Scope
This policy explains what personal data Knomatic processes when you visit codemonster.ai, use the CodeMonster desktop app, or build and run apps on the CodeMonster platform. It is written for the builders and administrators who hold an organization license.
Data that your own apps collect from your end users is covered separately: for that data you are the controller and we are your processor under the Data Processing Agreement.
Data we process
- Account data. Name, work email, organization, role, and the group and app-role assignments (owner, editor, viewer) that control what each builder may do.
- Operation records. Every named operation an agent or builder runs against the platform is recorded: which operation, when, under which account, and the result. This is the audit trail that lets you see what changed and who changed it, and it feeds our quality review of the platform’s tools.
- Quality and feedback records. When an agent or a builder files feedback about a tool, we attach the recent operation calls from that session so the report can be understood, and a person on our team reviews it in a quality queue. These records sit with our Supabase subprocessor and are used to fix the platform’s tools — not to profile your builders.
- Deployment and app records. App names, versions, deployment history, environment names, and the identity of whoever triggered each deploy or promotion.
- Contact and support data. What you send us through the site’s forms, by email, or in a support conversation.
- Website data. Server logs with IP address, user agent, and pages requested. [PLACEHOLDER: this site runs no third-party analytics today; if a provider is added, name it here and state what it collects.]
What we do not process
Your conversations with your AI provider. Your agent runs on your machine and talks to your AI provider directly: we do not see, store, meter, or resell your prompts, your model choice, or your provider keys. What we do record is listed above — the named operations your agent runs against the platform, and their results.
Why we process it
To provide and secure the service, to keep an audit trail your organization can rely on, to answer your requests, to improve the platform’s tools, and to meet legal obligations. [PLACEHOLDER: legal bases per purpose for GDPR/UK GDPR — counsel to complete.]
Where it is processed
Apps and data run on managed cloud infrastructure we operate, built primarily on AWS. The vendors we rely on are listed on the subprocessors page, with the purpose and data categories for each. [PLACEHOLDER: processing regions and the transfer mechanism for data leaving them.]
Retention
[PLACEHOLDER: retention periods for account data, operation records, deployment records, and website logs; deletion timeline after termination.] Until confirmed, this draft states no retention period.
Security
Every authenticated request carries a bearer token validated on every call, and the agent control surface rejects an unauthenticated request with a bare 401 — no tool list, no schema, no server information. Forms you publish as public accept anonymous end-user submissions by design. Authorization is enforced server-side with the caller’s own permissions, object data is separated per tenant at the row level, and every app URL is served over HTTPS. The security overview describes these controls in detail. No system is beyond compromise; if a breach affects your data we will notify you as described in the Data Processing Agreement.
Your rights
Depending on where you are, you may have the right to access, correct, export, restrict, or delete personal data we hold about you, and to object to certain processing. Send requests to privacy@codemonster.ai; we will verify the request and respond within the period the law requires. [PLACEHOLDER: supervisory authority and complaint route.]
Changes to this policy
We will post material changes on this page with a new effective date and notify your account owner by email. [PLACEHOLDER: notice period.]
Contact
Privacy questions and requests: privacy@codemonster.ai. Other legal requests go through the contact page. [PLACEHOLDER: postal address and, if appointed, data protection officer or EU/UK representative.]