codraftlegal

Legal

Privacy Policy

Last updated May 27, 2026.

1. Who We Are

codraft is built and operated by Fractal Labs LLC (Fractal Labs, we, us), a Delaware limited liability company. You can reach us at support@codraft.app.

2. What We Collect

We collect the following categories of information:

  • Account information. When you sign in to codraft, we receive your email address, name, and a unique profile identifier from the OAuth provider you used to sign in. We store this account record with our authentication and database provider.
  • Subscription information. Payments are handled by our third-party payment processor. The payment processor collects and stores your payment details directly; we receive only your subscription status, plan, renewal date, and the last four digits of your card.
  • Product analytics.codraft records how the application is used so we can understand which features matter and where the experience needs work. This includes things like application version, macOS version, anonymous install and session identifiers, which features and screens are opened, which agent integration is configured (for example, Claude Code or Cursor), how often you start an agent run, approximate latency of that run, and whether it succeeded or failed. It does not include the contents of your documents, your prompts, your agent's output, your file names, or your file paths.
  • Error and crash logs. When codraft hits an error or crashes, the application sends a diagnostic report so we can investigate. These reports contain technical context (stack traces, error codes, the operation that was in flight, application and OS version, anonymous install identifier) and are scrubbed of document content, prompts, agent output, file names, and file paths before they are sent.
  • Server logs. When your application contacts our servers (for sign-in, subscription checks, software updates, or analytics or error ingestion), our servers record standard request metadata such as IP address, user-agent, and timestamp. We use this to operate the Service, debug problems, detect abuse, and meet legal obligations.

3. What We Do Not Collect

We do not collect, read, store, transmit, or train on any of the following:

  • the contents of your documents;
  • the prompts you send to your AI agent or the output that agent returns;
  • file names, file paths, or folder structures on your Mac;
  • keystrokes, screen contents, or anything else you type or view inside codraft.

Document content stays on your device. Your AI agent (Claude Code, Cursor, GitHub Copilot, Codex, and so on) reads and edits it locally; what that agent sends back to its own provider is governed by that provider's privacy policy.

4. How We Use Information

We use the information we collect to:

  • create and authenticate your account;
  • manage your subscription, billing, and trial status;
  • provide customer support and respond to your requests;
  • understand which features are used and how the application is performing in aggregate, so we can prioritize what to build and fix;
  • diagnose crashes, errors, and reliability issues;
  • detect and prevent fraud, abuse, and security incidents;
  • meet legal and tax obligations.

We do not use your information for advertising and we do not sell or rent your personal information.

5. Service Providers

We rely on a small number of trusted service providers (subprocessors) to operate the Service. We use them by category rather than naming each vendor here so we can upgrade or change vendors without rewriting this policy.

  • an identity and OAuth sign-in provider;
  • an authentication, account database, and application hosting provider;
  • a payment processor for subscription billing and card handling;
  • a web hosting provider for the marketing site and account portal;
  • a product analytics provider and an error monitoring provider, which receive the telemetry and error reports described in Section 2 (and never receive document content, prompts, agent output, file names, or file paths);
  • an email delivery provider for transactional email (receipts, password resets, security notices).

These providers process information only on our instructions and under appropriate data protection agreements. We are happy to disclose the specific vendors in scope on request to support@codraft.app.

6. Where Information Is Stored

Your account information is stored in the United States by our authentication and database provider. Payment information is held by our payment processor under its own security practices. If you access codraft from outside the United States, your information will be transferred to and processed in the United States.

7. How Long We Keep Information

We retain your account information for as long as your account is active. If you delete your account, we delete your account record and associated subscription metadata within 30 days, except where we are required by law to retain certain information (for example, tax records related to past payments).

8. Your Rights

Depending on where you live, you may have the right to access the information we hold about you, correct inaccurate information, request deletion, object to or restrict certain processing, receive a copy of your information in a portable format, and lodge a complaint with your local data protection authority. To exercise any of these rights, email us at support@codraft.app and we will respond within 30 days.

If you are a California resident, the categories of personal information described in Section 2 are the same categories disclosed under the CCPA and CPRA. We do not sell or share your personal information.

9. Security

We use encryption in transit (HTTPS and TLS) for all communication with our servers. Account credentials are handled by our OAuth and authentication providers; we do not store passwords ourselves. We limit access to account data to the small number of Fractal Labs personnel who need it to operate the Service. Because we never collect your document content, there is no copy of it for us to defend.

10. Children

codraft is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at support@codraft.app so we can delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes we will post the updated policy here, update the Last updated date above, and try to notify you by email. Continued use of the Service after the update constitutes acceptance of the revised policy.

12. Contact

Questions, requests, or complaints? Email us at support@codraft.app.

Fractal Labs LLC