C:\> privacy

Privacy Policy

Last updated: July 13, 2026

Who we are

Codepanion ("we", "us") provides a business-to-business service that gives customer support teams an AI agent with read access to their organisation's source code, documentation, logs, and production databases. We are based in the United States and the service is hosted on Microsoft Azure in the Central US region.

For the content our customers connect to the service (source code, database contents, logs, documents), we act as a processor on the customer's behalf: we process it only to provide the service to that customer, under their instructions. For account and billing information we act as a controller.

What we collect and why

  • Account data — name, work email, and sign-in identifiers for the people your organisation invites, used to authenticate you and operate your tenant.
  • Customer content — the source code your CI pushes to us, database query results, log entries, and documentation pages the agent retrieves, plus the questions your team asks and the agent's answers. Used solely to answer your team's questions within your own tenant.
  • Usage and audit data — which tools the agent invoked, which files and tables it touched, token usage, and timestamps. Used for the audit trail we expose to you, for billing, and to operate the service.
  • Operational telemetry — service logs and performance metrics, used to keep the service healthy. We do not use third-party advertising or analytics trackers.

AI processing and where your data goes

The agent runs on Azure OpenAI / Azure AI Foundry models operated by Microsoft inside Azure. Microsoft is contractually committed to not using prompts or responses to train or improve its models. Your data is never used to train any AI model, by us or anyone else.

Our model deployments use Azure's Global Standard tier. This means that while your data is stored at rest in the United States, Microsoft may route individual model requests to Azure data centers in other regions worldwide for processing, in accordance with Microsoft's product terms. If your organisation requires processing to stay within a specific geography, contact us before onboarding.

Our current subprocessors are listed on the Security & Trust page. We will update that list and this policy before adding a new subprocessor or model provider.

Retention and deletion

Customer content is retained while your subscription is active so your team's investigation history stays useful. When a tenant is deleted, its data — code snapshots, embeddings, conversations, and stored credentials — is deleted from our systems. Audit log entries are retained as a record of processing. Backups age out on a rolling schedule.

Security

Data is encrypted in transit and at rest. Customer database credentials are held in Azure Key Vault (or never leave your network at all, with the on-prem connector). Tenants are isolated at the data layer. Details, including our vulnerability disclosure contact, are on theSecurity & Trust page.

Your rights

Depending on where you are, you may have rights to access, correct, export, or delete personal information we hold about you. Members of a customer's team should direct requests to their organisation (the controller of their workspace); we support our customers in fulfilling them. You can also contact us directly athello@codepanion.app.

Changes

We will post updates to this policy here and update the date above. For material changes affecting how customer content is processed — such as a new model provider — we will notify customers before the change takes effect.

This is a plain-language policy for a product in early access; a fuller legal document (including a signable Data Processing Agreement) is available to customers on request athello@codepanion.app.