What we collect.
What we don't.
Plain-language description of the data Codicresthandles today, why each piece exists, how long it stays, and how to ask for export or deletion. We'd rather this page be short than legalistic.
Who we are
Data controller & contact
Codicrest is operated by Polsia, the platform that builds and hosts this product. Polsia is the data controller for the personal data described on this page.
The operational contact for any privacy question — access, export, deletion, complaints, regulator correspondence — is codicrest@polsia.app. We answer within five business days.
What we collect
Three categories — and what we don't take.
Codicresthandles three categories of personal data today. Each is tied to a specific surface — the form you fill in, the account you sign up for, or the GitHub URL you paste on the connect page.
- Pre-accounting
Waitlist signups
source: /api/waitlist
Stored
- Email address (validated by zod in src/lib/waitlist/schema.ts)
- Submission timestamp (WaitlistEntry.createdAt)
Not collected
- Submitter IP address
- User-Agent string
- Post-signup
Account profile (better-auth)
source: /api/auth
Stored
- name, email, emailVerified, optional profile image, role and ban metadata (User)
- Session token, expiresAt, optional ipAddress and userAgent (Session)
- providerId, hashed password for email/password sign-ups, optional OAuth tokens (Account)
Not collected
- Plain-text passwords (auth hashes them before storage; we never see the cleartext)
- Onboarding
Repo metadata on /app/connect
source: /api/app/connect/repo
Stored
- The github.com URL you submit
- Resolved metadata returned by the public GitHub API: owner, name, fullName, defaultBranch, visibility (public only)
Not collected
- We do NOT persist this today — the resolve happens per request and is shown only to you in the confirmation card
Why we collect it
Purpose & legal basis, category by category.
For each category above, here is the specific purpose — and the GDPR Art. 6 ground that lets us process it.
Waitlist outreach
Sending onboarding emails, scheduling a 30-minute walkthrough, and quoting you for design-partner onboarding.
Legal basis
Consent
Art. 6(1)(a) GDPR
You can withdraw your email at any time — one link in any onboarding email, or by replying STOP.
Account & session for gated paths
Authenticating you on /dashboard and /app/*, holding your session, and surfacing what you opted into.
Legal basis
Contract
Art. 6(1)(b) GDPR
Needed to deliver the gated /app experience you signed up for.
Validating a repo before onboarding
Confirming the github.com URL is real, public, and ready to receive patch-ready PRs from Codicrest.
Legal basis
Legitimate interests
Art. 6(1)(f) GDPR
Verifying public-repo metadata to act on a request you made.
Retention
How long each piece stays.
Three retention rules — one per category. They run automatically; you do not need to ask.
Waitlist entries
Until you request deletion, or 24 months of inactivity, whichever comes first. One-click unsubscribe is in every onboarding email.
Account & sessions
Account: until you delete it. Sessions expire per the access-token lifetime configured in better-auth.
Connect-repo resolve
Not retained — the GitHub resolve runs per request and is discarded as soon as the confirmation card renders.
Who has access
Polsia only — with sub-processors that never see account data.
Codicrest's personal data is accessible to Polsia engineering and operations staff only, on a need-to-know basis. We do not sell or rent personal data to anyone, ever. Three categories of sub-processor touch our infrastructure — and they receive only what their role requires:
- Hosting (Postgres / Render). Database rows live in encrypted storage; engineers query them via a private network, not the public internet.
- Email transport (Polsia's platform email proxy). Used only for sign-up and onboarding emails; transactional only, never marketing blasts.
- GitHub public REST API. The connect page queries api.github.com/repos/{owner}/{name} to validate a URL you submitted. We send no user identifiers to GitHub.
Your rights
Six rights — one address to exercise them.
Under GDPR, you have six rights over personal data we hold. For each, email codicrest@polsia.app from the address you signed up with (or any address you can verify), and we answer within five business days.
Access
Ask for a copy of the personal data we hold about you.
Rectification
Ask for any incorrect data to be corrected.
Erasure
Ask for your data to be deleted — we remove your rows and send a confirmation email.
Restriction
Ask that we pause processing while a question is investigated.
Portability
Receive a JSON export of your User and Account rows.
Objection
Object to processing based on our legitimate interests — we will stop unless we can show a compelling override.
Export and deletion in practice
Export. We send a JSON dump of your User and Account rows, plus any WaitlistEntry tied to your email, to the requester.
Deletion. We remove every row tied to you across User, Session, Account, and WaitlistEntry, then send a confirmation email. This action is irreversible.
International transfers
Where the data lives.
Codicrest's infrastructure runs in the region configured for the Polsia deploy hosting this app. The default GitHub resolve runs from our public-internet egress in that region. Specifics depend on your tenant onboarding — email codicrest@polsia.app and we will tell you exactly which sub-processors sit in which region before you sign any data-processing agreement.
Changes to this policy
Material changes are announced, not buried.
When we add a category of data, change a legal basis, or extend retention, we publish a dated entry on the /changelog and email everyone on the waitlist or with an active account whose behavior changes.
The current version lives at /privacy; older versions are not retained, so this page always reflects what we do today.
Related
The engineering commitments behind this product.
This page covers what we collect. The Terms of Service cover the agreement that lets us use it on your behalf — uptime, responsibilities, and how the contract works day-to-day.
Privacy questions → codicrest@polsia.app