Privacy Policy

Last updated 5 September 2026

This policy explains what data Codensity collects, why we collect it, who processes it on our behalf, and how long we keep it.

Who we are

Codensity is operated by Codensity, Inc. (Ghana). We are the controller of the personal data described in this policy. You can reach us at hello@getcodensity.com.

What we collect

We collect three kinds of data, and we keep them separate.

  • Account data: your name, email address, profile image, the organizations you belong to, and your role in each. Provided by you, or by Google if you sign in with Google.
  • Telemetry you send us: feature keys, execution time, memory usage, and call counts reported by the Codensity SDK, along with the project and environment they belong to. This describes your software, not your end users. We do not ask for, and you should not send, personal data in telemetry payloads.
  • Product usage: how you use the Codensity dashboard, including pages viewed, features used, errors encountered, and session recordings of your dashboard activity.

How we use it

  • To provide the service: authenticating you, storing your projects, and turning telemetry into energy and carbon estimates.
  • To send transactional email you have asked for, such as verification, invitations, and scheduled reports.
  • To keep the service working and secure, including rate limiting, debugging, and investigating abuse.
  • To understand which parts of the product are used, so we can improve them.

Analytics and session replay

We use PostHog, hosted in the European Union, for product analytics, error tracking, and session replay. Session replay records your interactions with the Codensity dashboard so we can diagnose issues and improve the interface. Request and response bodies and headers are not recorded.

We do not use advertising networks and we do not sell personal data.

Cookies

We set a session cookie when you sign in, which keeps you signed in and is required for the service to function. We do not use advertising or cross-site tracking cookies.

Subprocessors

We use the following providers to run Codensity. Each processes data only to provide its service to us.

ProviderPurposeLocation
PostHogProduct analytics, session replay, and error tracking for the web dashboard.European Union
RenderHosting for the Codensity API and background worker.United States (Oregon)
VercelHosting and content delivery for the Codensity web application.Global edge network
NeonManaged PostgreSQL storing accounts, organizations, projects, and telemetry.United States
UpstashManaged Redis for rate limiting and background job queues.United States
Amazon Web Services (S3)Object storage for organization logos and profile images.United States (us-east-2)
ResendDelivery of transactional email such as verification, invitations, and reports.United States
StripePayment and subscription processing. Currently inactive during the public beta.United States
GoogleOptional Google sign-in for account authentication.United States

How long we keep data

  • Raw telemetry is retained according to your plan: 7 days on Free, 30 days on Team, and 90 days on Business. Aggregated rollups derived from it are kept for longer so historical charts remain available.
  • Account and organization data is kept while your account is active.
  • When you delete your account, we delete your account data and the telemetry belonging to organizations you solely own. Backups are purged on their own rotation.

Your rights

You can access and correct your account details in your dashboard settings, and delete your account from the same place. To request a copy of your data or ask us to erase it, email hello@getcodensity.com and we will respond within 30 days.

Depending on where you live, you may also have the right to object to processing, restrict it, or complain to your local data protection authority.

Security

Data is encrypted in transit. SDK keys are stored only as SHA-256 hashes, never in plain text, and the full credential is shown to you once at creation and is unrecoverable afterwards. Access to production systems is limited to people who need it.

International transfers

Our providers operate in the European Union and the United States, so your data may be transferred outside your country. Where required, these transfers rely on standard contractual clauses offered by the provider.

Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change is significant, notify you by email.

Questions about this page? Email hello@getcodensity.com.