Privacy policy
Last updated September 19, 2026.
Who looks after your data
CodeMago is a product of Alpha Developer Services LTDA, Brazilian company registry (CNPJ) 67.106.947/0001-52, based in Mogi das Cruzes, SP, Brasil. It is the controller of the data described here.
To talk about privacy, write to [email protected]. That is also the channel for our data protection officer. We answer within 15 days.
What data we keep
From your account: email, name and the language you use. If you pay by Pix, we also keep your Brazilian tax number and mobile phone, because Pagar.me requires them to issue the charge.
From your work: your projects, the chat messages with the AI, the versions of the generated code and the usage record, with the tokens and credits consumed.
From payment: the plan you bought, the billing history and the state of the subscription. Your card number does not stay with us: Stripe processes and stores that.
What we use it for
To create and maintain your account, generate the apps you ask for, publish and serve those apps, charge for the plan, count credits and apply usage limits.
To tell you what matters: payment receipts, notice that a Pix period is about to expire, a price change or a change to these documents. Those emails come from [email protected].
To find and fix problems, and to protect the service against abuse and fraud. We do not sell or rent your data, and we do not send you other companies' advertising.
Legal basis
Account, app generation and billing: performance of the contract with you (LGPD art. 7, V; GDPR art. 6(1)(b)).
Tax records and keeping access logs: compliance with a legal obligation (LGPD art. 7, II; GDPR art. 6(1)(c)). Security and fraud prevention: legitimate interests (LGPD art. 7, IX; GDPR art. 6(1)(f)).
Waiting list and product news: your consent (LGPD art. 7, I; GDPR art. 6(1)(a)), which you can withdraw at any time.
What you send to the AI
Your requests and the generated code are sent to third-party AI providers: DeepSeek, Meta and Z.ai.
The default model, called “Balanced”, runs on the Contributor tier of Meta's Muse Spark. On that tier, Meta may use your requests and the responses to train its models. In other words: what you write into that model may end up in training we do not control and cannot undo.
So do not write personal data, sensitive data or confidential information into your requests — not yours, not your clients', not anyone else's. If you do not accept this use, choose another model tier before you write.
Who we share it with
Only with those needed for the service to work: Hostinger (our server, in Brazil), Cloudflare (CDN, DNS and the generation engine), Stripe (card payments), Pagar.me (Pix), Google Firebase (sign-in) and the AI providers named above.
Each one receives only what it needs for its part, and may not use the data for any other purpose.
We may also hand data to authorities when a law or a court order requires it.
The site loads its fonts from Google Fonts. In that request, Google receives the IP address of whoever visits the page.
International transfers
Apart from the main server, which is in Brazil, the suppliers above process data outside the country. Part of your data therefore leaves Brazil.
We make that transfer because it is necessary to perform the contract with you. We require contractual protection from suppliers that is compatible with the LGPD and the GDPR.
Data inside the apps you publish
Apps generated today store their data in the browser of whoever uses them. That data does not pass through any database of ours, and we do not see what end users type inside your app.
If your app collects other people's data, you are the controller of that data. Informing those people and complying with the law towards them is your responsibility.
How long we keep it
Account, projects, AI chats and code versions: for as long as your account exists.
When you delete the account, we erase the personal data — email, name, tax number and phone are anonymised — and the apps go offline.
Tax records of the charges: for as long as the law requires, even after deletion. Access logs: for the period set by the Brazilian Internet Civil Framework.
Your rights
You can ask for access to your data, correction of anything wrong, deletion, portability, information about who we share it with, and withdrawal of consent where consent is the legal basis.
Much of this you can do yourself in the dashboard: change your name and language, download your projects and delete your account.
For the rest, write to [email protected] from the same email as your account. We answer within 15 days. If you are not satisfied, you can complain to the ANPD, the Brazilian data protection authority.
If you are in Europe or the United Kingdom
The same rights apply under the GDPR: access, correction, erasure, portability, restriction of processing, objection and withdrawal of consent.
The legal bases are those in the section above, and the contact is the same: [email protected].
You can also complain to the data protection authority in your country.
Cookies and what stays in your browser
We use only what the service needs to work: keeping you signed in, remembering your language and the light or dark theme, and storing the page's own preferences.
We do not use advertising cookies and we do not sell profiles to ad networks.
You can erase this data in your browser settings. If you do, you will have to sign in again and pick the theme again.
Your session is kept in the browser's own storage (localStorage), not in a cookie. Cloudflare, which protects the site, may set its own security cookies.
Security
Access to your account is protected by a password or by Google sign-in. Traffic to the site and to the apps uses an encrypted connection.
No system is completely secure. If there is an incident that could put you at risk, we notify you and the ANPD, as the law requires.
Changes to this policy
We may update this text when the service changes or when the law changes. The date of the last update is at the top of this page.
When a change is significant, we notify you by email before it takes effect.