Skip to content
codaicodai
ResolveBenchmarksPricingChangelogDocs
RO
Sign inGet started

Legal · Privacy

Privacy Policy

How codai (Dragos Catalin Vladulescu, Romania) collects, uses and protects personal data across the codai gateway, the web console, the Android app and the desktop app.

Version 1.2 · Updated September 14, 2026

This document is also available in Romanian.

Summary in plain words

  • We process what is needed to run the service: your account, your API keys (hashed), usage records, and the prompts and model outputs you send through codai.
  • The Android app can read your screen through the Accessibility permission and use your microphone — only while you run a task, only if you turn those permissions on, and you can switch them off at any time.
  • Data is processed in the EU (Google Cloud, Belgium). Model providers we route to (Anthropic via Google Vertex AI, Azure AI Foundry) run in EU regions under data-processing agreements.
  • If you bring your own provider key (BYOK), your prompts go straight to that provider under its own terms. If you use the on-device model, nothing leaves your phone for inference.
  • We train codai models on your prompts and replies only if you turn on "Use my data to improve codai". It is off by default and you can withdraw at any time.
  • No sale of data, no ads, no analytics SDKs, no tracking cookies. You can delete sessions, devices and your account yourself.

Contents

  1. 01 Who we are
  2. 02 AI transparency (EU AI Act)
  3. 03 What data we process
  4. 04 Android app and Accessibility permission
  5. 05 Why we process it and on what legal basis
  6. 06 Training our models
  7. 07 Referral program
  8. 08 Crash reports
  9. 09 Where your data goes
  10. 10 How long we keep it
  11. 11 Your rights
  12. 12 Security
  13. 13 Cookies
  14. 14 Children
  15. 15 Changes to this policy

01Who we are

The data controller is codai (Dragos Catalin Vladulescu), Romania. In this policy "codai", "we" and "us" refer to this controller.

Contact for privacy matters: [email protected]. Security reports: [email protected]. We have not appointed a Data Protection Officer because the size and nature of our processing do not require one under Article 37 GDPR.

This policy covers the codai gateway (ai.codai.ro), the identity service (auth.codai.ro), the web console (codai.ro), the codai Android app, the codai desktop app and our command-line tools and SDKs (together, the "Service").

02AI transparency (EU AI Act)

codai is an AI system within the meaning of Regulation (EU) 2024/1689 (the AI Act), and we comply with the transparency obligations of its Article 50. When you use the apps you interact with an AI agent; the apps tell you so at first run.

Text produced by codai is generated by a machine-learning model and can be wrong. Outputs delivered through our API include machine-readable provenance metadata where the format allows, so that downstream software can recognise them as AI-generated.

If you publish AI-generated content, you are responsible for labelling it where the law requires.

03What data we process

CategoryExamplesSource
AccountEmail address, display name, avatar URL and the identifier returned by your sign-in provider (Google or GitHub) through auth.codai.ro; email/password credentials if you register with a password (stored hashed).You / your sign-in provider
API keys and devicesAPI keys (we store only a hash and a short prefix), key names, device name and model, a randomly generated device identifier, device capabilities, and — when push is configured — a Firebase Cloud Messaging push token.You / your device
Usage and billingPer-request usage records (model, token counts, cost, timestamps, key and device identifiers), plan, credit balance and Stripe customer identifier. Card data never touches our systems; it is entered on and stored by Stripe.Generated by the Service / Stripe
Prompts and outputsThe messages you send, the model responses, tool calls and tool results, and — when Session sync is on — the step-by-step transcript of a session so your other devices can follow it.You / your apps
Android app contentScreen content read through the Android Accessibility Service (visible text, app and control names, and screenshots when a task needs to see the screen); results of tools you invoke (files you point it at; calendar, contacts or alarms when you ask); microphone audio only while you use voice input.Your phone, only while a task runs
Desktop app contentResults of shell commands, file reads/writes inside the folders you approved, and browser snapshots produced by tasks you run.Your computer, only while a task runs
Technical logsRequest metadata (timestamps, status codes, latency, IP address, user agent), error diagnostics from the web console (Sentry).Generated by the Service
Desktop crash reports (optional)Stack trace, app version, operating system and a random install identifier — only if you enable "Send crash reports" in the desktop app. Never prompts or session content.Your computer, only if enabled

Android password fields are hidden from accessibility services by the operating system, so codai cannot read them. The Android app bundles no analytics SDK, no advertising SDK and no crash reporter.

