Privacy Policy
Privacy Policy
Last Updated: September 2026
1. Scope and Who We Are
This Privacy Policy explains how CodeConda LLC, an Arizona limited liability company in the United States (“CodeConda,” “we,” “us,” or “our”), collects, uses, discloses, and otherwise processes personal information through our websites, applications, software, and related digital services (collectively, the “Services”). The data, vendors, payment arrangements, cookies, and features involved vary by Service, domain, account type, and user choices. A Service may provide a supplemental notice where a feature requires more specific information.
This Policy applies when CodeConda determines why and how personal information is processed. When a business or organizational customer controls personal data and CodeConda processes it on that customer's documented instructions, our Data Processing Agreement may apply to that processing. This Policy still covers CodeConda's independent processing, such as account administration, billing, security, support, and legal compliance.
CodeConda operates multiple websites, applications, and digital services across separate domains and subdomains, including codeconda.com, anifusion.ai, phototag.ai, shoptag.ai, flowpost.ai, jacsend.com, linguana.io, i18now.ai, contactcongress.io, mooseminutes.com, dailycompanygame.com, and yahrzeitalerts.com. The technologies, vendors, cookies, and data practices described in this Policy apply across those Services, but not every category, vendor, or feature applies to every Service. Consent and cookie choices are stored separately for each domain or subdomain. Accepting cookies or privacy choices on one Service does not automatically apply them on another.
2. Information We Collect
Information You Provide
- Account and contact information, such as name, email address, login credentials, organization, preferences, and age or eligibility attestations where required.
- Billing and transaction information, such as billing contact, country, tax details, subscription, purchase, credit balance, and transaction identifiers. Payment card or financial account details are generally collected directly by the applicable payment processor or merchant of record.
- User Content, including prompts, text, images, audio, video, files, translations, metadata, URLs, website materials, project settings, generated outputs, and other content submitted to or created through a Service.
- Feature-specific information, such as an address entered for a district lookup, a city or coordinates entered for a calculation, business contact information submitted for enrichment or outreach, or connected-platform identifiers and authorization tokens.
- Communications, including support requests, feedback, survey responses, abuse or copyright reports, and marketing preferences.
Information Collected Automatically
- Device and network information, such as IP address, browser, operating system, device type, language, referring page, timestamps, and identifiers associated with cookies or similar technologies.
- Usage and diagnostic information, such as pages and features used, interactions, job status, credit use, errors, performance data, security events, and approximate location inferred from an IP address.
The Services do not generally request precise device GPS location. A feature may process an address, city, or coordinates that you intentionally enter, and security, localization, tax, fraud prevention, or analytics systems may infer an approximate location from an IP address. Those are different from collecting precise device GPS data.
Information From Other Sources
We may receive information from payment providers, authentication providers, connected platforms you authorize, analytics and security providers, affiliate or referral partners, public or licensed data sources, enrichment providers, and business customers or users who submit information to a Service. Connected platforms determine what they disclose under your authorization and their own terms.
3. Private and Public Content
Prompts, uploads, projects, and drafts are not made publicly accessible merely because they are submitted to a Service. They may nevertheless be processed by CodeConda personnel and authorized providers for operation, security, support, abuse prevention, and the features you request, as described in this Policy, the applicable Data Processing Agreement, and any feature-specific notice. Content remains private service data unless you or an authorized user chooses a publishing, sharing, collaboration, hosting, or connected-platform feature that makes it available to others. Not all User Content is associated with a registered account or email address. Content you intentionally publish may be accessible to the public, indexed, copied, or further disclosed by recipients or third parties, and we may not be able to remove copies outside our control.
4. Sensitive Information
Please do not submit highly sensitive information unless the relevant Service expressly requests it and you are authorized to provide it. Depending on the feature, information in User Content could reveal sensitive characteristics or include regulated data. Where separate explicit consent, an authorization, or additional restrictions are required, the Service may present a feature-specific notice, obtain the required choice, or prohibit the upload. General acceptance of this Policy is not treated as blanket consent to process every category of sensitive information.
5. How We Use Information
- Provide, operate, authenticate, maintain, personalize, and improve the Services, including processing jobs, generating outputs, hosting or publishing content at your direction, and enabling connected-platform features.
- Administer accounts, subscriptions, credits, transactions, taxes, affiliate or referral programs, and customer relationships.
- Communicate about the Services, provide support, deliver transactional messages, and send marketing where permitted and consistent with your choices.
