Privacy Policy
Effective date: August 15, 2026
This Privacy Policy explains how TakoCode ("TakoCode", "we", "us") collects, uses, shares, and protects information when you use takocode.com and the TakoCode platform — the AI software builder, project workspaces, hosting and deployments, domain services, and billing (the "Services"). It should be read together with our Terms of Service.
Two roles. For your TakoCode account we act as the data controller. For data that end users submit to applications you build and deploy on our infrastructure, you are the controller and we act as your hosting processor — your application's privacy practices are your responsibility.
1. Information we collect
1.1 You provide it
- Account data: name/username, email address, password credentials or OAuth identifiers, organization membership, language preference.
- Project content: prompts and chat messages, uploaded files and images, code and files in your projects, project databases, secrets you store (encrypted), answers to agent questions, and design or configuration choices.
- Billing data: your payment card is collected and processed by Stripe — we never store full card numbers. We keep Stripe customer/subscription identifiers, wallet balance and top-up history, membership status, and invoices/usage records.
- Domain registrant data: if you register a domain, the registrant contact details you provide are shared with our registrar partner (Cloudflare) and the registry as required by ICANN policy.
- Support: messages, tickets, and feedback you send us.
1.2 Collected automatically
- Usage and metering data: agent sessions and duration, model/tier used, tokens processed, per-second usage records, deployment runtime, feature usage.
- Technical data: IP address, device and browser information, pages viewed, referring pages, approximate location derived from IP, and cookies or similar technologies used for sign-in sessions, security, and preferences.
- Project telemetry: build and runtime logs, error diagnostics from project previews, and screenshots the platform takes of your project previews to verify the agent’s work.
1.3 From third parties
- OAuth providers (e.g. GitHub or Google sign-in): basic profile information you authorize.
- Stripe: payment status, fraud signals, and subscription events.
2. How we use information
- Provide the Services: run AI agents on your projects, build and host applications, store project data, provide previews, checkpoints, and rollback.
- Process payments, meter usage, manage wallets, memberships, deployments, and domain purchases and renewals.
- Secure the platform: authentication, abuse and fraud prevention, isolation enforcement, incident investigation.
- Operate and improve the Services: debugging, performance, aggregate analytics, and product decisions. Aggregated or de-identified data may be used for statistics.
- Communicate with you: service and billing notices, support replies, security alerts, and (with your consent where required) product news. You can opt out of non-essential email.
- Comply with law and enforce our Terms.
AI model training: we do not use your prompts, code, or project content to train our own foundation models, and we send content to third-party AI providers under API terms that do not permit them to train on it (per those providers' published API data-usage policies).
3. When we share information
We share personal data only as described here. We do not sell personal data.
- AI model providers (OpenAI, Anthropic, Google AI): your prompts and relevant project content are sent to generate agent output. These providers process the data as our sub-processors under their API terms.
- Infrastructure providers: Google Cloud (compute, hosting, storage, builds), Neon (databases), Cloudflare (DNS, domains, delivery), and Redis (session/queue infrastructure).
- Stripe: payment processing, subscriptions, invoices, and fraud prevention.
- Registrars/registries: registrant data needed to register and maintain domains.
- GitHub: if you connect or export a repository, code is transmitted to your GitHub account.
- Legal: when required by law or to protect the rights, safety, or property of TakoCode, our users, or the public.
- Business transfers: as part of a merger, acquisition, or asset sale, subject to this policy.
4. Cookies
We use strictly necessary cookies for sign-in sessions and security, and preference cookies (e.g. language). We do not run third-party advertising trackers on the platform. You can control cookies in your browser; disabling essential cookies will break sign-in.
5. Data retention
- Account and project data: kept while your account is active. After account deletion, projects and backups are deleted or de-identified within 90 days, except data we must keep longer (see below).
- Billing and usage records: kept as required for tax, accounting, and audit obligations (typically 7 years).
- Logs and telemetry: kept for a limited operational window and then deleted or aggregated.
- Domain registrant data: retained per registrar/registry and ICANN requirements while the registration exists.
- We may retain data longer where necessary for legal claims, abuse prevention, or compliance.
6. Security
- Projects run in isolated environments with dedicated per-project databases.
- Secrets you store are encrypted; payment cards are handled solely by Stripe.
- Data is encrypted in transit (TLS) and at rest by our cloud providers.
- Access to production systems is restricted and logged. Platform actions taken by agents in your project are visible to you in the activity feed.
- No system is completely secure. If we learn of a breach affecting your personal data we will notify you as required by law.
7. International transfers
We operate on cloud infrastructure primarily located in the United States (with optional project regions where offered). If you use the Services from outside the US, your data is transferred to and processed in the US and other countries where our providers operate. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses implemented by our providers.
8. Your rights
Depending on where you live (e.g. GDPR in the EEA/UK, CCPA/CPRA in California), you may have rights to access, correct, delete, export, or restrict processing of your personal data, to object to processing, and to withdraw consent. You can exercise most of these directly: update account details in settings, export project code at any time, and delete projects or your account. For anything else, contact us via the support page — we respond within the time required by applicable law. You may also lodge a complaint with your local data-protection authority. We do not discriminate against you for exercising your rights, and we do not "sell" or "share" personal information as defined by the CCPA.
End users of applications built on TakoCode: if your data was submitted to an application built by a TakoCode customer, the application owner is the controller — please contact them directly; we will assist them as their processor.
9. Children
The Services are not directed to children under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. For material changes we will give notice by email or in-product before the changes take effect. The effective date above always reflects the current version.
11. Contact
Privacy questions and requests: takocode.com/support.