PRIVACY

Privacy at CodeRook

What we collect, why we have it, how long we keep it, and how to get it back or get rid of it.

Version 3 · effective 22 August 2026

Who is responsible for your information

CodeRook is operated by ACCA Gaming Productions, a business name registered to a sole trader in NSW 2259, Australia, under ABN 80 173 545 848. That is the entity accountable for the information described below.

For access, correction, deletion, or to make a privacy complaint, write to privacy@coderook.com.

What we collect, and how

Most of it you give us directly. The rest is generated by using the service — we do not buy personal information, and we do not collect it from third parties.

  • Account details — your email address, display name, username, and anything you choose to add to your profile such as a bio, location, website or avatar.
  • Sign-in and session data — password derivations (never the password itself), two-factor secrets and recovery code hashes, session records, and personal access tokens you create. If you sign in with Google or GitHub, the identifier they give us and the email on that account.
  • Billing information — your subscription, plan, invoices and payment history. We never see or hold your card details; those go to Stripe directly.
  • Your projects — the files you upload, their names and sizes, version history, and who made each change.
  • Security and operational records — IP addresses and request information used to detect abuse and to make rate limits work, and records of significant account actions such as sign-ins, permission changes and deletions.
  • Client information — which application and version you are using, so we can support it and require a minimum version when a release fixes something important.
  • Anything you send us — support emails, complaints, and vulnerability reports.

If you make a project public, the project and the activity on it are public by your choice, including your username and the version messages you write.

Why we have it

To run the service you asked for and for nothing else: to authenticate you, store and recover your versions, enforce access and quotas, take payments, prevent abuse, answer you when you write, and meet legal obligations.

ACCA Gaming Productions does not train machine learning models on your projects, public or private, and does not sell, licence or supply them to anyone. The service is funded by subscriptions rather than by anything done with the content stored on it. Each project also carries its own answers about machine access, which you set — see AI on CodeRook.

We do not use your content for advertising, and we do not run advertising networks on the site.

Whether anyone here can read your private projects

No feature of CodeRook lets an operator open your private projects. There is no support tool, no administrative viewer, and no moderation queue that reads private project contents. The administrative side of the service manages accounts, subscriptions and storage totals, and has no route that reaches a file.

It is also why support cannot look inside a project to help you debug one. There is nothing to look with, and that is the trade we have chosen.

How long we keep it

  • While your account is open — account and project information is kept for as long as you keep the account.
  • A project you delete — held for 30 days, then the stored objects are permanently reclaimed.
  • An account you close — every project goes on a seven-day clock and is then permanently deleted. Sessions and access tokens are revoked immediately, and the account record is anonymised.
  • Billing records — invoices and payment records are kept for as long as tax and record-keeping law requires, even after an account closes. They are financial records rather than content.
  • Security and audit records — kept while they are useful for detecting abuse and for answering questions about what happened to an account.
  • Backups — we take a nightly backup of the database and keep 30 days of them. Backups hold account and project records, so information you delete may persist in one for up to 30 days after you delete it, and is then gone as those backups age out. Backups are stored separately from the files the service serves, and are not readable by anything other than a restore.
  • Your uploaded files are not in those backups. They live in object storage and are removed on the schedules above — the backup covers the records that describe them.

Who else processes it

Cloudflare, PlanetScale, Stripe, and the sign-in provider you chose if you used one. What each holds and where is set out on the subprocessors page, which is updated when a provider changes.

Processing happens outside Australia. That is unavoidable for a service delivered on a global network. By using CodeRook you consent to your information being handled overseas by those providers under their own terms.

Getting at it, correcting it, deleting it

Most of it you can do yourself. Account settings expose your profile, sessions, access tokens, email address, subscription and account closure, and every project can be exported or deleted from the application.

For anything you cannot reach yourself — a copy of what we hold, a correction, or deletion — write to privacy@coderook.com. We will ask enough to be sure it is your account and no more, and we aim to answer within 30 days.

We will tell you if we cannot do something you have asked for, and why. The usual reasons are that a record is needed for tax law, or that removing it would misrepresent something that happened, such as a version somebody else relies on.

If something goes wrong

Where a data breach is likely to cause serious harm, Australia's Notifiable Data Breaches scheme requires notification to the people affected and to the Office of the Australian Information Commissioner. We would tell affected users directly, and we would say what we knew at the time rather than waiting until the picture was flattering.

Complaints

Write to privacy@coderook.com and tell us what happened. If you are not satisfied with how we handle it, you can refer the matter to the Office of the Australian Information Commissioner, which is free and does not require our agreement.

Changes to this policy

If we change how information is handled in a way that affects you, we will say so here and tell account holders by email before it takes effect.