Start Free

Privacy Policy

Effective July 9, 2026. Palisade Technologies LLC, doing business as Codaegis, collects only the information needed to provide and protect the service, manage accounts and billing, support customers, and produce governed packets.

Privacy contactsupport@codaegis.com

Use this address for privacy, access, correction, deletion, export, billing, refund, cancellation, support, and security requests.

Information Codaegis may collect

  • Account identity, email, sign-in state, account settings, and support contact details.
  • GitHub identity, repository metadata, pull-request metadata, discussions, changed-file references, commit metadata, and CI/status signals needed for a selected PR check.
  • Governed packet contents, risk findings, missing-proof notes, next-review-action guidance, blocked assumptions, provenance, policy-memory version, and human disposition records.
  • Usage, entitlement, allowance, billing receipt, failed-payment, export, route, and security-event metadata needed to operate the service.
  • Support, privacy, billing, refund, cancellation, and security messages that a customer chooses to send.
  • Essential cookie, session, device, route, IP-address, and security-log information needed to sign users in, prevent abuse, and operate the service.

How Codaegis uses information

  • Provide the GitHub-first governed packet service and deliver visible packet history and Starter export.
  • Manage accounts, subscriptions, usage limits, payment state, tax records, and accepted subscription terms.
  • Operate docs-first support, answer customer requests, investigate security reports, prevent abuse, and comply with legal obligations.
  • Not use customer packet, repository, or code content for broad model training without explicit opt-in and a later policy update.

Service providers and subprocessors

Codaegis relies on a small number of third-party providers to run the service. It names the provider that processes code content to produce packets and holds only the internal configuration that would help a competitor reconstruct how the engine reaches a verdict.

  • Codaegis sends bounded analysis requests through OpenRouter, which routes each request to an eligible model-hosting provider under Codaegis's request-level privacy and fallback controls. The selected model is developed by OpenAI, but the hosting provider is not pinned and may be OpenAI or another eligible company.
  • The specific model version, routing, and prompt configuration behind that analysis are not disclosed; they are internal engine configuration, not a data-handling boundary.
  • Codaegis does not use customer packet, repository, or code content for broad model training without explicit opt-in or a later reviewed policy.
  • Stripe processes payments through Stripe-hosted flows. Codaegis does not store full card details.
  • GitHub is the customer-authorized source of the repository and pull-request evidence Codaegis reads for a selected check.
  • Hosting, database, email, security, and logging providers may process the limited information needed to operate and protect Codaegis.
  • Codaegis may disclose information when legally required, to protect rights or safety, or as part of a business transfer with appropriate safeguards.

Retention and customer responsibility

The active plan limits which packet history is visible. These visibility windows are not a promise that every older record is automatically deleted on day 3 or day 30; automated deletion remains release-gated. Customers remain responsible for storing records they need, and may request legally applicable deletion through support.

  • Free: 3 days of visible packet history.
  • Starter: 30 days of visible packet history.
  • After a downgrade shortens the visible history window, older data may be held but unavailable during a brief recovery grace period. Its later deletion follows the active, release-gated retention controls and is not guaranteed merely by becoming hidden.
  • Subscription consent evidence is retained for at least three years after acceptance and at least one year after the subscription ends, whichever is later.
  • Detailed local Stripe event links are removed after three years. The Stripe event ID and event type may remain as a minimal duplicate-prevention record.
  • Support, security, billing, tax, legal, fraud, and audit records are retained only as long as reasonably needed for those purposes or required by law.

Choices and requests

  • Customers may revoke GitHub access, request access, correction, export, or deletion where applicable, and cancel billing online when the billing portal is available or through support otherwise.
  • Codaegis will verify a requester before acting and may retain information that law, security, fraud prevention, tax, billing, or dispute handling requires.
  • Codaegis does not sell personal information or use it for cross-context behavioral advertising.
  • Send requests to support@codaegis.com. Codaegis will respond within the time required by applicable law.

Age and geography

  • Codaegis may be used by individuals and businesses; it is not business-only by default.
  • The paid service is designed for professional, commercial, and organizational software-development work, including work performed by individual developers.
  • The service is intended for adults age 18 or older and is not directed to children.
  • The first paid service is offered for use in the United States. Do not purchase it for use outside the United States unless Codaegis later states that country is supported.

Policy changes

  • Codaegis may update this policy as the service changes and will post a new effective date.
  • Material changes will be announced through the service or by email when required by law.