Privacy Policy
Version 1.0 · Effective June 30, 2026
This policy explains what data Codetik collects, how it is used, and the rights you have over it. By using Codetik you agree to this policy.
Who We Are
Codetik is operated from Portugal. For the purposes of the EU General Data Protection Regulation (GDPR), the operator of Codetik is the data controller. You can reach us at legal@codetik.dev.
What We Collect
- Account data: your email address, handle, and profile details.
- Content: the tiks, code, and other material you create or publish.
- Usage and device data: how you interact with the app, device and app version, and similar technical information.
- IP address and approximate location, used for security and to shape the feed.
- Session recordings: how you move through and interact with the app (see below).
Session Replay and Analytics
We use session replay and product analytics tools, including LogRocket and UXCam, to understand how people use Codetik so we can fix bugs and improve the product. These tools may record the screens you view, your taps and gestures, navigation paths, and device information, and they may estimate your location from your IP address.
We configure these tools to avoid capturing passwords and similar sensitive fields, but recordings can include other information shown on your screen while you use the app. This data is used for product analytics only. We do not use it for advertising and we do not sell it.
By accepting our Terms of Service and using Codetik, you consent to this recording and analysis. You can ask us to stop recording your sessions at any time by emailing legal@codetik.dev.
How We Use Your Data
- To operate, maintain, and improve the Codetik platform.
- To personalise your feed based on the tags and content you engage with.
- To send transactional emails such as account confirmation and password reset.
- To detect, investigate, and prevent abuse, spam, and security incidents.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
Third-Party Services
We rely on a small set of service providers (sub-processors) to run Codetik. They process data only on our behalf:
- Supabase and Google Cloud — database, authentication, storage, and compute.
- Anthropic — AI models used to help create tiks.
- Google and GitHub OAuth — optional sign-in.
- Resend — transactional email delivery.
- RevenueCat — subscription and payment processing.
- LogRocket and UXCam — session replay and product analytics.
Legal Basis (GDPR)
We process your data to provide the service you request (performance of a contract), for our legitimate interests in keeping Codetik secure and improving it, and, where required, on the basis of your consent. Where we rely on consent, you may withdraw it at any time.
Data Retention
We keep your account data for as long as your account is active. When you delete your account, we remove your personal data within 30 days, except where we must keep it longer for legal or security reasons. Aggregated, anonymised data may be kept indefinitely.
Note that published tiks are openly licensed and may be forked by others. Copies and forks already made by other users are not deleted when you remove your tik or account. See the Terms of Service for details.
Your Rights
Under the GDPR you may request access to, correction of, export of, or deletion of your personal data, and you may object to or restrict certain processing. To exercise any of these, email legal@codetik.dev. You also have the right to lodge a complaint with your local data protection authority — for example, the CNPD in Portugal or the ICO in the United Kingdom.
International Transfers
Some of our providers process data outside the European Economic Area. Where they do, they rely on appropriate safeguards such as the European Commission Standard Contractual Clauses.
International Users
Codetik is operated from the EU but is available to people in other countries, including the United Kingdom, the United States, and Canada. By using Codetik from outside the EU, you understand that your data is processed in the EU and in other countries where our providers operate. We apply the GDPR as our baseline standard for everyone, and local laws may give you additional rights. Contact us at legal@codetik.dev to exercise them.
Children
Codetik is not intended for children under 13. If you believe a child under 13 has provided us with personal data, contact us and we will delete it.
Cookies and Local Storage
We use a session cookie or token to keep you signed in. Our analytics tools may store identifiers on your device to recognise sessions. We do not use advertising cookies or cross-site tracking for ads.
Changes to This Policy
We may update this policy from time to time. For material changes we will post an update here and, where appropriate, notify you by email. The effective date above always reflects the current version.