Privacy Policy
Last updated: September 5, 2026
Overview
Codecast ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service.
Codecast is a tool for syncing and managing AI coding conversations across devices and teams. We are designed with privacy as a core principle.
Information We Collect
Account Information
When you create an account, we collect your email address and authentication credentials (via GitHub or Google OAuth). This information is used solely for account management and authentication.
Conversation Data
By default, Codecast syncs conversation metadata only (titles, timestamps, tool usage). The actual content of your AI conversations is stored locally on your device unless you explicitly enable content sync.
- Metadata (default): Session titles, timestamps, project identifiers (hashed), tool names
- Content (opt-in): Full conversation messages and code snippets
Usage Data
We collect basic usage statistics to improve our service, including feature usage patterns and error reports. This data is anonymized and cannot be used to identify individual users.
How We Use Your Information
- To provide and maintain our service
- To authenticate your account and manage sessions
- To sync your conversation data across devices (based on your settings)
- To enable team collaboration features when you share conversations
- To improve our service through anonymized analytics
- To communicate important updates about the service
What We Do NOT Do
- No AI Training: Your data is never used to train AI models
- No Data Selling: We never sell, rent, or trade your personal information
- No Advertising: We do not use your data for advertising purposes
- No Unauthorized Access: Employees cannot access your data without explicit permission
Data Security
We implement industry-standard security measures to protect your data:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Optional client-side end-to-end encryption (AES-256-GCM)
- Automatic secret redaction (API keys, tokens, passwords)
- SOC 2 Type II compliant infrastructure (Convex)
Data Retention
We retain your data for as long as your account is active. You can delete individual conversations at any time. If you delete your account, all associated data is permanently removed within 30 days.
Your Rights
You have the right to:
- Access your personal data
- Export your data in a portable format
- Delete your data and account
- Opt out of optional data collection
- Update your account information
Browser Extension
The Codecast Chrome extension lets agent sessions running on your computer open and drive their own tabs in your Chrome. It has one purpose and collects nothing.
- It connects only to a bridge on your own computer (127.0.0.1) started by the Codecast CLI. It makes no other network connections and sends nothing to us or to anyone else.
- It acts only on tabs it opened for a session, grouped under one Cast tab group. It does not read, change, or record the tabs you opened yourself.
- Page content it reads on a session's request goes to that local bridge and is not stored by the extension.
- It stores one thing: the pairing token and port you granted, in Chrome's extension storage on your computer. Revoke it any time with
cast browser extension revoke, or by removing the extension. - It uses no analytics, no remote code, and no content scripts.
What a session does with a page it drives is governed by the rest of this policy, the same as any other session activity.
Third-Party Services
We use the following third-party services:
- Convex: Database and backend infrastructure
- GitHub/Google: OAuth authentication
- Vercel: Web hosting
These services have their own privacy policies and we encourage you to review them.
Children's Privacy
Codecast is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy, please contact us at [email protected]