CodeCordon policy
Privacy notice
CodeCordon collects only the information needed to operate accounts, run scans, enforce plan limits, and provide billing.
Effective July 18, 2026
Information collected
Account records include your name, email address, password hash, plan, session records, and API-key metadata. Project records include names, source type, public GitHub URLs when provided, scan status, scores, findings, and finding snippets. ShipBond records include the production URL, automated deployment-check results, activation status, and Stripe Checkout identifier.
How information is used
Information is used to authenticate your account, perform requested scans, present scan history, enforce usage limits, support CI access, prevent abuse, and manage subscriptions. CodeCordon does not sell submitted source code or account information.
CodeCordon records limited first-party product analytics such as page paths, campaign parameters, scan completion, account creation, and checkout events. Random visitor and preview analytics identifiers are used to measure the conversion funnel without storing opaque preview-access tokens in analytics; raw IP addresses are not stored in the analytics table. When you choose to save a preview, a short-lived secure cookie carries that request through sign-in or registration.
Billing
Stripe processes subscription, ShipBond activation, and prepaid Studio Pack payments. CodeCordon stores Stripe customer, subscription, Checkout, and credit-grant identifiers but does not receive or store full card numbers. Stripe's own privacy terms govern information entered in Stripe Checkout and the billing portal.
Retention and deletion
Project scan and associated ShipBond records remain until the project is deleted. Activated ShipBond records remain publicly accessible through their opaque URL after expiration so their historical status is not misrepresented. No-account public-repository preview results expire after 24 hours. If the preview holder saves a result into an account before it expires, the copied project and scan follow the project-retention rule above. Session and account records remain while the account is active or as needed to operate and protect the service. Legal, fraud-prevention, backup, or accounting obligations may require limited retention beyond an in-app deletion.
Service providers
CodeCordon uses Railway for hosting and data storage, Stripe for billing, and GitHub's public download service when a public repository URL is submitted. Data is shared only as required to provide those functions.