1Who we are, and what this covers
This policy explains how CoDuck, Inc., a Delaware corporation ("CoDuck," "we," "us"), handles personal data. For this data, we are the controller — we decide why it is held and what happens to it.
It covers the CoDuck website, the application, the command-line tool, and our APIs.
It does not cover the sites you build with CoDuck. When your application collects data from its own visitors, you are the controller of that data and we are only your processor. That relationship is governed by a Data Processing Addendum, which we provide to business customers on request — email liam@coduck.ai and we will send it. The privacy notice your visitors need is yours to write, not ours.
Questions, requests, or complaints: liam@coduck.ai, or by post to CoDuck, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713.
If you are in the EU or the UK: we have not appointed a representative under Article 27 GDPR. The usual move for a company our size is to assert the "occasional processing" exemption, but we serve EU and UK users continuously rather than occasionally, so we would rather say plainly that no representative is appointed than claim an exemption nobody has confirmed applies. We are reviewing whether one is required, and will name them here when appointed. In the meantime reach us directly at liam@coduck.ai; you also keep the right to complain to your local supervisory authority.
2What we collect
Account details. Your name, email address, and a hashed version of your password. If you upload an avatar, the image file. If you sign in with Google, your email address from that account.
Sign-in and security records. Every session records the IP address and browser user-agent it was created from, when it was last used, and when it ended. We keep these so that you can review and revoke your own sessions and so that we can investigate account compromise. Command-line tokens record the device name and last-used IP address the same way.
Your account activity. An append-only audit trail of sign-ins, two-factor changes, session revocations, team membership and role changes, and secret access — each with your email address, IP address, and user-agent.
Billing details. Your Stripe customer and subscription identifiers, your plan, your credit balances, the state of your payments, and a non-reversible payment-method fingerprint Stripe provides so we can enforce one Cloud trial per payment identity and prevent refund-policy abuse. We never receive your card number or security code. Those are entered on Stripe's hosted checkout page and stay with Stripe.
What you create. Your prompts, your project source code, your chat history with the assistant, the environment variables and credentials you store (encrypted), and the domains and third-party accounts you connect. Some of this is personal data if you put personal data in it — that is your choice and under your control.
Generation records. For each build we keep the model used, tokens, cost, timing, and the prompt text, plus a replay of the assistant's steps. Values you set as environment variables are stripped out before that replay is stored.
Support and feedback. Anything you send us, including the free-text reason you give if you cancel.
How you found us. When you browse coduck.ai we record page path, referrer, campaign tags, device, browser, operating system, and an approximate country, region and city. The location is worked out on our own server from your IP address using a local database — the IP address itself is never written down for this purpose.
We do not knowingly collect special-category data — health, biometrics, political opinions, and so on — and you should not put it into prompts or project data without your own legal basis for doing so.
3Why we hold it, and on what basis
To provide the Service — creating your account, running generations, deploying and serving your sites, and syncing anything you connected. In GDPR terms this is performance of a contract with you.
To take payment and to keep the tax and accounting records the law requires of us — contract, and legal obligation.
To keep accounts and infrastructure secure — detecting compromised accounts, investigating abuse, rate-limiting, and bot protection on sign-up. This is our legitimate interest in running a service that is not overrun, and yours in not having your account stolen.
To support you when you write in, and to send transactional email about your account, your builds, and your billing — contract and legitimate interest.
To understand how the product is used and how people find it — legitimate interest. This is first-party and aggregate; we are looking at which pages work, not at you.
Marketing email goes only where you have opted in or where you are an existing customer and the message is about something similar — consent or legitimate interest depending on where you are. Every one has an unsubscribe link that works.
We do not use your prompts, code, or project data to train AI models, and we do not sell or share personal data for advertising. There is no advertising or cross-site tracking pixel anywhere on CoDuck.
5Where your data is processed
All platform data, all customer project data, and every deployed application run on infrastructure provided by Advin Services LLC in the United States. We do not currently offer EU data residency, and nothing of ours runs in an EU region.
That means if you are in the EU, the UK, or Switzerland, your personal data is transferred to the United States. We rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) for those transfers. Business customers who need them incorporated contractually should ask us for our Data Processing Addendum.
Some providers on our subprocessors list — Cloudflare and Google in particular — operate global edge networks, so traffic to them may be handled outside the United States.
We name the country and not the city on purpose. Our own network measurements suggest particular US cities, but that is inference rather than something our hosting provider has confirmed in writing, and this is not a document to put inferences in.
6How long we keep it
A job runs once a day and deletes data past the windows below. These are the real defaults, and the sweep genuinely runs — it is not a policy we wrote and never implemented.
- Debug traces — 7 days. Only collected if you switch verbose debugging on.
