Cookies
We use essential cookies to keep you signed in and privacy-friendly analytics to understand how our website is used. We do not use advertising or cross-site tracking cookies.
You can block non-essential cookies in your browser settings without affecting the Services.
Plain English
Essential cookies and light analytics. No ad tracking.
§09
Changes to this policy
We’ll post any changes here and update the version and date above. For material changes, we’ll email workspace owners at least 30 days before they take effect.
Plain English
We’ll tell you before anything important changes.
v3.1
Sep 1, 2026
+ Added EU data residency for all paid plans
+ Listed our new transactional email sub-processor
− Removed a retired analytics provider
v3.0
Mar 12, 2026
+ Clarified zero-retention processing for prompts and code
+ Added CLI commands for exporting and deleting data
v2.4
Oct 3, 2025
+ Added disclosures for California residents (CCPA)











