Privacy Policy

Effective date: September 6, 2026

1. Who we are

This Privacy Policy explains how CodeLens, a business based in the United States ("we", "us"), collects, uses, and shares information when you use the CodeLens website and dashboard (the "Service"). It should be read together with our Terms of Service.

We only ever collect what the Service actually needs to work, described below — nothing is collected for advertising, and we do not sell your personal information.

2. Information we collect

Account information. Your email address, the name and nickname you provide, and a profile picture (either one you choose or your GitHub avatar if you sign in with GitHub).

Authentication data. Sign-in sessions, and whether you've enabled two-factor authentication on your account. If you enable it, the authenticator code itself is verified directly by our authentication provider (Supabase) — we never see or store the raw secret behind it.

GitHub data. If you connect a GitHub account, we store an access token that lets us read the repositories you choose to connect, and basic profile info (your GitHub username and avatar). If you use the coding agent feature and explicitly approve a change, that same token is used to create a branch and open a pull request on your behalf — we never push directly to your default branch, and never take any repository action without your explicit click.

Repository content. The file contents of any repository you connect (via GitHub or direct upload), which we read to build your Project Brain and to answer your questions.

Content you create. Your chat messages and questions, any files you attach to them, diagrams you generate, and — if you're part of a team — messages, reactions, and files you post in team chat.

Team and collaboration data. Which teams you belong to, your role, and invitations you send or receive.

Usage data. How much of your monthly usage allowance you've consumed, which model and features you used, and timestamps — needed to enforce plan limits and keep the Service reliable.

Payment data. If you subscribe to a paid plan, our payment provider Paddle collects and processes your billing details directly — we only receive confirmation of your subscription status, not your full card number.

3. How we use this information

  • To operate the Service: authenticate you, analyze the repositories you connect, and generate answers, diagrams, and code.
  • To provide team features: sharing projects and chat with people you invite.
  • To process payments and manage your subscription.
  • To enforce usage limits appropriate to your plan.
  • To keep the Service secure — detecting abuse, fraud, and unauthorized access.
  • To respond when you contact support.
  • To send you service-related emails (e.g. sign-in codes, billing receipts, security alerts). We won't send marketing email without your consent.

4. Who we share it with

We share data only with the service providers that help us run CodeLens, each bound by their own data-protection terms, and only to the extent needed for the purpose described:

  • Supabase — hosts our database and handles authentication and session storage. Your account data, connected repository data, chat history, and team data are stored here.
  • OpenRouter, and the underlying AI model provider for whichever model you select (for example Anthropic, OpenAI, Google, Meta, or DeepSeek) — receives your chat messages and the repository excerpts needed to answer them, in order to generate a response. We do not control, and this policy does not cover, how a third-party model provider itself retains or uses that data beyond generating your response; free-tier models in particular may be offered under different (sometimes less restrictive) data-handling terms than paid ones, as disclosed by that provider.
  • GitHub — used for sign-in and to read (or, only with your explicit action, write to) the repositories you connect.
  • Paddle — processes payment and billing information for paid subscriptions, as our Merchant of Record.

If you're part of a team, other members of that team can see the content you post in shared team chat and any projects the team owner has shared with the team, per that team's own access settings.

Authorized CodeLens personnel may access account and usage data when necessary for customer support, security investigations, fraud prevention, or legal compliance. This kind of internal access is restricted to a small number of people, requires its own two-factor authentication, and is never used to browse user data outside of a specific, legitimate need.

We do not sell your personal information, and we do not share it with third parties for their own advertising purposes. We may disclose information if required by law, such as in response to a valid legal request.

5. Cookies

We use a single functional cookie to keep you signed in between visits. We don't use advertising or cross-site tracking cookies, and we don't share cookie data with ad networks.

6. Data retention

We keep your data for as long as your account is active. If you delete your account, we delete your profile, connected repository data, and chat history within 30 days, except where we're required to keep certain records for longer — for example, billing records we're legally required to retain, or information needed to resolve a dispute or enforce our agreements.

Disconnecting your GitHub account revokes our access to your repositories immediately; you can also revoke that access at any time from your GitHub account's own authorized-applications settings.

7. Security

Data is encrypted in transit. Access to your data is governed by row-level security rules in our database, so one account can never read another account's private data through normal use of the Service, and we support optional two-factor authentication for your account. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, industry-standard measures to protect your information.

8. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data (most of this you can already edit yourself in Settings).
  • Request deletion of your account and associated data.
  • Export your data in a portable format.
  • Object to or restrict certain processing, or withdraw consent where processing is based on it.

To exercise any of these, contact us at privacy@codelens.me. If you're in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.

9. Children's privacy

The Service is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we'll delete it.

10. International data transfers

Our service providers may process and store data in countries other than your own. Where that involves a transfer out of the EU/UK/Switzerland, we (or the provider on our behalf) rely on recognized safeguards such as Standard Contractual Clauses.

11. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material, we'll notify you by email or through the Service before it takes effect.

12. Contact

Questions about this policy or your data? privacy@codelens.me.