- Measure use, troubleshoot, monitor performance, conduct research and analytics, and develop features using information that is aggregated, de-identified, or otherwise processed as permitted.
- Protect users, CodeConda, the Services, and others by detecting fraud, abuse, malicious activity, security incidents, and violations of our Acceptable Use Policy.
- Comply with law, enforce our terms, establish or defend legal claims, complete corporate transactions, and respond to valid legal requests.
6. Legal Bases Where Required
Where a law requires a legal basis, we rely as appropriate on performance of a contract, steps requested before entering a contract, our legitimate interests or those of others, compliance with legal obligations, consent, and other bases permitted by law. Legitimate interests may include operating and securing the Services, improving functionality, preventing fraud, supporting users, and conducting proportionate business communications. You may withdraw consent at any time, without affecting processing already carried out, but withdrawal may limit features that depend on consent.
7. AI, Translation, Enrichment, and Automated Features
Certain Services send prompts, uploads, settings, or related context to artificial intelligence, machine-learning, translation, enrichment, or processing providers to perform a requested feature. Depending on the provider, product configuration, account tier, and applicable provider terms, submitted data and outputs may be logged or retained for abuse prevention, quality, support, or legal compliance; may be reviewed by authorized personnel; and may or may not be used to train or improve provider models. Provider practices and available controls vary and can change.
Representative providers may include OpenAI, Google Gemini and other Google Cloud services, fal.ai, RunPod, DeepL and other translation providers, and Apollo.io or similar enrichment providers. Available business, API, privacy, retention, and no-training settings vary by provider, model, feature, account tier, and configuration. We do not make a portfolio-wide promise that every provider, model, or feature has identical retention, human-review, or training terms. Do not submit information that the relevant feature or provider terms prohibit.
Automated outputs can be inaccurate, incomplete, biased, offensive, or similar to outputs produced for others. We may use automated systems to support security or moderation, but we do not promise comprehensive review of all inputs or outputs. See the Terms of Service and Acceptable Use Policy.
8. How We Disclose Information
- Infrastructure, hosting, database, storage, authentication, content-delivery, and security providers, such as Supabase, Cloudflare, including Turnstile, Google Cloud, or Amazon Web Services, depending on the Service.
- Analytics, diagnostics, and monitoring providers, such as DataFast, Sentry, or similar services, subject to applicable consent requirements.
- Consent and preference-management providers, such as GetTerms, which may store consent choices and related records.
- Email, messaging, support, and communication providers, such as SMTP2GO or another configured delivery provider, which may process addresses, names, message content, and delivery metadata.
- AI, model-hosting, translation, media-processing, and enrichment providers, including the representative providers described above.
- Mapping, location, and civic-data providers, such as Google Maps or civic-data services, when a requested feature requires them.
- Payment processors and merchants of record, such as Stripe or PayPal where offered. Their role, checkout terms, and independent privacy obligations may differ by transaction.
- Affiliate, referral, advertising, and marketing technology partners used for attribution, program administration, or permitted promotion, such as Rewardful, ProfitWell, or Affonso where configured. Affiliate attribution is not necessarily behavioral advertising.
- Connected platforms, social networks, and their infrastructure when you authorize a connection, import, publication, message, or other action.
- Professional advisers, auditors, insurers, authorities, counterparties, and participants in an actual or proposed financing, reorganization, acquisition, sale, or similar transaction, subject to appropriate safeguards.
- Other service providers, processors, subprocessors, merchants of record, payment processors, and technology partners used to operate, secure, support, analyze, market, or provide the Services.
We may also disclose information at your direction, with your permission, to enforce agreements or protect rights and safety, or when reasonably necessary to comply with law or valid legal process. A maintained technology inventory is described in our Cookie Policy. Business customers may request applicable subprocessor information under the Data Processing Agreement.
9. Cookies and Similar Technologies
We and authorized third parties may use cookies, local storage, pixels, tags, scripts, software development kits, and similar technologies for essential operation, functionality, analytics, affiliate attribution, and marketing. Technologies and choices vary by Service and are generally stored separately for each domain or subdomain. See our Cookie Policy and use the “Cookie settings” link in the relevant Service where available.
10. Retention and Deletion
We retain personal information for periods reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining accounts and user-requested content, completing transactions, protecting security, resolving disputes, enforcing agreements, and meeting tax, accounting, legal, and regulatory duties. Retention varies by data type, Service, account status, feature, provider, legal requirement, and operational need. We do not promise that every category is deleted on a single portfolio-wide schedule.
