codeyy
Privacy Policy
Last updated: July 28, 2026
codeyy respects your privacy. This policy explains the data we process when you use the website or app, why we process it, the providers we may use, retention, your choices, and your rights — in line with UAE Federal Decree-Law No. (45) of 2021 on the Protection of Personal Data (PDPL). In the current mobile-app release, the app does not send your personal content to an AI or speech provider before showing a clear disclosure and obtaining your explicit permission as described below; this statement does not imply that the same mobile gate exists on the website.
01Data we collect
We collect the minimum data needed to provide our service:
- Account and authentication data: name, email, and password if you choose one (stored as a one-way hash; we do not store the original password), plus the Google or Apple identifiers and authorization tokens needed when you choose social sign-in.
- Technical and security data: IP address, browser, device and operating-system type, access and diagnostic logs, and fraud-prevention signals to the extent needed to operate and protect the service.
- Project and conversation content: descriptions, instructions (prompts), messages, answers, plans, code, files, documents, project and database data, deployment state, and secrets you choose to manage through the service.
- Images and attachments: files or photos you select from your device and images you capture with the camera. We access them only after the action and permission associated with that feature.
- Live-test data: when you start a live test for your project, we may automatically capture screenshots and page content and process the email and password of a test account you configured. Do not use real-account credentials for this purpose.
- Speech data: a recording you expressly start, the speech-to-text (STT) transcript, text you ask us to convert to speech (TTS), and the resulting audio when you use voice features.
- Notification data: push token, platform, user identifier, and notification preferences. On iPhone this may include a Live Activity token, task identifier, and generic state such as running, waiting for review, or complete; the card does not need the project name or prompt.
- Safety and content data: identifiers for listings and publishers you browse, a report category and optional comment, the content, task, or project identifier when you report a listing, publisher, or AI output, and the publisher identifier you choose to block.
- Usage and account data: plan, usage-credit balance and ledger, task cost, and billing or purchase status if applicable to your account, plus language, appearance, and setup preferences.
02How and why we use your data
- Create and authenticate your account and provide project building, conversation, voice, preview, deployment, and account-management features.
- Process prompts, files, images, and speech to generate plans, code, answers, and speech/text transformations under the applicable legal basis and, in the mobile-app release, after the required explicit permission.
- Send necessary service and security communications, such as email verification, password recovery, account-security alerts, and material service changes.
- Deliver the notifications and task states you choose, and operate the widget and Live Activity without exposing private project content.
- Carry out reports and blocks, filter and review content, respond to concerns and appeals, and protect the community.
- Measure consumption, manage credits, plans, and operational records, and improve reliability and user experience where permitted.
- Protect the platform and its users, prevent fraud and abuse, and comply with legal obligations.
03Mobile-app permission and AI and speech providers
In the current mobile-app release, before the app first sends personal content to an external AI or speech provider, we show a disclosure identifying the data categories, recipients, and purposes and ask for your explicit permission. We may use one or more providers depending on the feature, model, mode, and availability; listing every provider does not mean every request is sent to all of them. On the website, content is transmitted as part of the action you initiate to request an AI or speech feature, subject to this policy and any disclosure shown there.
- OpenAI, Anthropic, Google Gemini, and Kimi by Moonshot AI: their APIs may process prompts, conversations, plans, code, files, images, project context, live-test screenshots and page content, and credentials dedicated to the test account to generate plans, code, and answers and to run safety or quality checks.
- fal.ai: its service may process an image description, instructions, and reference images or assets you choose to generate or edit images.
- Deepgram: its service may process a recording you start to convert speech to text.
- ElevenLabs: its service may process text you choose to play aloud to generate audio.
We aim to minimize direct identifiers sent to these providers. codeyy does not sell content to them or use it for advertising. Training, human review, abuse monitoring, retention, and deletion terms differ by provider product, contract, region, and codeyy account setting, so we do not represent that every provider has the same default or retention period. We update this policy and the mobile disclosure if a provider, purpose, or processing practice changes materially.
You may decline permission. We will then not start sending new data to these providers, but features that require that processing — such as running an AI task, STT, or TTS — will not work. You may withdraw permission for new tasks and requests through the in-service consent control when available or by contacting us. A task or process already started before withdrawal may continue until it completes, so stop any active task first if you do not want it to continue. Withdrawal does not affect processing lawfully performed before it and does not automatically erase records that must be retained temporarily for security or legal obligations; you may request account and data deletion as described below.
04Sign in with Google and Google user data
If you choose Sign in with Google, we receive your name, your Google-verified email address, and Google's stable account identifier (sub) through the openid, email, and profile scopes. Google may include a profile-picture URL in profile, but codeyy discards it before issuing the session and does not persist it in the database or use it. We do not request or access Gmail, Drive, Contacts, or any sensitive Google data.
We use this data only to authenticate you; securely create, link, and operate your codeyy account; send necessary transactional, service, and security messages; and prevent account takeover and fraud. We retain the name, email, and stable identifier with your account under the retention terms below. We do not sell Google user data, use it for advertising or model training, or share it except with service providers necessary to operate the service or where legally required.