- Sign-in sessions — deleted 30 days after they expire.
- Visitor analytics for your deployed sites — raw page views 90 days. Hourly aggregate counts are kept as the long-term record.
- Error reports — 90 days, after which only the grouped summary remains.
- Generation replays — the step-by-step assistant transcript is erased after 90 days. The build's cost and timing record is kept.
- Email delivery records — 365 days.
- Audit trail — 730 days.
What has no automatic expiry, stated plainly: your account and its contents for as long as it is open; your projects, chat history, and generation prompts; form submissions collected by your deployed sites; our own website analytics; and feedback you have sent us. These are kept until you or we delete them.
After you cancel, your sites serve for 30 days, then sleep. Nothing is deleted at that point — your projects and their data stay so that resubscribing restores them.
We then keep that data indefinitely, until you ask us to delete it. There is no expiry date on a cancelled account and no scheduled deletion: your projects, their databases and their contents simply remain. We are telling you this rather than quoting a tidy number because the number would not be true — nothing deletes them but a request.
Deletion is on request, and the request is handled by a person. There is no button for it. Email liam@coduck.ai from your account address and we will erase your account and tear down its sites and databases. We will do it within 30 days of being asked.
Deleting a project removes its container, its entire database (including any accounts and data your application stored), its analytics, form submissions, email records, domains and connections. Some engineering records — the generation history for that project, including prompt text, plus deploy attempts and error reports — are not removed by that action today.
Where we are required to keep something for tax, accounting or legal-claim reasons, we keep it for as long as that requires, and no longer.
7Your rights, and how to use them
Depending on where you live, you have some or all of the following rights: to access your data, to have it corrected, to have it deleted, to restrict or object to how we use it, to portability, and to withdraw consent where consent is what we relied on. If you are in California, you also have the right not to be discriminated against for exercising them — and we do not sell or share personal data, so there is nothing to opt out of on that front.
What you can do yourself, right now: change your name, email and password; review every active session and revoke any of them; read your own audit trail; turn two-factor authentication on; remove your avatar; and delete any individual project. You can also start a supervised personal-data export by emailing us from the address on the account.
Personal-data exports are supervised, not one-click. Email liam@coduck.ai from the address on your account. A person starts the request, then we send that account a 48-hour confirmation link. You must be signed in to the same account to confirm. We prepare and review the archive before releasing it through an authenticated download that expires after seven days. The archive contains personal data tied to the requester, such as account and security records, prompts and assistant responses, billing, support, account analytics, team membership and safe project metadata. It is not a project backup: project source, generated files, uploads, databases, form submissions, visitor analytics and deployed-site user records are not included. Reusable credentials, security-sensitive internals and another person's information are excluded or redacted where appropriate. An export never deletes, suspends or changes your account, sites, projects or databases.
Deletion is a separate request and remains manual. Email liam@coduck.ai from your account address. We verify the request before erasing the account and tearing down its sites and databases. Asking for an export is not a deletion request, and asking for deletion does not happen as a side effect of an export.
We respond within 30 days. We may ask you to confirm who you are first, which for a request from your account's own email address is usually just a reply.
You can complain to your data protection authority if you think we have got this wrong. In the EU that is the authority where you live; in the UK it is the Information Commissioner's Office. We would appreciate the chance to fix it first.
9How we protect it
Secrets you store — environment variables, database credentials, connected-account tokens, and two-factor seeds — are encrypted with AES-256-GCM, each value bound to the record it belongs to so a ciphertext cannot be moved between records. Passwords are hashed with bcrypt and cannot be read by anyone, including us. API keys and recovery codes are stored only as hashes.
Every public endpoint is TLS 1.2 or 1.3 only. Each deployed project runs in its own container as a non-root user against its own database with its own credentials.
Our security page describes this in more detail, including what is still in progress. For an enterprise review we share a fuller pack that also lists our current open findings and the plan for each — we would rather hand you those than have you find them.
No system is perfectly secure. If you find a vulnerability, please tell us at liam@coduck.ai — we aim to acknowledge within two business days.
10Children
CoDuck is not intended for children under 13, and we do not knowingly collect their personal data. We do not currently ask for a date of birth at sign-up, so this rests on the age you confirm by accepting our Terms of Service.
If you believe a child under 13 has given us personal data, email liam@coduck.ai and we will delete it.
11Changes to this policy
When we change this policy materially we will update the effective date at the top and tell you by email or in the product before the change takes effect.
Earlier versions are available on request — a privacy policy that quietly rewrites its own history is not worth much.
Questions about this document? Email liam@coduck.ai. This version is effective September 4, 2026 and replaces any earlier version at coduck.ai/privacy.