After an account or content deletion request, eligible information may be removed or de-identified from active systems within a reasonable period after verification and completion of dependent processing. Processors may need additional time to complete deletion under their schedules. Billing, tax, fraud-prevention, consent, security, legal-hold, and dispute records may be retained where required or reasonably necessary. Residual copies may remain in backups until those backups expire or are overwritten in the ordinary course and generally are not restored except for continuity or disaster recovery.
You are responsible for exporting content you need before deletion or account closure. Deletion may not remove content intentionally published or disclosed to others, records another controller must retain, or copies outside our control.
11. Security
We use administrative, technical, and organizational measures designed to protect personal information in light of the nature and risks of processing. No transmission, storage system, or security measure is guaranteed to be completely secure. You are responsible for protecting account credentials and promptly reporting suspected unauthorized access through our support page. If a personal-data breach occurs, we provide notices to affected individuals or authorities when and within the time legally required, based on the facts and risks involved.
12. International Processing and Transfers
CodeConda operates from the United States, and information may be stored or processed in the United States and other countries where our providers or users operate. We do not represent that data is stored in Canada, the United Kingdom, or any other particular country unless a Service or binding agreement expressly says so. Where required for restricted international transfers, we use recognized safeguards such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK Addendum, or another permitted mechanism. Business-customer transfers governed by our DPA are addressed in the Data Processing Agreement.
13. Your Privacy Rights and Choices
Depending on your location and relationship with us, you may have rights to request access, confirmation, correction, deletion, portability, or restriction of personal information; object to certain processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive personal information; and appeal a denied request. These rights are not absolute and exemptions may apply.
Submit a request through our support page. We may ask for information reasonably necessary to verify your identity, authority, account, or jurisdiction. Authorized agents may be required to provide proof of authorization, and we may separately verify the request with the individual. We generally respond within the legally required period. For UK and EEA requests, this is ordinarily one calendar month, subject to lawful extensions. Requests are generally handled at no or minimal cost, although a reasonable fee or refusal may be permitted for manifestly unfounded, excessive, or repetitive requests.
If you have a legal right to appeal a denied request, submit an appeal through our support page. You may also have the right to contact your local data protection authority or attorney general. We will not unlawfully discriminate against you for exercising privacy rights.
Marketing, Sale, Sharing, and Targeted Advertising
Where promotional email is based on consent, you may withdraw that consent at any time. You may also opt out of promotional email using the unsubscribe method in the message. If that method is unavailable or does not work, send an opt-out request to CodeConda Support from the email address you want removed. We process valid requests within the legally required period. Opting out of promotional email does not stop essential transactional or service-related communications. Where advertising, analytics, or similar technologies are legally treated as a sale, sharing, or targeted advertising, use the relevant Service's cookie preference center or submit a request through our support page. Available choices depend on the technologies actually used by that Service.
Global Privacy Control and Do Not Track
Where legally required, we process recognized Global Privacy Control (“GPC”) and similar opt-out preference signals as requests to opt out of sale or sharing to the extent we can associate the signal with the browser, device, or account that transmitted it. If we can reasonably link the signal to a logged-in account, we apply the opt-out to that account and related sale or sharing as required. If we cannot identify the consumer, the opt-out applies to the browser or device that sent the signal. GPC does not by itself authenticate you or automatically carry across unrelated browsers, devices, domains, or subdomains. Older browser “Do Not Track” (“DNT”) signals do not have a uniform legal or technical standard, so the Services may not respond to DNT. GPC and DNT are distinct.
14. Children
The Services are not directed to children under 13, and Services requiring an adult account are intended for users who are at least 18 or the age of legal majority where they live. We do not knowingly seek personal information from children unlawfully. If you believe a child provided personal information improperly, contact us through our support page. A business customer that submits information about minors is responsible for its lawful authority and any required notices or consents.
15. Changes to This Policy
We may update this Policy to reflect changes in the Services, law, or our practices. We will update the “Last Updated” date and provide additional notice where legally required. If consent is required for a new use, we will seek it before that use.
16. Contact
For the processing described in this Policy, CodeConda generally determines why and how personal information is processed unless a supplemental notice states otherwise. We have not appointed a Data Protection Officer unless we expressly identify one in a current notice. For privacy questions, rights requests, deletion requests, or concerns, contact us through the support page.