Privacy Policy · CodeMote
Last updated: 26 July 2026
This policy was drafted by the developer of CodeMote, not by a lawyer, and it is not legal advice. It describes what the software actually does. If you find a difference between this document and the product's behaviour, that is a bug and we want to hear about it.
1. Who we are (data controller)
We are the data controller for the personal data processed through the CodeMote web application at codemote.dev, under Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended.
2. What we never see
CodeMote connects your browser to a machine you already control, over a tunnel you start yourself. That connection does not pass through our servers, which means we never see, receive or store:
The tunnel you choose is part of the path. CodeMote reaches your machine through a tunnel you start yourself: Cloudflare, Microsoft devtunnel, ngrok or Tailscale. The connection is encrypted in transit, but that provider operates the path, and depending on which one you pick it can see the traffic crossing it. Which provider to trust is your choice, governed by that provider's terms rather than ours. We are not on that path at all.
Coding agents run on your machine, under your own API keys or subscriptions. Your prompts and your code go to those vendors (Anthropic, OpenAI, Cursor or whoever you have chosen) under their own privacy terms, and never through us.
Details of the machines you connect to stay in your browser. Host addresses, pairing tokens, saved connections, saved terminal commands and your interface preferences are stored in your browser's localStorage on the device you are using. They are never transmitted to us, and clearing your browser storage removes them.
What we do process is the small amount of data needed to run an account and a subscription, listed next.
3. What we process
| What | Where it lives | Why | How long |
|---|---|---|---|
| Email address, account identifier, creation time | Our database (Turso) | Create and operate your account | Until you delete the account |
| Session token and expiry, IP address, user agent | Our database (Turso) | Keep you signed in; detect and limit abuse | 7 days from last use; using the app rolls the expiry forward, so an account you keep visiting stays signed in |
| One-time sign-in code and its expiry | Our database (Turso) | Prove you control the email address | 5 minutes, after which the code is invalid |
| Subscription grants: capability, source, status, period end | Our database (Turso) | Decide what your account may use | Life of the account; deleting your account deletes them. The tax record of a purchase is held by Polar, not by us. |
| Founder seat number | Our database (Turso) | Allocate the twenty free seats | Released when the account is deleted |
| Billing notifications from our payment providers, once web purchases are live | Our database (Turso) | Apply purchases reliably, and debug them when they fail | Deleted once no longer needed for billing support |
| Host addresses, pairing tokens, saved connections, preferences, saved commands | Your browser only | Reconnect without retyping | Until you clear them; never sent to us |
| Server request logs, including IP address | Vercel | Serve and secure the site | Vercel's own retention |
| Recipient address and delivery status of your sign-in email | Resend | Deliver the code | Resend's own retention |
| Name, address, tax status and payment details of a purchase | Polar, as Merchant of Record (we receive only order and subscription metadata) | Sell the subscription and meet tax obligations | Up to 10 years for invoicing records, under Italian law |
| App user identifier and subscription status | Apple and RevenueCat | Honour an iOS purchase on the web | Life of the account |
We do not ask for your name, and nothing in the product requires you to give one.
4. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating your account, signing you in, running the service | Performance of a contract (Art. 6(1)(b)) |
| Managing subscriptions, entitlements and renewals | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, rate limiting, server logs | Legitimate interest (Art. 6(1)(f)) |
| Answering your support and privacy requests | Legitimate interest (Art. 6(1)(f)) |
| Invoicing and tax records | Legal obligation (Art. 6(1)(c)) |
There is no consent-based processing today, because there is no analytics and no marketing. If that ever changes, this policy changes first, and we ask you before we start.
5. Who else processes it
| Provider | What they get |
|---|---|
| Vercel Inc. | Hosting. Sees requests to codemote.dev, including IP addresses, in its logs. |
| Turso (Chiselstrike Inc.) | Runs the database holding your account, sessions and grants. |
| Resend (Plus Five Five, Inc.) | Your email address, to deliver a sign-in code. |
| Polar Software Inc. | Merchant of Record for web purchases. Collects and holds the billing and payment data; we receive order and subscription metadata only. |
| Apple Inc. and RevenueCat, Inc. | Purchase and subscription status for the iOS app. |
Each acts under its own privacy terms. Some are outside the EU/EEA; those transfers rely on appropriate safeguards, such as the EU Standard Contractual Clauses or an adequacy decision.
Tunnel providers (Cloudflare, Microsoft devtunnel, ngrok, Tailscale) are chosen and started by you on your own machine. They are not our processors, and your use of them is governed by their own terms.
We do not sell personal data, and we do not share it for advertising.
6. How long we keep it
Retention is stated per item in the table in section 3. In summary: sign-in codes last minutes, a session lasts a week from the last time you used it, account data lasts until you delete the account, and invoicing records are kept as long as Italian tax law requires, generally up to ten years.
7. Cookies
CodeMote sets one cookie: a strictly necessary, httpOnly session cookie that keeps you signed in. It is not used to profile you and it is not shared.
There is no analytics, no tracking, no advertising and no third-party cookie in the web application. Because we set nothing beyond what is strictly necessary to provide a service you asked for, no consent banner is required, and we would rather not show you one. If we ever add analytics, this policy is updated first and consent is asked for where the law requires it.
8. Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw any consent you have given.
Two of these are worth knowing in practice:
Deleting your account does not cancel a subscription billed by Polar or Apple; cancel that with them, as described in the Terms of Service.
9. Complaints
If you believe we have handled your data unlawfully, please tell us first; we would rather fix it. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of the EU country where you live.
10. Age
The service is for people 18 years of age or older. We do not knowingly process the data of children, and we will delete such data if we learn we hold it.
11. Security
We use measures appropriate to the risk, including:
No system is perfectly secure. You remain responsible for the machine you connect to, for the pairing tokens held in your browser, and for the devices you stay signed in on.
12. Changes to this policy
We may update this policy. Material changes are signalled by a new "Last updated" date and, where appropriate, a notice in the application.
13. Contact
Questions about privacy, or a request about your data: s.castellitti.dev@gmail.com. Salvatore Castellitti, Via Giacinto Albino 9, 86100 Campobasso, Italy.