Last updated 25 July 2026 · Codelight AB, Stockholm, Sweden
Codelight AB is a Swedish company registered in Stockholm. We are the data controller for personal data processed through codelight.ai and app.codelight.ai. For anything in this policy, contact us at [email protected].
Account data. When you sign in with GitHub we receive your GitHub user ID, username, display name, avatar URL and primary email address. We use it to create and identify your account. The legal basis is performance of our contract with you.
Source code. When you connect a repository, we read its contents in order to analyse it for vulnerabilities. Source code frequently contains personal data — author names and email addresses in commit metadata, names in comments, and sometimes personal data in test fixtures. You remain responsible for what your repositories contain.
Scan results. Findings, severities, file paths and the code excerpts they refer to, retained so you can view and act on them.
Billing data. If you subscribe, Stripe processes your payment details. We never see or store card numbers.
Operational logs. Request logs and error traces, kept to run and secure the service. The legal basis is our legitimate interest in operating a reliable service.
Analysis runs on our own inference hardware located in Europe. Your source code is not sent to third-party AI providers, and is not transferred outside the EU/EEA for analysis.
We do not use your code, your scan results, or anything derived from them to train our models.
Source code is not retained after analysis completes. Scan results — findings and the excerpts they cite — are retained so the product is useful to you.
We use a small number of sub-processors: GitHub (repository access and sign-in), Stripe (payments), Cloudflare (website hosting and content delivery), our European hosting provider (application and database hosting), and an email provider for transactional email such as password resets.
TO CONFIRM BEFORE PUBLICATION: name each sub-processor, its role, its location, and the safeguard relied on for any transfer outside the EEA. A current sub-processor list is required for a GDPR-compliant policy.
Account data is kept while your account exists and deleted when you close it.
Scan results are kept while your account exists, or until you delete the repository from your account.
TO CONFIRM: specific retention periods for logs and backups.
Under the GDPR you may request access to your personal data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Write to [email protected] and we will respond within one month.
If you believe we have handled your data unlawfully you may lodge a complaint with the Swedish Authority for Privacy Protection (IMY), or with the supervisory authority in your country of residence.
We use a session cookie to keep you signed in. We do not use advertising or third-party analytics cookies, and there is no tracking across other sites.
If we change this policy materially we will tell account holders by email before the change takes effect.
Questions about this document? [email protected]