Privacy Policy

Last updated August 16, 2026 · Codespective (codespective.com)

Who we are

Codespective (“we”, “us”) provides software that helps you understand your product and codebase — including GitHub repository analysis, product specifications, architecture views, and LaunchGuard readiness scoring. This policy describes how we handle information for the MVP at codespective.com.

Account & authentication

You may create an account with email/password or sign in with GitHub via our authentication provider (Supabase Auth). We store account identifiers such as user id, email, and profile display name.

GitHub connection

If you connect GitHub, we receive an OAuth access token with the scopes you approve (typically read:user and repo). That token is encrypted at rest on our servers and is used only to list repositories, import source for analysis, and refresh project readiness. We do not store the token in browser localStorage. You may disconnect GitHub at any time in Settings, which deletes the stored token.

Project and analysis data

Connected GitHub and public URL imports are server-processed. For those modes, we may process repository source and store snippet-free analysis graphs, project metadata, and readiness summaries associated with your account. GitHub imports are not covered by the Private Analysis guarantee.

Private Analysis

Private ZIP and Private Folder analysis keeps raw source in browser worker memory. We exclude sensitive and generated files, redact suspected secrets before local model use, and do not send repository source, snippets, paths, repository names, or symbols to Codespective, Supabase, Google Analytics, or an external model API. Raw files are not stored in localStorage or IndexedDB and are released when the worker is cleared, the tab closes, you sign out, or the page reloads.

If you choose local model assistance, WebLLM downloads a model to browser-managed cache before source enters the analysis worker. The model then runs with WebGPU on your device. Browser extensions and a compromised device are outside this privacy boundary.

Optional cloud enhancement

Cloud enhancement is a separate, one-run choice. Before sending, we show the exact sanitized payload containing only your approved goal, framework and dependency classifications, aggregate counts, and boolean readiness outcomes. It uses Codespective-managed model credentials and does not remember blanket consent. Browser storage of personal OpenAI or Gemini keys is not used for repository analysis.

Cookies & local storage

We use cookies for authenticated sessions (Supabase). Some preferences may use browser localStorage on your device. Clearing site data removes local preferences. Your analytics choice is stored locally so we can respect it on later visits.

Optional analytics

If you select Accept analytics, we load Google Analytics 4 to measure visits, page engagement, sign-up and login methods, repository import and Build Pack outcomes, analysis refreshes, and checkout outcomes. Google Analytics may set first-party identifiers such as _ga cookies and process pseudonymous device, browser, approximate location, page, and interaction data. Purchase events may include the selected plan, billing interval, currency, amount, and Razorpay order identifier so duplicate purchases are not counted.

We do not send Google your account id, name, email, repository name or URL, source code, project or Build Pack id, payment signature, or raw error messages. Google advertising storage and personalization remain disabled, and we do not use the Google Analytics User-ID feature.

No Google Analytics tag or request is loaded before you opt in. You can change your choice through Cookie settings; withdrawing consent stops future collection on this device and removes accessible Google Analytics cookies. Analytics data already received by Google follows the retention settings of our Analytics property. Learn more in the Google Privacy Policy.

Email delivery and optional lifecycle messages

We use Zoho ZeptoMail to deliver necessary account, authentication, security, billing, and service-status messages. Delivery events such as successful delivery, deferral, bounce, and complaint may be processed to protect sending reputation and prevent repeated delivery to invalid addresses.

If you explicitly opt in, we use Zoho Campaigns for onboarding tips, product education, and re-engagement messages. We share the email address and limited account or product lifecycle fields needed to select relevant guidance. You can withdraw this consent in Settings or through the unsubscribe link in those messages. Withdrawing optional email consent does not disable necessary account or transaction messages.

Data retention & deletion

You may request deletion of your account data by contacting us. Disconnecting GitHub removes stored OAuth tokens. We retain project data while your account is active unless you delete projects or request erasure.

Sharing

We use infrastructure providers for hosting, database, authentication, AI processing, payments, and—when you consent—Google Analytics measurement. We do not sell your personal data. Shared public links you create may expose project documentation you choose to share.

Children

Codespective is not directed at children under 16.

Changes

We may update this policy as the product evolves. Material changes will be reflected by updating the date above.

Contact

Privacy questions: [email protected]. Also see our Support page.