Codag

Last updated · August 2026

The short version

Your model traffic goes from a local proxy on your machine directly to your model provider; it never passes through Codag's cloud. When your agent produces a large eligible tool result, that output plus minimal task context is sent to Codag, processed transiently to produce the reduced evidence, and not retained. Exact omitted content stays encrypted on your machine. Codag's cloud keeps contentless accounting metrics, never your content.

What we collect

  • Account data. Name, email, organization. Used to authenticate and bill.
  • API keys. Issued by us, scoped to your workspace, hashed at rest.
  • Eligible tool output, transiently. Large eligible tool results (logs, test and build output, search results, file listings, document reads, agent handoffs) plus minimal task context are processed to produce the reduced evidence and are not retained.
  • Contentless usage metrics. Byte and token counts, estimated costs, latency, reduce or passthrough decisions, fail-open reasons, retry and retrieval counters, client versions, plan and billing events. Metrics never include prompts, commands, paths, filenames, task text, or tool output.

What never reaches our cloud

  • Your model provider credentials and your model traffic. Both stay on your machine; the local proxy forwards provider requests directly to your provider.
  • Source code, diffs, configuration, and any tool result Codag does not recognize as eligible. These pass through locally and are never sent to Codag.
  • The exact content a reduction omits. It is kept encrypted on your machine for seven days with a 1 GiB cap, retrievable only by your agent through selector-limited local retrieval, and removed by codag uninstall.

How we use data

  • Process eligible tool output transiently to return the reduced evidence. Customer content is processed only on inference endpoints Codag controls and is not retained after the request completes.
  • Meter usage, bill plans, and report savings using the contentless metrics described above. Dollar savings are estimates computed from public model prices.
  • Aggregate reliability and cost metrics to diagnose issues, prevent abuse, plan capacity, and guide product decisions.

We do not share or sell your data, and we do not build datasets from your content: it is not retained.

Telemetry choices

Contentless accounting metrics are required to operate, meter, and secure the service and cannot be disabled while Codag is attached. Optional product telemetry can be turned off at any time with codag config set telemetry off or CODAG_TELEMETRY=0.

Data retention

Contentless metrics, account data, and billing records are retained while your account is active. If you delete your account or request deletion in writing, we purge all per-customer data within 30 days. Aggregated, de-identified service metrics may be retained beyond that for service-quality, capacity, security, and pricing analysis. The local encrypted cache on your machine expires on its own after seven days and is yours to delete at any time.

Storage and security

Account data and contentless metrics are stored in an encrypted PostgreSQL database hosted on US-based cloud infrastructure. All traffic is TLS-encrypted in transit. Reduction runs on inference endpoints Codag controls (see sub-processors); customer content is processed transiently there and not retained.

Sub-processors

  • Google OAuth. Console sign-in. We receive name and email from your Google account.
  • Stripe. Payment processing and subscription management. Handles card data; we do not store full card numbers.
  • Modal. Managed infrastructure for Codag-controlled inference.
  • Railway. US-based cloud hosting for the API and database.
  • Vercel. Hosting for the web console.
  • Resend. Transactional email delivery (such as organization invites).
  • PostHog. Product analytics, website analytics, feature usage, and opt-out state for non-essential analytics.

These providers process data only as needed for their service and are bound by their own agreements. We will update this list before adding any new sub-processor.

Data sharing

We do not sell or rent your data. We do not share it with third parties for marketing. We disclose data only when required by law.

Your rights

  • Access, correct, or delete your account data.
  • Export your usage records.
  • Request full deletion of all per-customer data by emailing [email protected]. We honor requests within 30 days.

EU and UK residents have additional rights under GDPR; California residents have additional rights under CPRA. Contact us to exercise them.

Changes

Updates to this policy will be posted here with a new date. Material changes will be announced by email to account owners. Continued use of the service after changes take effect constitutes acceptance.

Contact

Questions or deletion requests? Email [email protected].