The short version
code-anything.com turns a written description into a working, hosted application. Doing that means we store what you write and what gets built, and it means your prompts and your source code are sent to the AI providers that do the work. We do not sell personal information, we run no advertising, and we have no analytics or tracking software of any kind on this site. This page explains the rest.
Who we are
code-anything.com (“we”, “us”) operates the website at code-anything.com and the application behind it. This policy covers both. It does not cover the applications you build with the service once they are running under your own control — you are responsible for those, including any privacy notice their own users need.
What we collect
Account and identity
When you create an account we store your email address, and, if you sign in with Google or GitHub, the display name and profile-picture URL that provider gives us. We keep the profile picture as a link to the provider, not as a copy — your browser fetches it from them when it is shown. We do not store passwords: sign-in is handled by our authentication provider using a one-time email link or an identity provider.
What you write and upload
- Prompts and briefs — the description of what you want built, kept with the build it produced.
- Chat transcripts — the full conversation for each project, including the planning conversation before a build starts.
- Attachments — documents you attach are converted to plain textin your browser and only that text is uploaded; the original file is not. Images you attach as visual references are uploaded as images.
- Answers to questions the agent asks you mid-build.
What the service produces for you
We store every file of every project, each version of each file, a searchable index of your code (including numeric embeddings computed from it), a reconstructed map of the project’s structure, generated documentation about it, and a record of each build: the steps taken, the tools called and their results, and what the reviewer concluded. If you connect a repository, a working copy of it is held in the build sandbox and a snapshot of that workspace is kept in encrypted object storage for 30 days.
Two kinds of image are stored differently and you should know it: screenshots of your app’s preview, and images you upload to the design canvas, are held at long, unguessable web addresses that can be opened without signing in, so they can be shown in the interface and alongside published apps. Anyone given one of those links can view it, so do not put anything confidential on the design canvas.
Credentials you connect
API keys and environment secrets you paste in are encrypted with AES-256-GCM before they are written down, using a key that is held in our application environment and never in the database. If that key is absent the service keeps them in memory for the session instead — they are never written in plain text. They are decrypted only to be placed into your project’s own sandbox environment so your app can use them.
Technical data
We do not keep server-side profiles of visitors. Your IP address is used in memory to rate-limit API requests and is not stored in any database; it can appear in an operational log line if a request is throttled. We write one structured log line per server request (path, status, timing and a correlation id), which our hosting provider retains. We do not log browser user-agent strings.
Payments
Payments are handled by Stripe. Card details are entered on Stripe’s own checkout and never reach our servers. We send Stripe the price you are buying and an internal account identifier; Stripe collects your email and billing details itself and tells us the resulting subscription status.
Signing in with Google
If you choose “Continue with Google”, Google asks you to confirm before anything is shared. We then receive, from your Google account:
- your email address and whether Google has verified it;
- your name as it appears on your Google profile;
- the URL of your Google profile picture;
- the unique identifier Google uses for your account.
That is the whole of it. We request only basic sign-in. We do not request, receive or hold access to Gmail, Google Drive, Calendar, Contacts, Photos or any other Google service, and the application contains no code that calls any Google API on your behalf.
We use this data for one purpose: to create and sign you into your account, and to show you which account you are signed in as. We do not use it for advertising, we do not sell or rent it, we do not use it to build profiles, and we do not transfer it to anyone except the infrastructure providers listed below that store it on our behalf. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect code-anything.com from your Google account at any time at myaccount.google.com/permissions. That stops future sign-ins; to remove the data already held, ask us to delete your account as described below. On the sign-in page only, your browser loads Google’s sign-in script from accounts.google.com so that Google can draw its own button; this tells Google you visited that page.
Connecting GitHub
Connecting GitHub is optional and only needed to import or push to a repository. GitHub’s classic authorisation has no read-only option for private repositories, so the permission you grant is read and write across your public and private repositories. We use it to list your repositories, clone the one you pick, and — when you ask — push a branch or open a pull request. Your GitHub access token is held in a secure, HTTP-only cookie in your browser that expires after eight hours, and is cleared when you disconnect.
How we use what we collect
To run builds and edits you ask for; to sign you in and keep you signed in; to show you your projects, their history and what they cost; to host and deploy the apps you publish; to notify you about your account, a failing agent or a payment problem; to meter usage and take payment; to prevent abuse; and to find and fix faults. We do not use your prompts or your code to train our own models.
Who your data goes to
We keep this list specific, because in a service like this the interesting question is not whether there are subprocessors but what leaves.
- AI model providers, through our gateway — this is the significant one. To build or edit an app we send your prompt, the relevant source files of your project, the text of documents you attached, any reference images, and screenshots of your app’s live preview. Requests are routed through our own gateway to third-party model providers, which today include Google (Gemini), Z.ai/Zhipu served via Together.ai, and Inception. These run in the United States and we make no data-residency promise for them. The set of providers can change as models change.
- Our review and research service — a separate system that checks finished work and researches a request before building. It receives the prompt, the diff of the generated code, preview screenshots and an anonymous project and account identifier — not your name or email. Most of those requests are marked so that nothing is retained; the exception is a short per-project memory of what was learned, which is stored durably so later builds are better informed.
- Our screenshot service — receives the public preview URL of your app in order to load and photograph it.
- Supabase — the managed database, authentication and file storage where everything in the sections above is kept.
