// legal
Privacy Policy
This policy explains what personal data Sprisa Inc. collects when you use Codeplace, why we collect it, who we share it with, and the choices and rights you have. We keep data collection to what the service actually needs.
1Who we are
Codeplace (“codeplace,” the “Service”) is operated by Sprisa Inc. (“Sprisa,” “we,” “us”). For the purposes of the EU/UK General Data Protection Regulation (“GDPR”) and similar laws, Sprisa Inc. is the data controller for personal data processed through the Service. You can reach us at [email protected].
This policy covers codeplace.app, opencode.codeplace.app, docs.codeplace.app, and related dashboards and APIs. It does not cover third-party services you choose to connect (such as your AI model providers), which are governed by their own policies.
2Information we collect
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, email address, and authentication metadata (e.g., login method, two-factor settings) | You, via our authentication provider (Clerk) |
| Billing | Subscription status, billing email, country, the last four digits and type of your card, and invoice history. We never receive or store your full card number. | Our payment processor (Stripe) |
| Your content | Files, code, prompts, and the HTML documents you create or publish in your sandbox | You |
| Connected credentials | API keys for model providers you choose to add, stored encrypted | You |
| Usage & technical | Resource metrics (CPU, memory, disk), session and request logs, sandbox lifecycle events, IP address, browser/user-agent, approximate location derived from IP | Automatically |
| Support | Messages you send us and their contents | You |
We do not intentionally collect special categories of data (such as health or biometric data). Please do not store such data in fields we use for account administration.
3How we use it
- Provide the Service — create and authenticate your account, provision and run your sandbox, store your content, publish your documents, and transfer your session between devices.
- Billing — charge your subscription, send invoices and receipts, and handle renewals, cancellations, and failed payments.
- Operate, secure, and improve — monitor resource usage and capacity, detect and prevent abuse and fraud, debug, and improve reliability and performance.
- Communicate — send service, security, and transactional messages (including subscription and renewal notices). We do not send marketing email without your consent.
- Comply with law — meet tax, accounting, and other legal obligations, and respond to lawful requests.
We do not use your content to train machine-learning models, and we do not sell your personal data.
4Legal bases (GDPR)
Where the GDPR applies, we rely on these legal bases:
- Performance of a contract — to provide the Service you sign up for and to bill you.
- Legitimate interests — to secure the Service, prevent abuse, keep records, and improve the product, balanced against your rights.
- Legal obligation — to meet tax, accounting, and regulatory requirements.
- Consent — where we ask for it (e.g., optional communications). You can withdraw consent at any time.
5Cookies & analytics
We use a small number of strictly necessary cookies and local storage values to keep you signed in and to remember your preferences. We do not use advertising or cross-site tracking cookies.
codeplace_viewer— a session cookie that authenticates your sandbox.codeplace-theme— remembers your light/dark preference (local storage).- Session cookies set by our authentication provider (Clerk) to keep you signed in.
For aggregate usage statistics we run Umami, a privacy-first analytics tool that we self-host — your data stays with us and is not shared with a third-party analytics company. It is cookieless, sets no identifiers on your device, and does not track you across other sites. It records anonymous, aggregated metrics such as page views, referrers, and approximate country, with no profile that identifies you personally.
6Who we share it with
We share personal data only with service providers (“processors”) that help us run Codeplace, each under a data-processing agreement and only as needed:
| Provider | Purpose | Policy |
|---|---|---|
| Clerk (Clerk.com / Clerk, Inc.) | Authentication & account management | clerk.com/legal/privacy |
| Stripe, Inc. | Payment processing & subscription billing | stripe.com/privacy |
| Cloudflare, Inc. | CDN, DNS, edge caching, and R2 object storage for backups and published documents | cloudflare.com/privacypolicy |
| Our hosting/infrastructure provider | Compute and storage for sandboxes | Available on request |
| Model providers you add | Run your AI requests using keys you supply | Their respective policies |
We may also disclose data: (a) to comply with law or a valid legal request; (b) to protect the rights, safety, and security of Sprisa, our users, or the public; and (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you of any change in control or use of your personal data.
We do not sell your personal data, and we do not share it for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA).
7International transfers
We and our providers may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), together with additional measures where required.
8Data retention
We keep personal data only as long as needed for the purposes above:
| Data | Retention |
|---|---|
| Account & identity | For the life of your account, then deleted or anonymized within 90 days of closure (unless law requires longer). |
| Sandbox content & persistent volume | While your subscription is active. After cancellation, retained for a 30-day grace period, then permanently deleted. Backup copies in Cloudflare R2 are purged within 35 days of deletion. |
| Published documents | Until you delete them or close your account, then removed (including from backups) within 35 days. |
| Connected API keys | Until you remove them or close your account. |
| Billing & invoices | Up to 7 years, to meet tax and accounting obligations. |
| Logs & resource metrics | Up to 90 days, then deleted or aggregated into non-identifying form. |
9Security
We use encryption in transit (TLS), isolation between tenant sandboxes, access controls, and encryption at rest for sensitive credentials. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
10Your rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your data (“right to be forgotten”).
- Port your data to another service in a machine-readable format.
- Restrict or object to certain processing.
- Withdraw consent where processing is based on consent.
- Opt out of any “sale” or “sharing” and limit use of sensitive personal information (CCPA/CPRA). We honor Global Privacy Control (GPC) signals.
- Non-discrimination — we will not deny service or charge you differently for exercising these rights.
To exercise any right, email [email protected]. You may also access, update, or delete much of your data directly from your dashboard. We respond within 30 days (45 days under the CCPA, extendable where permitted), and we may need to verify your identity first. You can authorize an agent to act for you. If you are in the EEA/UK, you also have the right to lodge a complaint with your local data-protection authority.
11Content you publish
When you publish a document as public at docs.codeplace.app, anyone with the link can view it and it may be cached at the edge and indexed. Do not publish personal data or anything confidential that you do not want to be public. You can delete a published document at any time; cached and backup copies are purged on the schedule above.
12Children
Codeplace is not directed to children. You must be at least 18 years old (or the age of majority where you live) to use the Service, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
13Changes to this policy
We may update this policy from time to time. If we make a material change, we will update the effective date above and, where appropriate, notify you by email or in the dashboard before the change takes effect. Your continued use of the Service after an update means you accept the revised policy.
14Contact
Questions, requests, or complaints about privacy? Email [email protected], or write to Sprisa Inc. at the postal address published at sprisa.com. See also our Terms of Service.