On this page
01The short version
We collect what we need to run your account and nothing else. We never sell your data, never advertise to you, and never look at your code except when you ask us to for support. Payment details are handled by Cashfree — they never reach our servers.
This policy explains it fully. Mohit Bansal is the data controller (“we”, “us”), and it applies to kodeo.website and the KODEO app.
02What we collect
You give us:
- Account details — name, username, email address, password (stored only as an Argon2id hash), and optionally a profile picture, bio, developer role and tech stack.
- Workspace content — workspace and project names, descriptions, files and the people you invite.
- Billing details — the name, email, phone number and optional company, GSTIN and address you enter for receipts.
- Anything you write to us in a support message.
We record automatically:
- Session and security data — sign-in time, IP address, browser/device description and an approximate location, so you can review and revoke sessions.
- Payment records from Cashfree — plan, amount, status, and a masked description of the method (for example “UPI · name@bank” or “VISA •••• 4242”).
- Basic technical logs needed to keep the service running and safe.
We never collect your card number, CVV, UPI PIN or bank credentials. Those are entered on Cashfree’s own page.
03Why we use it
- To provide the service — accounts, workspaces, projects, collaboration and themes (performing our contract with you).
- To take payments, issue receipts and apply plan limits (performing our contract, and meeting legal accounting duties).
- To keep accounts safe — detecting suspicious sign-ins, rate limiting and preventing abuse (our legitimate interest in security).
- To send service email — verification codes, security alerts, invitations, receipts and billing notices. These are not marketing and cannot be switched off while your account is open.
- To improve the product by understanding which features are used (our legitimate interest), never by reading your code.
05How long we keep it
- Account and workspace data — until you delete your account or the workspace.
- Sessions — until they expire or you revoke them.
- One-time codes (OTP) — 10 minutes.
- Payment records, receipts and invoices — retained as required by Indian tax and accounting law (generally up to 8 years), even after account deletion.
- Security and webhook logs — kept for a limited period for debugging and audits, then deleted.
- KODEO Assist conversations (signed in) — 30 days, deletable any time; a visitor’s stay only in their own browser. The questions asked, with personal details removed, are kept 180 days to improve the Help Center.
- Support tickets — while your account exists; screenshots and logs attached to a ticket are deleted 90 days after it closes.
06How we protect it
- Passwords are hashed with Argon2id and checked against known breach lists; we can never read them.
- Sessions use short-lived tokens with rotation and reuse detection, in secure, httpOnly cookies.
- All traffic is encrypted with HTTPS, and the database connection uses TLS.
- Payment webhooks are cryptographically verified before anything is recorded.
- Access to production data is limited to what is needed to operate the service.
08Your rights and choices
- Access and correct your details from your profile at any time.
- Export or ask for a copy of your data by writing to us.
- Delete your account yourself from Settings → Danger zone; owned workspaces and projects go with it.
- Object to or restrict certain processing, and complain to a data protection authority.
Write to privacy@kodeo.website and we will respond within 30 days. Under India’s IT Rules, our grievance officer is Mohit Bansal, grievance@kodeo.website.
09International transfers & children
Our providers may process data outside India. When that happens we rely on their contractual safeguards and standard data protection clauses.
KODEO is not intended for children under 18. If you believe a child has given us personal data, contact us and we will delete it.
10Changes to this policy
If we change how we handle your data, we update this page and the date above, and tell you in the app or by email before significant changes take effect. See also our Terms and Refunds policy.