Legal
Privacy Policy
Last updated: September 30, 2026
1. Information We Collect
We collect information that you provide directly, that is generated by your use of the Service, and that is necessary to operate and improve the platform. This includes:
- Account information — name, email address, and authentication credentials provided at registration.
- Enquiry and access-request information — the name, email address, and message you send us through the site's forms; the optional role and team-size answers on the access-request form; and the page you submitted from, along with any campaign parameters and the referring site's domain.
- Usage and activity data — tasks created, workflows executed, agent runs, session durations, and interactions with the Service interface.
- Cost and metering data — token counts, API call volumes, and associated spend data for the AI provider integrations you connect.
- Task content — descriptions, comments, code artefacts, and other content you or your agents submit as part of your work.
- Device and connection data — information about registered devices, including device identifiers and connectivity status, to enable agent-execution routing.
- Technical and log data — IP addresses, browser type, operating system, referring URLs, and error logs collected automatically to support security and reliability.
2. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Service;
- Authenticate your account and authorise access to workspaces and resources;
- Route tasks to registered devices and track execution progress;
- Calculate and display cost and usage metrics in your dashboard;
- Detect and prevent fraud, abuse, and security incidents;
- Diagnose technical issues and improve Service reliability;
- Communicate with you about your account, updates, and changes to these policies;
- Comply with applicable legal obligations.
We do not sell your personal information or use it for advertising purposes.
3. Legal Basis for Processing
Where data protection law requires a legal basis for processing personal data, we rely on the following:
- Contract performance — processing necessary to provide the Service under the agreement you enter into by accepting these Terms.
- Legitimate interests — processing necessary for the security of the Service, fraud prevention, product improvement, and analytics, where those interests are not overridden by your rights.
- Consent — where you have expressly opted in to specific processing, such as optional communications.
- Legal obligation — processing required to comply with applicable laws and regulatory requirements.
4. Data Retention
We retain your account and usage data for as long as your account is active or as needed to provide the Service. After account deletion, we retain data for a limited period as required by law or to resolve disputes. The service sets retention for task content and artefacts. Retention windows depend on your plan and on the operator's server settings.
To request deletion of your data, contact us. An instance operator runs the erasure. The app at app.codeherder.com has no self-serve deletion control.
5. Security Measures
We implement reasonable technical and organisational measures to protect your data against unauthorised access, disclosure, alteration, or destruction. These include:
- Encryption of data in transit using TLS;
- Optional container isolation for agent sessions, which an operator can choose per stage. The default runs agents as host processes; see agent isolation;
- Encryption at rest for workspace secrets, integration tokens and webhook secrets;
- Allow-listed, sign-in-protected access to the administration plane;
- Dependency vulnerability and secret scanning in our build pipeline.
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6. Sharing & Sub-processors
We do not share your personal information with third parties except as described below:
- AI providers — task content and prompts are sent to the AI model APIs you configure. Your use of those APIs is subject to the relevant provider's terms and privacy policy.
- Infrastructure and hosting providers — we use cloud infrastructure services to host, store, and deliver the Service. These providers process data on our behalf under appropriate data processing agreements.
- Source-control and code-hosting platforms — if you connect a git host integration, relevant task and repository data is exchanged with that platform.
- Legal and safety — we may disclose information where required by law, court order, or to protect the rights, property, or safety of CodeHerder, our users, or the public.
7. Cookies & Local Storage
The CodeHerder application sets one first-party session cookie. It is HttpOnly, Secure and SameSite=Strict, and it keeps you signed in. The application also uses browser local storage and session storage for preferences and workspace context. No third-party advertising or tracking cookies are used in the application.
This marketing site uses Google Analytics 4 to measure aggregate site usage — page views and a small number of conversion events such as opening the app or submitting the contact form. Google Analytics sets first-party _ga* cookies for this purpose; we do not use it for advertising, and no ad-related signals are shared. You can opt out using Google's Analytics opt-out browser add-on, or read Google's privacy policy for more detail.
8. Your Rights
Depending on your location, you may have rights under applicable data protection law, including the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Request deletion of your data (subject to legal retention requirements);
- Ask for a copy of your data in a portable format (the app has no export tool; requests go through support);
- Restrict or object to certain types of processing;
- Withdraw consent where processing is based on consent.
To exercise these rights, contact us. You can manage your account at app.codeherder.com. You may also have the right to lodge a complaint with a supervisory authority in your jurisdiction.
9. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child under 16 has provided personal information, we will take steps to delete that data promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will provide notice through the Service. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.