Legal
Privacy Policy
Codz is local-first. Most of what it measures never leaves your Mac, and the parts that do are listed here.
Last updated 30 August 2026
Local by default
Codz is a macOS application that reads agent activity already on your machine. On the Free tier nothing leaves your Mac: usage is collected, stored, and displayed locally, and we receive none of it.
Provider credentials are never transmitted to us. Claude, Cursor, and Codex keep their own CLI sign-ins on your machine, and OpenRouter and DeepSeek keys are held in the macOS Keychain and reachable only as a finished authorization header.
Account information
Creating an account stores your email address and an account identifier. Authentication is handled by Supabase; we do not store passwords, because Codz signs in with an emailed magic link or with Google, Apple, or GitHub.
You may optionally set a display name and username. These are private unless you choose to make your profile public.
Usage data on Pro
With a Pro or Team subscription, Codz syncs a daily summary of agent usage so it is available across your devices. Each record covers a day, a provider, and a model, and includes token counts and provider-reported costs.
- We do not receive your prompts, your agent conversations, or the contents of your files.
- We do not receive your source code, diffs, terminal output, or repository names beyond what you choose to display.
- Usage totals keep their source and fidelity, so account-reported figures are never mixed with estimates.
Public profiles and community stats
Your usage profile is private by default. If you turn on a public profile, the pages you choose to publish become readable by anyone with the link.
Community statistics aggregate only the accounts that have explicitly opted in to sharing. The aggregate carries no account identifiers, and turning sharing off removes you from it.
Remote control
Pairing an iPhone or iPad creates an encrypted connection to your Mac. Your Mac stays authoritative: paired devices reach only the workspaces you approve, and provider credentials and permission enforcement never leave the host.
Message payloads are end-to-end encrypted. We relay them; we cannot read them.
Payments
Subscriptions are billed by Stripe, or by Apple if you subscribe through the App Store. We never see or store your card details.
We store the identifiers those providers give us — a customer id, a subscription id, its status, and its renewal date — so we know whether your account is entitled to Pro.
Service providers
We share data only with the providers needed to run the service: Supabase for accounts and storage, Stripe and Apple for payments, and Cloudflare for hosting, delivery, and transactional email such as team invitations.
We do not sell your data, and we do not use it for advertising.
Retention and deletion
Synced usage is retained while your account is open. You can request account deletion from the iOS app or by emailing us; deleting your account removes your profile, your synced usage, and your organization memberships.
Cancelling a subscription does not delete your data — it stops the sync and returns you to the local-only tier.
Your rights
You can request access to, correction of, or deletion of your personal data at any time by emailing support@codz.com. Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA, and we honour those requests regardless of where you are.
Changes
If we change this policy we will update the date above, and we will tell you directly when a change materially affects how your data is handled.