# Privacy Policy — How we collect, use, and protect personal data. This Privacy Policy explains how **Code Together, Inc.** (**"Company,"** **"we,"** or **"us"**) collects, uses, and shares personal data when you visit our website or use the "Code Together" platform, including any related plugins or extensions (the **"Service"**). This Privacy Policy is incorporated into, and should be read together with, our **Terms of Service** and, where applicable, your signed SaaS Agreement with Company. ## 1. Scope — personal data vs. Customer Data **1.1 What This Policy Covers.** This Privacy Policy covers **personal data** — information that identifies or relates to an identifiable individual, such as account holders and Authorized Users (for example, names, email addresses, login activity, and plugin telemetry described in Section 6). **1.2 What This Policy Does Not Cover.** This Privacy Policy does not govern the source code, repositories, or other content Customer submits to the Service in the course of using it (**"Customer Data"**). Ownership, confidentiality, and use of Customer Data — including Company's rights to use Aggregated Data derived from it — are governed by the Intellectual Property and Data Protection sections of the applicable SaaS Agreement (Trial Services Agreement, or the Month-to-Month or Annual SaaS Subscription Agreement), not by this Privacy Policy. Where Customer Data itself contains personal data (for example, a developer's name in a code comment or commit history), Company handles that personal data consistently with the security and confidentiality commitments in the applicable SaaS Agreement and with the principles in this Privacy Policy. **1.3 Personal Data Within Code Content.** In providing the Service, including real-time collaborative editing, Company's systems may access and process the code content Customer and its Authorized Users submit, and that content may sometimes include personal data (for example, a name in a comment or commit message, or a credential accidentally checked in). Company does not extract, separately catalog, or independently use personal data found within code content; it is processed and retained solely as part of Customer Data itself, under the data protection, security, and retention terms of the applicable SaaS Agreement. Customer and its Authorized Users are responsible for the content they submit to the Service and should avoid checking in sensitive personal data (such as government ID numbers, financial account numbers, or health information) or credentials as part of code content. **1.4 No Training on Customer Data.** Company does not use Customer Data — including any personal data it may contain — to train Company's or any third party's machine learning or artificial intelligence models. Where the Service provides AI-powered or analytics features, Company analyzes data in the aggregate, as described in Section 3.2 below. ## 2. Information we collect We collect the following categories of information: - **Account Information:** name, work email, company name, job title, and password (stored in hashed form), collected when you register for an account. - **Billing Information:** billing contact name, address, and payment details, collected (directly or through a payment processor) when you subscribe to a paid tier. - **Usage Data:** information about how you and your Authorized Users interact with the Service, such as features used, session activity, and coding-activity metadata (e.g., commit frequency or collaboration patterns) used to generate the Service's team insights and analytics. - **Device and Log Data:** IP address, browser type, operating system, and access timestamps, collected automatically when you use the Service or website. - **Plugin/Extension Telemetry:** if you install a Company IDE, editor, or CI/CD plugin or extension, the plugin may collect anonymized telemetry, as described in Section 6 below. - **Communications:** information you provide when you contact support, respond to surveys, or otherwise communicate with us. - **Cookies and Similar Technologies:** as described in Section 5 below. ## 3. How we use information **3.1** We use personal data to: - Provide, operate, secure, and maintain the Service, including authenticating accounts and generating the team insights, dashboards, and reports that are core to the Service; - Process payments and manage subscriptions and billing; - Communicate with you about your account, updates, security notices, and (where permitted) product news; - Provide customer support and respond to inquiries; - Monitor, analyze, and improve the Service, and develop new features, including using plugin telemetry to diagnose performance issues; - Detect, investigate, and prevent fraud, abuse, and security incidents; - Comply with legal obligations and enforce our Terms of Service and applicable SaaS Agreements. **3.2 No Model Training; Aggregate Analysis Only.** To generate the Service's insights, dashboards, and AI-powered features, Company analyzes Customer Data and Usage Data in the aggregate (for example, patterns across a team's commits and collaboration activity) to produce team- and organization-level insights and recommendations. **Company does not use Customer Data, or personal data contained within it, to train Company's or any third party's machine learning or artificial intelligence models.