Legal
Privacy Policy
Last updated September 18, 2026
This policy explains what codiv.ai collects when you use the Codiv website and API (“the Service”), why, and what control you have. The short version: we keep what is needed to run your account and count your usage, and we do not store the content you send to the API.
What we collect
Account information
- Your name, email address and whether it is verified.
- If you sign in with Google or GitHub, your account identifier with that provider and, if provided, your profile picture URL. We ask only for basic profile and email access.
- If you sign up with a password, a salted one-way hash of it. We never see or store the password itself.
Sessions and security
- A session cookie that keeps you signed in, and the IP address and browser user agent for each session.
- Signup, sign-in and password reset forms use Cloudflare Turnstile to block bots. Turnstile processes signals from your browser under Cloudflare's Turnstile privacy terms.
API keys and usage
- API keys are stored only as a SHA-256 hash, plus a short prefix so you can tell keys apart. A key is shown to you once, when you create it.
- For each account, key and day we store the number of requests and input and output tokens, and when each key was last used. These counts power your dashboard and your free quota.
What we do not collect
- API request content. The state and questions you send, and the answers returned, are processed in memory to produce a response. We do not write them to logs or to a database, and we do not use them to train models. Our inference engine may briefly keep processed prompts in its GPU cache to speed up repeated requests; that cache lives only in memory and is continuously overwritten.
- Requests you run in the dashboard playground are handled the same way.
- We do not use advertising or third-party analytics trackers, and we do not sell personal data.
How we use it
- To create and secure your account, sign you in and send verification and password-reset emails.
- To authenticate API calls, enforce quotas and rate limits, and show your usage.
- To prevent abuse, for example creating many accounts to get extra free quota.
- To contact you about your account or important changes to the Service. We will not send marketing email without asking.
Service providers
- Cloudflare hosts the website, the database and the network between you and our servers. Like any network provider, it may keep operational logs such as request URLs, IP addresses, status codes and timing, but not request bodies.
- Resend delivers our transactional email (your email address and the message).
- Google and GitHub, if you choose to sign in with them.
Model inference runs on servers we operate. It is not sent to any third-party AI provider.
Retention
Account, key and usage records are kept while your account exists. Sessions expire after 7 days without use, and verification and password-reset links expire after one hour. If you ask us to delete your account, we delete your profile, sessions, keys and usage records within 30 days. Aggregated statistics that cannot identify you may be kept.
Your choices and rights
You can revoke API keys at any time from the dashboard. To access, correct, export or delete your data, email support@codiv.ai from the address on your account. We will respond within 30 days. Depending on where you live (for example the EU, UK or California), you may have additional rights under local law, and we will honor them.
Security
Traffic is encrypted in transit. Passwords and API keys are stored only as hashes, and our inference servers accept requests only from our own gateway. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you.
Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
Changes
If we change this policy, we will update the date above. For material changes we will notify you by email or on the website before they take effect.