- Cloudflare — hosting, edge compute, the build sandboxes, object storage and the delivery of published apps. Server logs are retained here.
- GitHub — only if you connect it, and only for the repository you point us at.
- Stripe — payments and subscriptions.
- Resend — sends the transactional emails above to your address. We send no marketing email.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
The databases of the apps you build
When we provision a database for an app you build, we may store a snapshot of that database — its structure and its rows — so a build can be rolled back. If your app collects information about its own users, that information is inside those snapshots. For that data you are the controller and we act on your instructions; you are responsible for telling your users what you collect and for having a lawful basis to do so. Deleting the project deletes its snapshots.
Errors reported by the apps you build
Apps built here ship with a small error reporter. When an app throws an unhandled error in a visitor’s browser, or its backend returns a 5xx, the app sends us a short report so you can see that your live app is broken without reading logs. This happens automatically in apps we generate; the endpoint that receives it is /api/app-errors.
What the report contains: the error type, the error message, the page path it happened on, the HTTP method and status, a request id, a release identifier, and the first few lines of the stack. That is the whole list — it is an allow-list, not a filter, so anything not named here is dropped before it is stored rather than collected and then cleaned.
What it deliberately does not contain: request bodies, headers, cookies, form values and browser storage are never sent or stored. URLs keep their origin and path and lose the entire query string, because the set of parameter names that carry a token or an email is not something anyone can enumerate reliably. We do not record the visitor’s IP address, and there is no field anywhere in this data that identifies an individual person. It answers “what is broken”, never “who was using it”.
These reports come from your app’s visitors, so for them you are the controller and we are processing on your behalf — the same relationship as the app databases described above. One honest limit: if your own code puts personal data into an error message (throw new Error('no user for alice@example.com')), that text is in the message field. We scrub the patterns we can recognise, and we cannot promise to catch every one. If you would rather send nothing at all, remove VITE_CA_INGRESS_URL from your project’s environment and the reporter goes silent.
Cookies and browser storage
We use no advertising, analytics or tracking cookies, and there are no third-party cookies on this site. What we do set:
- A session cookie from our authentication provider, which keeps you signed in. It is set for up to 400 days and is readable by the application running in your browser, which is how the signed-in interface works. Signing out clears it.
- Short-lived GitHub cookies, only if you connect GitHub: a ten-minute anti-forgery value during the connection, and the access token and your GitHub username for eight hours. These are HTTP-only and sent over HTTPS only.
Your browser’s local storage also holds a working copy of some of your own content so the interface survives a reload — your theme choice and layout preferences, your unsaved editor changes, and a recent slice of each project’s chat. This stays on your device; clearing site data removes it. We use no session storage, no service worker, and fonts are served from our own domain rather than fetched from a font provider.
How long we keep it
We will not pretend to a schedule we do not run. Your account, projects, prompts, chat transcripts, files, version history, index and build records are kept until you delete them or ask us to delete your account. There is no automatic expiry of your content. The exceptions, which do expire on their own, are: sandbox workspace snapshots after 30 days, the GitHub cookies after eight hours, connection-flow tokens after 30 minutes, and server logs under our hosting provider’s retention.
Deleting your data
Deleting a project from your dashboard removes it and everything attached to it — files, versions, chat, prompts, build records, the index, its stored secrets and any database snapshots. This is immediate and cannot be undone. Two things outlive it briefly: images uploaded to the design canvas and preview screenshots remain in storage, and the sandbox snapshot expires on its own 30-day timer.
Account deletion is handled by a person, not a button. Email hello@code-anything.com from your account address, or use the option in Settings, and we will delete your account and the projects under it within 30 days. We will confirm when it is done. Records we are required to keep for tax and accounting — invoices, essentially — are retained for as long as the law requires.
Security
What is actually in place:
- Every table holding your data is protected by database-level row security, so a query can only ever return rows belonging to the signed-in account. Requests for a project you do not own return “not found” rather than revealing that it exists.
- Connected credentials are encrypted with AES-256-GCM, with the key held outside the database.
- Build sandboxes are isolated per project — one container per project, with the durable copy of your files held outside it. We also apply an outbound allowlist to the container during the agent phase; we describe that as best-effort rather than a boundary, because it depends on a capability the host may not grant. The security page explains exactly what that does and does not guarantee.
- HTTPS is enforced, and API requests are rate-limited.
No service is perfectly secure, and we would rather say so than imply otherwise. If you find a vulnerability, please tell us at security@code-anything.com before disclosing it publicly.
Where your data is processed
We operate on globally distributed infrastructure, and the AI providers that process build requests run in the United States. Using the service therefore involves transferring your information outside your own country, including outside the UK and the EEA. Where that applies, transfers rely on the standard contractual clauses our providers offer.
Your rights
Depending on where you live you may have the right to access the personal information we hold about you, correct it, delete it, receive a copy of it, object to or restrict how we use it, and complain to your data-protection regulator. Email hello@code-anything.com and we will respond within 30 days. We will not charge you for exercising these rights or treat you differently for it.
Children
The service is not intended for anyone under 16 and we do not knowingly collect their information. If you believe a child has given us personal information, tell us and we will delete it.
Changes
If we change this policy we will update the date at the top of the page. If a change materially affects how we handle information we already hold, we will tell account holders by email before it takes effect.
Contact
Questions about this policy, or about the information we hold on you: hello@code-anything.com.