← Cody Labs

Cody Labs website privacy

Effective 14 August 2026

No advertising trackers, cookies, user identifiers, or customer files are used for Cody Labs acquisition measurement.

Privacy-preserving usage events

When you click a Cody Labs install, checkout, template-download, or tool link, or interact with a free tool or demo, our first-party site code validates three allowlisted fields: the Cody Labs product, the action, and the page/tool source. Only daily counts grouped by product and action, together with the aggregate's last-updated time, are retained. The source is discarded before storage, and no individual event log or exact visitor timestamp is kept. This lets us see which products and actions are useful without tracking individual visitors.

Our application code does not store your IP address, user agent, email address, URL query string, account identity, file contents, invoice data, project data, or a device/browser identifier. Events cannot be tied into a browsing history for a person. Only atomic daily totals by product and action are stored; totals older than 90 days are deleted on the next event or dashboard refresh and are never included in the 30-day dashboard.

Files and browser-based tools

The invoice CSV checker reads the file or pasted text only in your browser. It does not upload the CSV to Cody Labs. Downloadable workbook templates are static files.

Hosting and external destinations

Cloudflare hosts codylabs.uk and processes network requests needed to deliver the site and its first-party event endpoint under Cloudflare’s own terms. If you follow a link to Google Workspace Marketplace, Visual Studio Marketplace, Polar checkout, or another external service, that service’s privacy policy applies from that point.

For endpoint abuse prevention only, the acquisition endpoint runs behind Cloudflare Pages and accepts a connection address only when Cloudflare's platform-supplied edge metadata is present. Edge code converts that address into a secret-keyed, daily rotating rate-limit value. Only the current minute bucket is active; stale buckets are opportunistically pruned during subsequent acquisition requests. The derived value is never added to an analytics event or exposed in the dashboard. The raw address is not stored, and the derived value cannot link activity across days.

Product data

This page covers the public website. Each product’s own privacy page explains the data flow inside that add-on or extension. The usage events described here never include the business data handled by a product.

Contact

Questions or privacy requests: [email protected].