Google sign-in is optional. You may revoke codeyy's access from your Google Account settings; revocation prevents new Google authorizations and sign-ins until you grant access again, but it does not end an existing codeyy session or automatically delete your codeyy account or its data. To request deletion of your account and associated Google user data, contact us under “Your rights” below. We process the request and erase or anonymize data as required by law, while limited records may be retained where necessary for legal or financial obligations, platform security, or abuse prevention.
05Sign in with Apple and Apple user data
If you choose Sign in with Apple, we receive Apple's stable account identifier for codeyy (sub), an Apple-verified email address that may be an Apple Hide My Email relay address, and—only on the first authorization—the name you choose to share. We do not receive your Apple password or request access to iCloud, Photos, Contacts, or other data in your Apple Account.
We use this data only to authenticate you; securely create, link, and operate your codeyy account; prevent account takeover and fraud; and send necessary service and security messages. Our server exchanges the one-time authorization code for a refresh token and stores that refresh token encrypted while the account is linked so it can revoke authorization when you delete the account. We do not sell Apple user data, use it for advertising or model training, or share it except with service providers necessary to operate the service or where legally required.
Apple sign-in is optional. You can manage Sign in with Apple, Hide My Email, and relay forwarding in your Apple Account settings. Revoking codeyy's Apple access prevents new authorizations until you grant access again, but it does not end an existing codeyy session or automatically delete your codeyy account. When you delete an Apple-linked account in the app, we request fresh Apple authorization, invalidate codeyy sessions, and anonymize core account data. We then retain the stable identifier and encrypted revocation token only temporarily in a secure retry queue until Apple accepts revocation; after that, we delete the revocation token and release the identifier. Limited records required for legal, financial, or security obligations may remain as described below.
06Legal basis for processing
Depending on the processing and service surface, we rely on your explicit consent — including mobile-app permission when sharing data with AI and speech providers — performance of the service you request, legitimate interests such as platform security and fraud prevention, or compliance with a legal obligation. You may withdraw consent at any time without affecting processing lawfully performed before withdrawal.
07Data sharing and cross-border transfers
We do not sell your personal data. We share only what is necessary with hosting, CDN, database, infrastructure, email, notification, support, observability, and fraud-prevention providers, and with OpenAI, Anthropic, Google Gemini, Kimi by Moonshot AI, fal.ai, Deepgram, and ElevenLabs solely for the purposes above and, where applicable, after mobile-app permission. Each provider's processing is governed by its contract, codeyy account settings, policies, and applicable law; we do not assume a uniform retention period or training position unless the current documents for that route establish it.
Some of this data may be processed or stored on servers outside the United Arab Emirates. Processing locations, transfer mechanisms, and terms vary by provider, product, region, and the contract enabled for that route. We minimize the data sent and require transfers to comply with applicable law, but this notice alone does not assert that one particular contractual mechanism applies to every route. Contact us for details about the route used by a specific feature.
08Your rights under the data protection law
The PDPL grants you the following rights regarding your personal data:
- The right to access your data and understand how it is processed.
- The right to rectify inaccurate data or complete incomplete data.
- The right to erase your data.
- The right to restrict or stop processing.
- The right to object to processing, including automated processing and automated decision-making.
- The right to withdraw your consent at any time.
- The right to transfer your data to another party.
To exercise any of these rights, contact us using the details below, and we will respond within the periods prescribed by law.
09Data security
We apply technical and organizational measures to protect your data, including encryption of sensitive data, isolation of execution environments (containers), and strict access controls. However, no method of electronic transmission or storage is 100% secure, and we continuously work to strengthen our protections.
10Data retention and deletion
We retain account data and project content while the account remains active or for as long as needed to provide a service you requested, unless you delete content or request deletion sooner. The app cleans temporary local audio files after completion or failure. We keep push and Live Activity tokens and states only while needed for delivery and the related task, then invalidate or delete them when no longer needed. We may retain report, block, and moderation records for the period needed to investigate, respond, handle appeals, and prevent repeated abuse, and limited operational, financial, or security records to comply with law, resolve disputes, and prevent fraud. An external provider may retain temporary copies or records under its product, contract, region, codeyy account settings, and security requirements. Retention and deletion availability differ by provider; contact us to request current information or deletion available under the contract and law.
You can start account deletion in app settings, through the public account-deletion page, or by contacting us. When the request is completed, we revoke sessions. Account identifiers include name, email, and the stable Google and Apple identifiers; we then erase or anonymize them and associated content, while the limited financial or security records described above may remain. For an Apple-linked account, the Apple identifier and encrypted revocation token may remain temporarily only until authorization revocation succeeds; the token is then deleted and the identifier released. Deletion from active systems may not remove backups immediately; backup copies are removed or overwritten according to the applicable backup cycle and policy.
11Cookies and local storage
We use cookies necessary for sign-in, session security, and abuse prevention; preference cookies such as language; and may set a time-limited referral cookie to attribute an invitation or referral when you visit its dedicated link. We may also use local storage for interface preferences. We do not use these technologies for behavioral advertising or cross-site tracking.
12Changes to this policy
We may update this policy from time to time. We will post any changes on this page and update the “Last updated” date above.
13Contact us
For any question about your privacy or this document, or to exercise your rights, reach us at:
- Location: Dubai, United Arab Emirates
- Phone: +971 50 678 3032
- Email: info@codeyy.ai
We may update this document when the service or legal requirements change and will show the latest revision date.