04Android app and Accessibility permission

The codai Android app can operate other apps on your phone (open apps, tap, type, read what is on screen). Android requires an Accessibility Service for this. The Accessibility permission is optional: without it codai works as a plain chat app.

  • What it reads: the accessibility tree of the foreground app (visible text, labels, control names and positions) and, when a task needs to see the screen, a screenshot. Screen content is read only while a task you started is running; codai does not read your screen in the background.
  • What happens with it: a summary of the screen is sent to the AI backend you configured — the codai gateway by default, or your own provider key — so the model can decide the next step. Steps handled by the on-device model (codai-nano / Gemma) are processed entirely on the phone and nothing is sent anywhere.
  • Sensitive apps: banking, wallet and password-manager apps and any message send, payment or settings change require you to confirm an on-screen "ask card" first. Messaging apps default to "ask every time" and can be blocked entirely.
  • Microphone: used only while you use voice input; audio is transcribed and then discarded. Notifications: used to show task progress and to let you answer questions from a task.
  • Turning it off: Android Settings → Accessibility → codai → Off, or uninstall the app. Screen content is not stored on our servers beyond the session transcript described below, and only if Session sync is on.

We do not use the Accessibility Service to collect data for advertising, analytics, profiling or any purpose other than performing the task you asked for. The app source code is public under the Apache-2.0 licence so you can verify this.

05Why we process it and on what legal basis

PurposeLegal basis (GDPR art. 6(1))
Providing the Service: authentication, routing your requests to models, running tasks, syncing sessions between your devices, billing.(b) performance of a contract
Security, fraud and abuse prevention, rate limiting, spend caps, debugging outages.(f) legitimate interest in keeping the Service secure and available
Reading screen content through Accessibility, using the microphone, sending push notifications.(a) your consent, given through the Android permission prompts; withdraw at any time in system settings
Complying with tax, accounting and legal obligations (invoices, records of payments).(c) legal obligation
Contacting you about material changes to the Service or these terms.(b) contract / (f) legitimate interest
Improving codai models with prompts and responses sent through the codai model (see "Training our models").(a) your consent, given by turning on "Use my data to improve codai"; off by default, withdraw at any time
Receiving crash reports from the desktop app (see "Crash reports").(a) your consent, given by enabling "Send crash reports" in the app; off by default

We do not build advertising profiles.

06Training our models

We use prompts and codai replies to train codai models only if you turn on "Use my data to improve codai" (Console → Settings → Privacy, app → Settings → About, or the first-run screen). It is off by default. The legal basis is your consent (Article 6(1)(a) GDPR).

You can withdraw at any time from the same places; we stop collecting from that moment and data collected under your consent is deleted within 30 days of withdrawal. Withdrawing does not affect the lawfulness of processing before withdrawal.

Screen content read through Accessibility, BYOK traffic and end-to-end-encrypted sessions are never used for training.

07Referral program

You can choose a username (3–20 lowercase letters, digits or underscore). If you agree, your username also serves as your referral code and appears in your invite link (codai.ro/r/<username>). We only use it that way after you tick the referral consent in Console → Settings; the legal basis is your consent (Article 6(1)(a) GDPR), which you can withdraw there at any time. Withdrawing stops new referrals from being attributed to you; existing relationships stay recorded for the reasons below.

When someone signs up with your code we record the referral relationship — who invited whom, the code used, when, and its status — so that we can pay the credits and answer disputes. The invited person sees your username; you see how many people you invited and the reward status, never their identity.

  • Welcome credit: every new account receives 10 € of wallet credit.
  • Referral credit: the invited person receives 10 € at signup with a valid code; the inviter receives 10 € once the invited person has spent 2 € of real usage. Limits: 10 rewarded referrals per month, 50 in total, and at most 100 € of promotional credit per account.
  • All promotional credit expires 90 days after it is granted. Credit has no cash value and cannot be paid out.

To prevent abuse of the program without asking anyone for identity documents, we store at signup a salted hash of the device identifier, a salted hash of the network part of your IP address (/24 for IPv4, /64 for IPv6), a salted hash of the browser or app user-agent string, and the domain of your email address. We do not store the raw IP address and we do not perform identity verification (no KYC). When inviter and invitee share a device, network cluster or payment-method fingerprint, or the email domain is a disposable-mail service, the referral is held as "flagged" and reviewed manually; credits are then granted or refused. The legal basis for this abuse prevention is our legitimate interest (Article 6(1)(f) GDPR) in not paying out credit for fake accounts; you may object at [email protected].