** This commitment is also reflected in the Intellectual Property section of the applicable SaaS Agreement. ## 4. Legal bases for processing (EEA/UK users) If you are located in the European Economic Area or the United Kingdom, we process personal data on the following legal bases, as applicable: performance of a contract with you (e.g., providing the Service); our legitimate interests (e.g., securing and improving the Service), provided those interests are not overridden by your data protection rights; compliance with a legal obligation; and, where required, your consent (e.g., for certain marketing communications or non-essential cookies). ## 5. Cookies and tracking technologies We use cookies and similar technologies to operate the Service, remember your preferences, and understand usage patterns. You can control cookies through your browser settings; disabling certain cookies may limit functionality of the Service or website. Where required by law, we will request your consent before setting non-essential cookies. ## 6. Plugin and extension telemetry **6.1 What Plugin Telemetry Includes.** Company's IDE, editor, and CI/CD plugins and extensions may collect anonymized telemetry, such as feature usage frequency, session duration, performance metrics, and error or crash diagnostics, to help us operate, secure, and improve the Service. Plugin telemetry is designed not to include the content of Customer Data (such as source code) or to directly identify an individual. **6.2 Duration of Collection.** A Company plugin or extension collects telemetry for as long as it remains installed on a device, including after a subscription has ended or an account has been closed, unless and until it is uninstalled. As described in the applicable SaaS Agreement and our Terms of Service, Customer is responsible for uninstalling Company's plugins and extensions from its and its Authorized Users' systems upon termination of its subscription in order to stop telemetry collection. **6.3 Use of Plugin Telemetry.** Company uses plugin telemetry in the aggregate to operate, secure, diagnose, and improve the Service and its plugins, consistent with Section 3.2 above. ## 7. How we share information We may share personal data with: - **Service Providers:** vendors who help us operate the Service (e.g., cloud hosting, payment processing, analytics, customer support tools), under confidentiality and data protection obligations; - **Your Organization:** if you access the Service through an employer or customer account, information about your activity may be visible to administrators of that account; - **Aggregated or De-Identified Data:** we may share data that has been aggregated or de-identified such that it no longer reasonably identifies you, consistent with the Aggregated Data provisions of the applicable SaaS Agreement; - **Legal and Safety:** where required to comply with law, respond to legal process, or protect the rights, property, or safety of Company, our users, or others; - **Business Transfers:** in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections. **We do not sell personal data to third parties for their own marketing purposes.** ## 8. Data retention We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes, including as described in the Effect of Termination provisions of the applicable SaaS Agreement. Plugin telemetry is retained consistent with Section 6 and is not tied to Customer Data retention or deletion timelines. We will delete or de-identify personal data when it is no longer needed, except where retention is required by law. ## 9. Data security We maintain administrative, technical, and physical safeguards designed to protect personal data, consistent with the security commitments in the applicable SaaS Agreement. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. ## 10. International data transfers We may process and store personal data in the United States and other countries. Where we transfer personal data from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of protection, we rely on appropriate safeguards, such as Standard Contractual Clauses, as required by applicable law. ## 11. Your rights and choices Depending on your location, you may have rights to: access, correct, or delete your personal data; object to or restrict certain processing; port your data; and withdraw consent where processing is based on consent. California residents may have additional rights under the CCPA/CPRA, including the right to know what personal data we collect and to opt out of certain sharing. To exercise these rights, contact us at **privacy@codetogether.com**. We will respond in accordance with applicable law. If you access the Service through an employer or customer account, some requests may need to be directed to that organization as the account administrator. ## 12. Children's privacy The Service is intended for business use by adults and is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, please contact us so we can delete it. ## 13. Changes to this Privacy Policy We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (such as by email or an in-product notice) before the changes take effect. ## 14. Contact us If you have questions about this Privacy Policy or our data practices, contact us at: **Code Together, Inc.** Email: privacy@codetogether.com --- - Human view of this page: https://codetogether.com/privacy - All pages as Markdown: https://codetogether.com/llms.txt - Contact: info@codetogether.com CodeTogether · Patent pending