- Home
- Privacy Policy
Privacy Policy
Last updated: July 15, 2026
Thank you for trusting Codemod Inc. ("Codemod", "we", "us", or "our") to help automate and orchestrate code modernization work. This Privacy Policy explains what information we collect, how we use it, how we share it, how long we retain it, and the choices you have.
If you have questions about this Privacy Policy or your data, contact us at privacy@codemod.com.
This Privacy Policy applies to Codemod's website, web application, platform, APIs, integrations, and related services (collectively, the "Service").
This Privacy Policy does not apply to customer-managed systems, source-code hosting accounts, identity providers, project-management systems, CI/CD systems, local developer environments, or third-party services that customers connect to Codemod, except for Codemod's processing of information through those integrations as part of the Service.
We may collect account and authentication information, including:
- Name, email address, username, profile image, user ID, and organization membership.
- Authentication provider identifiers, such as GitHub, GitLab, Google, SSO, OIDC, or SAML identifiers where configured.
- Session data, access tokens, refresh tokens, OAuth records, session cookies, expiration timestamps, IP address, user agent, and related security or authentication records.
Depending on how you use the Service, we may process customer content and product data, including:
- Organization, project, campaign, workflow, automation, insight, dashboard, Studio, package registry, API key, billing reference, and integration configuration records.
- Repository URLs, repository metadata, branches, commits, pull requests, merge requests, file paths, issue or project-management references, workflow parameters, and customer-configured values.
- Source-code content, code snippets, source archives, indexed code data, diffs, patches, package artifacts, workflow inputs, generated outputs, and files processed by Codemod features when you authorize or submit that content.
- Chat threads, prompts, code context, AI-assisted feature inputs and outputs, and related interaction history.
- Workflow, job, build, activity, audit, application, security, and operational logs.
We may collect website, usage, analytics, and telemetry data, including:
- Device, browser, operating system, IP address, approximate location, referral source, pages viewed, links clicked, feature usage, product events, and interaction data.
- Session replay, UI event, error, diagnostic, stack trace, performance, and debugging information where analytics or debugging tools are configured.
- User or organization identifiers, email address, and account context when needed to associate product activity with an authenticated account.
- Local browser storage or similar client-side state used for product functionality, such as Studio session state, UI preferences, or redirect state.
If you purchase paid services, we may process billing-related information such as customer email, order records, checkout session references, payment status, product or subscription references, amount, currency, and related payment metadata. Payment card information is processed by our payment processor. Codemod does not store full payment card numbers.
If you contact us, submit a form, request support, join a waitlist, schedule a demo, or communicate with us, we may collect contact information and communications such as name, email address, company, role, message content, support requests, call or meeting context, and related business communications.
We use information to:
- Provide, operate, maintain, secure, and improve the Service.
- Authenticate users, manage sessions, administer accounts, and enforce access controls.
- Connect to customer-authorized integrations and perform requested product functionality.
- Run workflows, codemods, package operations, indexing, Studio, Insights, automation, AI-assisted features, and related platform operations.
- Process payments, manage subscriptions, and maintain billing records.
- Monitor, debug, troubleshoot, measure, and improve product quality and performance.
- Detect, investigate, prevent, and respond to security incidents, abuse, fraud, unauthorized access, policy violations, and technical issues.
- Communicate with you about product updates, security matters, support, administrative notices, billing, and marketing where permitted.
- Maintain business, audit, compliance, legal, and security records.
- Comply with applicable laws, enforce agreements, and protect the rights, safety, and security of Codemod, our customers, users, and others.
Codemod includes AI-assisted features that may process prompts, code context, workflow context, repository metadata, generated outputs, and related product data to provide requested functionality. Depending on the feature and configuration, this data may be sent to approved AI providers or processed by Codemod-controlled systems.
You are responsible for deciding what data to submit to AI-assisted features and for avoiding unnecessary submission of secrets, credentials, regulated data, or other sensitive information unless that processing is appropriate for your use of the Service.
We may share information:
- With authorized service providers and subprocessors that help us operate, secure, improve, and support the Service. These providers may support cloud infrastructure, hosting, databases, storage, analytics, telemetry, session replay, error tracking, payment processing, customer support, communications, CRM, security, compliance, AI-assisted features, source-code integrations, project-management integrations, and workflow automation.
- With customer-authorized integrations, such as source-code hosting, project-management, identity, CI/CD, communication, or other third-party systems, when configured or authorized by you or your organization.
- With your organization or workspace administrators where needed to administer the Service, manage users, enforce permissions, review activity, or support organization-level controls.
- With professional advisors, auditors, insurers, legal counsel, and similar parties where needed for business, legal, security, compliance, or audit purposes.
- With government authorities, law enforcement, courts, or other third parties where required by law or where we believe disclosure is necessary to protect rights, safety, security, or the integrity of the Service.
- In connection with a business transaction, such as a merger, acquisition, financing, corporate reorganization, or sale of assets.
- With your consent or at your direction.
Our current list of subprocessors and relevant service providers is maintained in our Trust Center at https://trust.codemod.com. We update that list as our vendor environment changes.
We retain information for as long as reasonably necessary to provide the Service, support customer use, maintain security and audit records, comply with legal and contractual obligations, resolve disputes, enforce agreements, and operate our business.
Retention periods vary based on the type of data, the purpose of processing, customer configuration, legal or contractual requirements, security needs, backup or archival practices, and whether the data is still needed for product functionality or support.
Examples include:
- Account, organization, billing, and administrative records are retained while the account or organization is active and for a reasonable period afterward as needed for business, legal, tax, audit, security, or compliance purposes.
- Customer content, source-code-derived data, Studio sessions, chat threads, workflow records, logs, and package data are retained as needed to provide product functionality, support user reference, troubleshoot issues, maintain security, and meet operational or compliance needs.
- Analytics, telemetry, and diagnostic data are retained according to our operational needs and the retention settings of the relevant service providers.
- Backup, archive, security, and audit copies may persist for a limited period after deletion from active systems.
You may request deletion of account data, chat threads, workflow logs, or stored code by contacting privacy@codemod.com. We will process deletion requests in accordance with applicable law, customer agreements, security requirements, and technical feasibility.
Depending on where you live and your relationship with Codemod, you may have rights to request access, correction, deletion, export, objection, restriction, or other control over your personal information.
You may:
- Request access to, correction of, or deletion of personal information by contacting privacy@codemod.com.
- Request deletion of your account or certain product data, subject to applicable legal, contractual, security, and technical limitations.
- Opt out of marketing communications by using unsubscribe links or contacting us.
- Manage cookies, local storage, and similar technologies through your browser settings, recognizing that disabling some technologies may affect product functionality.
If your account is provided by an organization, we may direct certain requests to that organization or coordinate with the organization as appropriate.
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These safeguards include access controls, authentication controls, encryption where applicable, monitoring, vulnerability management, vendor review, incident response, and other security practices appropriate to our remote SaaS operating model.
No method of transmission or storage is completely secure. If you believe your information or account has been compromised, contact us at privacy@codemod.com or irt@codemod.com.
Codemod and our service providers may process information in the United States and other locations where we or our providers operate. When information is transferred internationally, we rely on appropriate safeguards where required by applicable law.
The Service is not intended for children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to Codemod, contact us at privacy@codemod.com.
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated policy on our website, updating the "Last updated" date, or using another reasonable notice method.
If you have questions or requests regarding this Privacy Policy or your data, contact us at:
For externally reported security vulnerabilities or suspected security incidents, contact: