// legal

Privacy Policy

Effective June 14, 2026 · Codeplace, a Sprisa Inc. product

This policy explains what personal data Sprisa Inc. collects when you use Codeplace, why we collect it, who we share it with, and the choices and rights you have. We keep data collection to what the service actually needs.

In short: we collect your account email (via our login provider), billing details (via our payment processor), the resources your sandbox uses, and the content you create. We do not sell your personal data and we do not run advertising or cross-site tracking.

1Who we are

Codeplace (“codeplace,” the “Service”) is operated by Sprisa Inc. (“Sprisa,” “we,” “us”). For the purposes of the EU/UK General Data Protection Regulation (“GDPR”) and similar laws, Sprisa Inc. is the data controller for personal data processed through the Service. You can reach us at [email protected].

This policy covers codeplace.app, opencode.codeplace.app, docs.codeplace.app, and related dashboards and APIs. It does not cover third-party services you choose to connect (such as your AI model providers), which are governed by their own policies.

2Information we collect

We collect the following categories of personal data:

CategoryExamplesSource
Account & identityName, email address, and authentication metadata (e.g., login method, two-factor settings)You, via our authentication provider (Clerk)
BillingSubscription status, billing email, country, the last four digits and type of your card, and invoice history. We never receive or store your full card number.Our payment processor (Stripe)
Your contentFiles, code, prompts, and the HTML documents you create or publish in your sandboxYou
Connected credentialsAPI keys for model providers you choose to add, stored encryptedYou
Usage & technicalResource metrics (CPU, memory, disk), session and request logs, sandbox lifecycle events, IP address, browser/user-agent, approximate location derived from IPAutomatically
SupportMessages you send us and their contentsYou

We do not intentionally collect special categories of data (such as health or biometric data). Please do not store such data in fields we use for account administration.

3How we use it

We do not use your content to train machine-learning models, and we do not sell your personal data.

4Legal bases (GDPR)

Where the GDPR applies, we rely on these legal bases:

5Cookies & analytics

We use a small number of strictly necessary cookies and local storage values to keep you signed in and to remember your preferences. We do not use advertising or cross-site tracking cookies.

For aggregate usage statistics we run Umami, a privacy-first analytics tool that we self-host — your data stays with us and is not shared with a third-party analytics company. It is cookieless, sets no identifiers on your device, and does not track you across other sites. It records anonymous, aggregated metrics such as page views, referrers, and approximate country, with no profile that identifies you personally.

6Who we share it with

We share personal data only with service providers (“processors”) that help us run Codeplace, each under a data-processing agreement and only as needed:

ProviderPurposePolicy
Clerk (Clerk.com / Clerk, Inc.)Authentication & account managementclerk.com/legal/privacy
Stripe, Inc.Payment processing & subscription billingstripe.com/privacy
Cloudflare, Inc.CDN, DNS, edge caching, and R2 object storage for backups and published documentscloudflare.com/privacypolicy
Our hosting/infrastructure providerCompute and storage for sandboxesAvailable on request
Model providers you addRun your AI requests using keys you supplyTheir respective policies

We may also disclose data: (a) to comply with law or a valid legal request; (b) to protect the rights, safety, and security of Sprisa, our users, or the public; and (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you of any change in control or use of your personal data.

We do not sell your personal data, and we do not share it for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA).

7International transfers

We and our providers may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), together with additional measures where required.

8Data retention

We keep personal data only as long as needed for the purposes above:

DataRetention
Account & identityFor the life of your account, then deleted or anonymized within 90 days of closure (unless law requires longer).
Sandbox content & persistent volumeWhile your subscription is active. After cancellation, retained for a 30-day grace period, then permanently deleted. Backup copies in Cloudflare R2 are purged within 35 days of deletion.
Published documentsUntil you delete them or close your account, then removed (including from backups) within 35 days.
Connected API keysUntil you remove them or close your account.
Billing & invoicesUp to 7 years, to meet tax and accounting obligations.
Logs & resource metricsUp to 90 days, then deleted or aggregated into non-identifying form.

9Security

We use encryption in transit (TLS), isolation between tenant sandboxes, access controls, and encryption at rest for sensitive credentials. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

10Your rights

Depending on where you live, you may have some or all of the following rights regarding your personal data:

To exercise any right, email [email protected]. You may also access, update, or delete much of your data directly from your dashboard. We respond within 30 days (45 days under the CCPA, extendable where permitted), and we may need to verify your identity first. You can authorize an agent to act for you. If you are in the EEA/UK, you also have the right to lodge a complaint with your local data-protection authority.

11Content you publish

When you publish a document as public at docs.codeplace.app, anyone with the link can view it and it may be cached at the edge and indexed. Do not publish personal data or anything confidential that you do not want to be public. You can delete a published document at any time; cached and backup copies are purged on the schedule above.

12Children

Codeplace is not directed to children. You must be at least 18 years old (or the age of majority where you live) to use the Service, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

13Changes to this policy

We may update this policy from time to time. If we make a material change, we will update the effective date above and, where appropriate, notify you by email or in the dashboard before the change takes effect. Your continued use of the Service after an update means you accept the revised policy.

14Contact

Questions, requests, or complaints about privacy? Email [email protected], or write to Sprisa Inc. at the postal address published at sprisa.com. See also our Terms of Service.