Privacy
CoDesk reads your business tools to answer questions about them. This page says exactly what that involves.
Who we are
CoDesk is operated by [TO CONFIRM: legal entity name, registered address, company number]. For anything on this page, contact us at our contact page.
What we collect from you directly
- Your account. Name, work email, and a password if you set one. You can sign in with Google, with an email and password, or with a one-time link sent to your email; we store only what the method you choose requires.
- Your workspace. The company name and address you pick, your role, and who else you invite.
- What you ask. Your questions and the answers returned, so a conversation can continue and you can come back to it.
What we read from your connected tools
When you connect a tool, CoDesk reads from it to answer your questions. It can only ever see what the credentials you supply can see; connecting a tool does not widen anyone’s access to it.
- Project and issue records, including status, assignment and history.
- Code activity: changes, reviews and releases.
- Messages in the channels you choose to connect.
- Meeting transcripts and the action items drawn from them.
- Accounting records: invoices, expenses, customers and totals.
Some of this is fetched at the moment you ask and not retained. Messages and transcripts are indexed so they can be searched by meaning, which means we hold a processed copy. [TO CONFIRM: how long indexed content is retained, and whether disconnecting a tool deletes its index immediately or on a schedule.]
What we never do
- We do not use your business data to train models, ours or anyone else’s.
- We do not sell your data or share it for advertising.
- We do not let one workspace see another’s data. Separation is enforced in the database, not only in the application.
- We do not change anything in your tools by ourselves. CoDesk can prepare a draft, but it only reaches your systems when a person approves it, and we record who did.
Who else processes your data
Running CoDesk means passing data through a small number of other services. As of this draft, they are:
- Supabase — hosts the database and handles sign-in.
- Anthropic — the model that reads retrieved records and writes the answer.
- Voyage AI — turns messages and transcripts into the form that makes search-by-meaning possible.
- Vercel — hosts and serves the application.
- The tools you choose to connect, which you already have your own relationship with.
[TO CONFIRM: hosting regions for each, whether data leaves your jurisdiction, and the transfer mechanism if it does. Confirm this list is complete against current production before publishing.]
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Because most of what CoDesk reads lives in your own tools, deleting your workspace removes what we hold rather than anything of yours at source.
[TO CONFIRM: which regimes apply — UK GDPR, EU GDPR, CCPA and so on — the lawful basis for each purpose above, response times, and how to escalate to a regulator.]
Security
Access is scoped per workspace and enforced at the database level. Credentials for connected tools are stored encrypted. Every question, every record read and every action approved is logged, so an answer can be taken apart months later.
[TO CONFIRM: encryption specifics, breach notification commitments, and whether you hold or intend to hold SOC 2 or ISO 27001.]
Changes
If we change this policy in a way that matters, we will tell workspace owners rather than quietly updating the date at the top.