CodeMote

Privacy Policy · CodeMote

Last updated: 26 July 2026

This policy was drafted by the developer of CodeMote, not by a lawyer, and it is not legal advice. It describes what the software actually does. If you find a difference between this document and the product's behaviour, that is a bug and we want to hear about it.


1. Who we are (data controller)

Salvatore Castellitti, sole trader (ditta individuale)
Via Giacinto Albino 9, 86100 Campobasso, Italy
P.IVA 01945740700
s.castellitti.dev@gmail.com

We are the data controller for the personal data processed through the CodeMote web application at codemote.dev, under Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended.


2. What we never see

CodeMote connects your browser to a machine you already control, over a tunnel you start yourself. That connection does not pass through our servers, which means we never see, receive or store:

your source code, or any file in your workspace;
your terminal sessions, their input or their output;
your git history, diffs, branches or pull requests;
your notes;
your conversations with coding agents.

The tunnel you choose is part of the path. CodeMote reaches your machine through a tunnel you start yourself: Cloudflare, Microsoft devtunnel, ngrok or Tailscale. The connection is encrypted in transit, but that provider operates the path, and depending on which one you pick it can see the traffic crossing it. Which provider to trust is your choice, governed by that provider's terms rather than ours. We are not on that path at all.

Coding agents run on your machine, under your own API keys or subscriptions. Your prompts and your code go to those vendors (Anthropic, OpenAI, Cursor or whoever you have chosen) under their own privacy terms, and never through us.

Details of the machines you connect to stay in your browser. Host addresses, pairing tokens, saved connections, saved terminal commands and your interface preferences are stored in your browser's localStorage on the device you are using. They are never transmitted to us, and clearing your browser storage removes them.

What we do process is the small amount of data needed to run an account and a subscription, listed next.


3. What we process

WhatWhere it livesWhyHow long
Email address, account identifier, creation timeOur database (Turso)Create and operate your accountUntil you delete the account
Session token and expiry, IP address, user agentOur database (Turso)Keep you signed in; detect and limit abuse7 days from last use; using the app rolls the expiry forward, so an account you keep visiting stays signed in
One-time sign-in code and its expiryOur database (Turso)Prove you control the email address5 minutes, after which the code is invalid
Subscription grants: capability, source, status, period endOur database (Turso)Decide what your account may useLife of the account; deleting your account deletes them. The tax record of a purchase is held by Polar, not by us.
Founder seat numberOur database (Turso)Allocate the twenty free seatsReleased when the account is deleted
Billing notifications from our payment providers, once web purchases are liveOur database (Turso)Apply purchases reliably, and debug them when they failDeleted once no longer needed for billing support
Host addresses, pairing tokens, saved connections, preferences, saved commandsYour browser onlyReconnect without retypingUntil you clear them; never sent to us
Server request logs, including IP addressVercelServe and secure the siteVercel's own retention
Recipient address and delivery status of your sign-in emailResendDeliver the codeResend's own retention
Name, address, tax status and payment details of a purchasePolar, as Merchant of Record (we receive only order and subscription metadata)Sell the subscription and meet tax obligationsUp to 10 years for invoicing records, under Italian law
App user identifier and subscription statusApple and RevenueCatHonour an iOS purchase on the webLife of the account

We do not ask for your name, and nothing in the product requires you to give one.


4. Why we process it, and on what legal basis

PurposeLegal basis
Creating your account, signing you in, running the servicePerformance of a contract (Art. 6(1)(b))
Managing subscriptions, entitlements and renewalsPerformance of a contract (Art. 6(1)(b))
Security, abuse prevention, rate limiting, server logsLegitimate interest (Art. 6(1)(f))
Answering your support and privacy requestsLegitimate interest (Art. 6(1)(f))
Invoicing and tax recordsLegal obligation (Art. 6(1)(c))

There is no consent-based processing today, because there is no analytics and no marketing. If that ever changes, this policy changes first, and we ask you before we start.


5. Who else processes it

ProviderWhat they get
Vercel Inc.Hosting. Sees requests to codemote.dev, including IP addresses, in its logs.
Turso (Chiselstrike Inc.)Runs the database holding your account, sessions and grants.
Resend (Plus Five Five, Inc.)Your email address, to deliver a sign-in code.
Polar Software Inc.Merchant of Record for web purchases. Collects and holds the billing and payment data; we receive order and subscription metadata only.
Apple Inc. and RevenueCat, Inc.Purchase and subscription status for the iOS app.

Each acts under its own privacy terms. Some are outside the EU/EEA; those transfers rely on appropriate safeguards, such as the EU Standard Contractual Clauses or an adequacy decision.

Tunnel providers (Cloudflare, Microsoft devtunnel, ngrok, Tailscale) are chosen and started by you on your own machine. They are not our processors, and your use of them is governed by their own terms.

We do not sell personal data, and we do not share it for advertising.


6. How long we keep it

Retention is stated per item in the table in section 3. In summary: sign-in codes last minutes, a session lasts a week from the last time you used it, account data lasts until you delete the account, and invoicing records are kept as long as Italian tax law requires, generally up to ten years.


7. Cookies

CodeMote sets one cookie: a strictly necessary, httpOnly session cookie that keeps you signed in. It is not used to profile you and it is not shared.

There is no analytics, no tracking, no advertising and no third-party cookie in the web application. Because we set nothing beyond what is strictly necessary to provide a service you asked for, no consent banner is required, and we would rather not show you one. If we ever add analytics, this policy is updated first and consent is asked for where the law requires it.


8. Your rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw any consent you have given.

Two of these are worth knowing in practice:

Erasure is self-service. You can delete your account from inside the application at any time. This erases the account, its sessions and its subscription grants, and returns any founder seat to the pool. It is immediate, and it does not depend on us answering an email.
Access and portability: write to s.castellitti.dev@gmail.com and we will respond within the period the GDPR allows, normally one month.

Deleting your account does not cancel a subscription billed by Polar or Apple; cancel that with them, as described in the Terms of Service.


9. Complaints

If you believe we have handled your data unlawfully, please tell us first; we would rather fix it. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of the EU country where you live.


10. Age

The service is for people 18 years of age or older. We do not knowingly process the data of children, and we will delete such data if we learn we hold it.


11. Security

We use measures appropriate to the risk, including:

session cookies that JavaScript cannot read (httpOnly), sent over HTTPS;
one-time sign-in codes that expire after minutes and stop working after a few wrong attempts;
rate limiting on sign-in;
transport encryption (HTTPS and WSS) between your browser and your machine; read section 2 for what the tunnel provider you choose can see along the way.

No system is perfectly secure. You remain responsible for the machine you connect to, for the pairing tokens held in your browser, and for the devices you stay signed in on.


12. Changes to this policy

We may update this policy. Material changes are signalled by a new "Last updated" date and, where appropriate, a notice in the application.


13. Contact

Questions about privacy, or a request about your data: s.castellitti.dev@gmail.com. Salvatore Castellitti, Via Giacinto Albino 9, 86100 Campobasso, Italy.