1. The companies that control your personal data
We use codus across two related UK private limited companies that act as joint data controllers for the purposes of Article 26 UK GDPR. The arrangement between us, in plain language, is:
- AI Search Labs Ltd (company no. 16719803; registered office: Windrush House, Windrush Park Road, Witney, OX29 7DX) is the owner of the codus product and the customer database. It determines what data is collected for product purposes, how it is used to develop and improve codus, and how it is retained over the life of the product. We refer to it as “ASL”.
- Search Intelligence Ltd (company no. 09361526; registered office: Witney Business and Innovation Centre, Windrush Park Road, Brighthampton, Witney, OX29 7DX) is the operator of the codus Service and the merchant of record. It determines what data is collected for billing, customer-support, security and operational purposes. We refer to it as “SI”.
Both companies operate from the United Kingdom and are subject to the UK GDPR and the Data Protection Act 2018.
1.1 Single point of contact
Although ASL and SI are joint controllers, we have designated SI as the single point of contact for data subjects. Whichever entity you contact, we will route your request to the appropriate party and respond as a single team. The fastest way to reach us about any privacy matter is [email protected]. You retain the right to exercise your rights against either or both controllers directly.
Neither ASL nor SI has been required to appoint a Data Protection Officer under Article 37 UK GDPR, but the same [email protected] mailbox is monitored by the person responsible for data protection at codus.
2. What this policy covers
This policy applies to:
- your use of the codus desktop application (the “Software”);
- your visits to trycodus.com and any subdomain;
- your codus account (sign-up, sign-in, billing, support);
- communications you receive from us; and
- any cloud feature of codus that synchronises your account or settings.
It does not cover what happens to your code or your files inside the Software when codus runs on your machine. codus is a local-first tool: most of what it does happens on your own device, with your own files, under your own operating-system user account. We see those interactions only to the extent the Software emits operational telemetry, makes a request to a third-party AI provider on your behalf, or syncs explicitly to your codus account.
3. Personal data we collect
3.1 Data you give us
- Account data: name, email address, password (hashed and salted), country of residence, communication preferences.
- Billing data: billing name, billing email, billing address, VAT number (if you supply one), the last four digits of your card and card brand. Full card numbers are not stored by us — they are handled directly by Stripe.
- Subscription data: plan, plan history, renewal dates, invoices, refund history.
- Communications: emails, support tickets, in-product chat messages, survey responses and any feedback you give us.
- Identity verification (where required): if we need to verify a corporate signatory, we may collect basic identity information for that purpose.
3.2 Data the Service generates
- Usage and telemetry: events emitted by the Software such as feature usage, crash reports, performance metrics, model latency, error stack traces, and codus version. Where you opt in to richer telemetry we may also collect anonymised prompt-and-response signals (no Customer Content) to detect bugs and regressions.
- Device information: operating system and version, processor architecture (Apple Silicon, Intel, ARM, x86_64), app build, locale.
- Network information: IP address (truncated where possible), approximate geolocation derived from IP at city level, and connection metadata visible to our service providers (e.g. our CDN).
- Authentication tokens: tokens issued by us and (where you have linked an account) opaque references to GitHub, Google or other identity providers we support.
- Audit logs: records of significant security events (sign-ins, password changes, payment attempts, admin actions on team accounts).
3.3 Data we receive from third parties
- Stripe: payment confirmations, invoice metadata, refund and dispute outcomes, fraud signals.
- Identity providers: when you sign in via GitHub, Google or another supported provider, we receive the basic profile information you authorise (name, email, avatar URL, account ID).
- AI providers: usage and quota metadata when you make requests through codus to a third-party AI provider.
- Public sources: we occasionally check public registers (Companies House, sanctions lists) for B2B due diligence on team accounts.
3.4 What we do not collect
- We do not store the contents of your code, your repositories, or the files you operate on with codus, except (a) ephemerally and only to the extent strictly necessary to forward your prompt to the AI provider you have selected, and (b) where you explicitly opt in to a feature (for example team-shared task planning) that requires it.
- We do not use your code, prompts or outputs to train any machine-learning model.
- We do not knowingly collect personal data from anyone under 18.