Retention: the signup fingerprint and the referral relationship are kept for as long as your account exists and are deleted with it. Wallet ledger entries are kept with your account and, once anonymised, as part of our billing records (see Retention).

08Crash reports

The desktop app can send crash reports to Sentry, but only if you enable "Send crash reports" in the app. It is off by default and you can turn it off again at any time. The legal basis is your consent (Article 6(1)(a) GDPR).

A crash report contains the stack trace, the app version, the operating system and a random install identifier. It never contains prompts, model outputs or session content. The Android app has no crash reporter.

09Where your data goes

Our own infrastructure runs on Google Cloud in region europe-west1 (Belgium). Your data is stored and processed there.

RecipientWhatWhere / safeguards
Google Cloud (hosting, Cloud SQL, Cloud Run)All Service dataEU (Belgium); Google Cloud Data Processing Addendum
Anthropic via Google Vertex AIPrompts, outputs and tool results routed to Claude modelsEU regions; Google Cloud DPA and Vertex AI terms — inputs are not used for training
Microsoft Azure AI FoundryPrompts, outputs and tool results routed to models hosted thereEU regions; Microsoft Products and Services DPA
StripePayment and invoicing dataStripe DPA; Stripe is an independent controller for card data
Google Firebase Cloud MessagingPush token and a wake-up signal (no message content)Google DPA; used only in builds configured with Firebase
SentryError diagnostics from the web console; desktop crash reports only if you enabled themSentry DPA
Google / GitHub (sign-in)Identity assertion when you sign inTheir own privacy policies apply

Bring-your-own-key (BYOK): if you configure your own OpenAI, Anthropic, Google Gemini or OpenRouter key in an app, your prompts and outputs are sent directly from the app to that provider under that provider’s terms. codai is not a party to that processing. Some of these providers are in the United States; transfers rely on the provider’s Standard Contractual Clauses or EU-US Data Privacy Framework certification.

We do not sell personal data and we do not share it with advertisers or data brokers. We disclose data to authorities only when legally required.

10How long we keep it

  • Account, API keys, devices, session events and usage records: for as long as your account exists. You can delete individual sessions and devices from the console or in-app; deleting your account deletes them all.
  • Technical logs: 30 days.
  • Database backups: 30 days, after which deleted data disappears from backups too.
  • Billing records: as long as Romanian tax and accounting law requires (currently 10 years for invoices).
  • Local data on your phone or computer (encrypted settings, local session database, optional trace files in Downloads/codai-nano/): under your control; removed when you uninstall or delete them.

11Your rights

Under the GDPR you have the right to access your data, to have it rectified or erased, to receive it in a portable format, to restrict or object to processing based on legitimate interest, and to withdraw consent at any time without affecting past processing.

Most of this you can do yourself: sessions, devices and API keys can be deleted from the console and the apps; your account can be deleted from the console (Settings → Delete account; step-by-step at https://codai.ro/account/delete). For anything else, email [email protected] — we answer within one month.

You can lodge a complaint with the Romanian supervisory authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), www.dataprotection.ro, or with the authority of the EU country where you live.

12Security

API keys are stored only as hashes. Traffic is encrypted in transit (TLS). Data at rest is encrypted by Google Cloud. Access to production systems is limited to the controller. The apps store credentials in the platform’s encrypted storage (Android EncryptedSharedPreferences, OS keychain on desktop).

Report vulnerabilities to [email protected]. We will confirm receipt and keep you informed.

13Cookies

codai.ro uses a session cookie to keep you signed in to the console and the cookies Stripe sets during checkout for fraud prevention. We do not use tracking or advertising cookies, and we do not use analytics cookies. Because these cookies are strictly necessary, no cookie banner is shown.

14Children

The Service is intended for people aged 18 or over. We do not knowingly process data of anyone under 18; if you believe we have, email [email protected] and we will delete it.

15Changes to this policy

We will notify you by email or in the console at least 14 days before a material change takes effect. The version number and "Last updated" date at the top of this page identify the current text.

↑ Back to top

codaicodai

One model name. Every frontier model.

All systems operational

Product

ResolveBenchmarksPricingChangelogWeb app

Developers

DocsAPI referenceSDKsStatusGitHub

Company

AccountSecurityContact

Legal

PrivacyTermsImprint

© 2026 codai · Built in Romania 🇷🇴 · Cloud Run · EU data

RO
ResolveBenchmarksPricingChangelog