Privacy Policy
Last updated 30 August 2026.
Contents
- 1. Introduction
- 2. What we store about you
- 3. Your own API key
- 4. Source data — what we collect about other people
- 5. What we send to AI providers
- 6. How long we keep it
- 7. How we protect it
- 8. Where your data is processed
- 9. Cookies, analytics and advertising
- 10. Your rights
- 11. Do-Not-Track signals
- 12. Children's privacy
- 13. Changes to this policy
- 14. Contact
1. Introduction
CodeKudo evaluates startup ideas against evidence collected from public sources. This notice explains what we store about you, what we never store, how long anything is kept, and what you can ask us to do with it.
It describes what the software actually does. Where a claim here could be checked against the product — encryption, retention windows, what leaves the browser — it was written from the code, not from a template.
2. What we store about you
- Account: your email address, plus whatever the sign-in method you chose requires. You can sign in four ways: email and password, a magic link, Google, or GitHub. If you use a password we store only a hash of it, never the password itself. If you use Google or GitHub we store the authentication identifier that provider gives us, not your credentials there.
- Founder profile, if you fill it in: technical level, available capital band, hours per week, goal, distribution channels, preferred build platforms. Used to scope the specs we write for you. Optional; specs work without it.
- Your work: conversations, generated specs, watchlists, and the credit ledger.
- Billing: a Stripe customer identifier and your plan status. We never see or store card numbers — those go directly to Stripe.
- Product analytics: which pages and features are used. No session recording, and no analytics on the Spec Grader.
3. Your own API key
If you connect one:
- It is encrypted with AES-256-GCM before it reaches the database. The encryption key lives in the server environment, not in the database — a database dump on its own decrypts nothing.
- It is decrypted in memory only, immediately before a model call.
- It is never written to logs, never attached to error reports, and never returned by the API. The interface only ever shows the last four characters.
- Deleting it from settings removes the stored value immediately.
4. Source data — what we collect about other people
The engine reads public posts from App Store, Discourse forums, EU procurement, GitHub, GitLab, Hacker News, Product Hunt, Stack Exchange and TrustMRR. Most of that is through the platforms' own APIs; where a platform has closed its API to us we use a third-party collection service instead. Either way the boundary is the same: we do not log in as anyone, do not access private groups, and do not collect anything behind a login.
- What you see: a derived signal (the problem, in our words), a quote of up to 200 characters with attribution, and a link to the original post.
- What we hold internally: a private copy of the source text, used to re-run extraction when prompts or models change. It is never shown in the product and never republished. This is a processing copy, not a redistribution.
- What we do not do: build profiles of the people who wrote those posts, contact them, or sell any of it.
If you wrote something quoted here and want it removed, email privacy@codekudo.com with the link and we will remove the quote and the stored copy.
5. What we send to AI providers
Chat messages and the evidence needed to answer them go to our model provider. Your email address, billing details and account identifiers are not included in model requests. We do not use your conversations to train anything.
6. How long we keep it
- Account and work data: kept while your account exists.
- The idea text you submit — to an attack or a research run — is redacted after 30 days by a nightly job. The verdict and its evidence survive; the words you typed do not.
- After deletion: your account, profile, conversations and specs are removed within 30 days. Billing records are kept as long as tax law requires.
- Source records and derived signals are kept indefinitely — the time series is what makes momentum measurable, and deleting it would destroy the product's core function. It contains no personal data about you.
7. How we protect it
- Traffic is encrypted in transit (HTTPS enforced site-wide), and the database is encrypted at rest by the hosting provider.
- Row-level security is enabled on every table holding user data, so one account cannot read another's rows even if application code asked it to.
- API keys and credentials are stripped from error reports before they are sent.
- No security measure is absolute. If a breach affects your personal data we will notify you and the relevant authority as the law requires.
8. Where your data is processed
Your account and work data live in the European Union. Some of the services we rely on — payments, email delivery, error monitoring and AI model routing — process data outside the EU, including in the United States. If you allow advertising measurement in section 9, LinkedIn is added to that list; without your consent it receives nothing.
Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard. We use these services under data processing terms; they act on our instructions and cannot use your data for their own purposes.
9. Cookies, analytics and advertising
Two things are stored without asking, because the site cannot work otherwise: a session cookie that keeps you signed in, and a preference for light or dark theme. Neither is used to track you and neither leaves this domain.
Analytics is different and it is off until you allow it. We use a privacy-focused analytics service hosted in the EU to see which pages get used. It does not load, set anything, or send a request until you choose “Allow” on the banner. Choosing “No thanks” costs you nothing — every feature works identically.
No session recording. The Spec Grader page is excluded from analytics entirely, because what you paste there is your own document.
Changing this here takes effect immediately: turning it off stops the client and clears what it stored in your browser. To have data already collected deleted, email us.
Advertising measurement
This is a separate decision, and answering the analytics question does not answer this one. Allowing analytics does not switch this on, and this is off unless you turn it on here yourself. Nothing below loads, stores anything, or sends a request until you do.
If you allow it, we load the LinkedIn Insight Tag, provided by LinkedIn Ireland Unlimited Company (part of Microsoft). We use it for one purpose: to learn how many people who arrived from a LinkedIn ad went on to start an attack. That single event is the only thing we report — a counter, with no idea text, no report contents, no email address, no account identifier and no attack identifier attached to it.
LinkedIn itself receives more than that counter. Like any third-party tag, it can read your IP address, browser and device information, the page address you are on and the page you came from, and it can set or read its own cookies to recognise a browser across sites. We do not control that collection and we cannot switch parts of it off, which is why it sits behind its own consent rather than the analytics one. We have not enabled its optional email-matching feature. LinkedIn describes its own processing in its privacy policy.
The tag is not loaded on the Spec Grader page, on your dashboard, or on any signed-in page whose address could reveal what you are working on — the same rule analytics follows. It is also never loaded outside codekudo.com, so preview and development builds do not run it.
Data goes to LinkedIn in the United States under the European Commission's Standard Contractual Clauses. Withdrawing consent below stops any further reporting immediately; because a script already loaded into the page cannot be recalled, reload the page afterwards to remove it completely.
10. Your rights
You can export or delete your data at any time. Email privacy@codekudo.com and we will respond within 30 days.
Depending on where you live, you may also have the right to access a copy of your data, correct it, restrict or object to how it is processed, withdraw consent you gave earlier, and receive it in a portable format. If you are in the EU or UK you can lodge a complaint with your national data protection authority. Exercising any of these costs nothing and we will not treat your account differently for it.
11. Do-Not-Track signals
There is still no agreed standard for how sites should answer a Do-Not-Track header, so we do not rely on one. It does not matter much here: analytics stays off until you allow it, which is a stronger default than any DNT signal would give you.
12. Children's privacy
CodeKudo is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.
13. Changes to this policy
When this notice changes, the date at the top changes with it. If a change materially affects what we do with your data, we will say so directly rather than relying on you to notice a new date.