4. Why we use your personal data, and our lawful bases
Under the UK GDPR we must have a lawful basis for each purpose for which we process personal data. Our purposes and bases are:
| Purpose | Categories of data | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Providing the codus Service to you (account creation, sign-in, app delivery, sync) | Account data, device data, telemetry essential to operation, authentication tokens | Performance of a contract with you (Art. 6(1)(b)) |
| Taking payment, raising invoices and handling refunds, chargebacks and disputes | Billing data, subscription data, communications | Performance of a contract (Art. 6(1)(b)) and compliance with our legal obligations under tax and accounting law (Art. 6(1)(c)) |
| Customer support and replying to you | Account data, communications, audit logs | Performance of a contract (Art. 6(1)(b)) and our legitimate interest (Art. 6(1)(f)) in operating an effective support function |
| Securing the Service: detecting fraud, abuse, AUP breaches, and unauthorised access | Usage and telemetry, network information, audit logs, authentication tokens | Legitimate interests (Art. 6(1)(f)) in protecting the Service, our users and our infrastructure; legal obligation (Art. 6(1)(c)) where applicable (e.g. AML) |
| Improving codus: understanding which features work, fixing crashes, evaluating model performance | Usage and telemetry, device data, anonymised diagnostics, opted-in prompt signals (no Customer Content) | Legitimate interests (Art. 6(1)(f)) in product improvement, balanced against your privacy by truncation, aggregation and opt-out controls |
| Sending essential service emails (security alerts, billing, terms changes) | Account data, communications | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Sending marketing emails (product news, tips, launch announcements) | Account data, communications | Consent (Art. 6(1)(a)) and, for B2B existing-customer marketing, the soft-opt-in under Regulation 22(3) PECR. Each marketing email contains a one-click unsubscribe. |
| Complying with law (tax, accounting, sanctions, court orders, ICO requests) | Whatever is required | Legal obligation (Art. 6(1)(c)) and, where applicable, public interest (Art. 6(1)(e)) |
| Asserting, defending or settling legal claims | Whatever is necessary | Legitimate interests (Art. 6(1)(f)) — to establish, exercise or defend legal claims (Recital 47) |
| Corporate transactions (financing, restructuring, sale of part or all of the business) | Account data, subscription data, anonymised aggregates | Legitimate interests (Art. 6(1)(f)) in operating, financing and ultimately exiting our business, balanced by appropriate confidentiality and contractual safeguards |
Where we rely on legitimate interests, you have the right to object — see section 9.
5. How we share personal data
We share personal data only where necessary, and only with parties bound by appropriate confidentiality and data-protection obligations. The categories of recipient are:
5.1 Each other
ASL and SI share Customer Data with each other under the joint- controller arrangement and a written data-sharing agreement. ASL receives the data needed to operate as the long-term owner of the product (see section 1). SI receives the data needed to operate as the day-to-day operator and merchant of record.
5.2 Service providers (processors) we use to run codus
We rely on a small number of trusted vendors. Each of them processes personal data on our instructions under a written data-processing agreement that includes Article 28 UK GDPR clauses. The current list is below; we may update it from time to time.
| Vendor | Purpose | Where data is processed |
|---|---|---|
| Stripe Payments Europe, Limited (and group companies) | Card processing, subscription billing, fraud and dispute handling | EEA, UK and the United States |
| Vercel Inc. | Hosting trycodus.com and serving the codus website and download routing | United States with EU/UK edge |
| Neon Inc. | Managed Postgres database for the codus content management and account systems | EU region (we select EU-only deployments where available) |
| Anthropic PBC | Provider of large language models accessed by codus when you choose Anthropic models | United States (with applicable transfer safeguards) |
| OpenAI, OpCo, LLC | Provider of large language models accessed by codus when you choose OpenAI models | United States (with applicable transfer safeguards) |
| Google Cloud / Workspace and Microsoft 365 | Productivity, email and limited internal analytics | Multi-region with UK/EU primary where available |
| GitHub, Inc. | Identity provider when you sign in with GitHub; source-control integration | United States |
| Customer support tooling (e.g. Plain or equivalent) | Handling support tickets and live chat | Predominantly UK/EU with US sub-processors |
| Email delivery (e.g. Postmark or equivalent) | Sending transactional and marketing email | United States and EU |
For an up-to-date list of sub-processors please contact [email protected].
5.3 Professional advisers
We share data with our auditors, accountants, lawyers, insurers and professional advisers where reasonably necessary, in confidence.
5.4 Authorities and law-enforcement
We may share data with regulators, courts and law-enforcement agencies where required by law or where reasonably necessary to protect our rights, the rights of our users, or the public interest. We do not provide bulk access to user data.
5.5 Corporate transactions
If we are involved in a financing round, restructuring, change of control, sale of business or assets, or comparable transaction affecting either ASL or SI, we may share personal data on a confidential basis with prospective counterparties, advisers and successors. Personal data shared in this way is, and will continue to be, subject to this Privacy Policy or to a successor policy at least as protective.
6. International transfers
Some of our processors are based outside the United Kingdom and the European Economic Area, principally in the United States. Where we transfer personal data internationally, we rely on:
- the UK’s adequacy regulations where they apply (for example, the UK Extension to the EU–US Data Privacy Framework, in respect of certified US recipients);
- the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, with supplementary technical and organisational safeguards as recommended by the European Data Protection Board following the Schrems II judgment;
- any other transfer mechanism approved under the UK GDPR.
You can request a copy of the relevant transfer mechanism (with commercially sensitive details redacted) by emailing [email protected].
7. How long we keep your data
We keep personal data only for as long as necessary for the purpose we collected it for, plus a reasonable archival period for our legal, audit and dispute-defence needs. The default retention periods are:
- Active account data: for as long as your account exists, plus 30 days after closure.
- Billing and tax records: at least six (6) years after the end of the tax year to which they relate, in line with HMRC requirements (Schedule 11 paragraph 6 VATA 1994 and equivalent).
- Support tickets: three (3) years after closure of the ticket.
- Telemetry and crash logs (raw): 90 days, after which they are aggregated to a non-identifiable form.
- Audit logs and security events: 13 months.
- Marketing preferences and unsubscribe records: indefinitely, so that we can honour your unsubscribe.
- Records relating to legal claims: until the relevant limitation period has expired (typically six years in England, longer for deeds and certain claims).
After the retention period, we either delete or irreversibly anonymise the relevant personal data.
8. Cookies and similar technologies
trycodus.com uses a small number of cookies and similar technologies. Where any of them are not strictly necessary for the website to function, we ask for your consent in line with PECR before they are set.
- Strictly necessary cookies: session, authentication, load-balancing, CSRF protection, language preference. These are set without consent because the website cannot reasonably operate without them.
- Analytics cookies: we use privacy-respecting, aggregated analytics to understand site usage at a non-identifying level. We avoid third-party advertising cookies.
- Functional cookies: remembering your dark-mode preference, your CTA dismissals, etc.
The codus desktop Software does not use browser cookies. It stores local-application state (settings, tokens, cached search indexes) on your device, in a per-user application directory provided by your operating system. You can clear that state by uninstalling codus or by deleting the application support folder.
9. Your rights
Subject to the conditions and exemptions in the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:
- Right of access — to obtain a copy of the personal data we hold about you.
- Right to rectification — to correct inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”) — to ask us to delete your personal data in defined circumstances.
- Right to restriction of processing — to ask us to pause processing in defined circumstances.
- Right to data portability — to receive certain personal data in a structured, commonly used, machine-readable format.
- Right to object — to processing based on legitimate interests, and an absolute right to object to processing for direct marketing.
- Rights in relation to automated decision-making — codus does not currently make any decision producing legal or similarly significant effects about you solely by automated means.
- Right to withdraw consent — where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right to complain to the ICO — at any time, free of charge, at ico.org.uk. We would, however, appreciate the chance to address your concern first.
To exercise any of these rights, email [email protected]. We will respond within one month, with the option to extend by a further two months for complex requests as permitted by law. We may need to verify your identity before acting on a request.
10. Google user data
When you connect a Google account to codus (for Google Search Console, Google Analytics, Google Tag Manager or Google Ads), codus’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We only access the Google data needed for the features you ask codus to perform, use it solely to provide and improve those user-facing features, and do not transfer or sell it to third parties, use it for advertising, or allow humans to read it except with your consent, for security or to comply with law. Your Google OAuth tokens are stored encrypted on your own device via your operating system’s keychain and are never stored on our servers; API requests are made directly from your device to Google. You can disconnect Google at any time in codus (Settings, Integrations), or revoke access at myaccount.google.com/permissions.
11. Security
We use industry-standard technical and organisational measures to protect your data, including TLS encryption in transit, encryption at rest for our database, role-based access controls, multi-factor authentication on administrative systems, secret rotation, regular backups, vendor due diligence and audit logging. No method of transmission or storage is, however, completely secure. If you believe your account or personal data has been compromised, contact us immediately at [email protected].
12. Personal-data breaches
Where a personal-data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the ICO without undue delay, and where feasible no later than 72 hours after we become aware of it, in accordance with Article 33 UK GDPR. Where a breach is likely to result in a high risk, we will also notify affected individuals in accordance with Article 34 UK GDPR.
13. Children
codus is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data to us, please contact [email protected] and we will delete it.
14. Changes to this policy
We may update this policy from time to time. The current version is always at trycodus.com/privacy with a “Last updated” date. Material changes will be notified by email and/or in-product. Continued use of the Service after a change takes effect constitutes acceptance of the change.
15. Contact
See also our Terms of Service and Legal & corporate information.