CodexFlow
WorkflowInstall layerUpdatesPricingDocs
Get CodexFlow
WorkflowInstall layerUpdatesPricingDocs
CompareDemoFAQ
Read docsGet CodexFlow
←Legal center

CodexFlow legal

Privacy Policy

How CodexFlow handles personal data across the website, checkout, licensing, fulfillment, support, security, and analytics.

Policy status

Production Ready
Updated
24 May 2026
Effective
24 May 2026
Operator
Nova Group Sp. z o.o.
Jurisdiction
Poland / European Union

Documents

TermsPrivacyCookiesRefundsDisclaimerImprintSecurityAccessibility

On this page

1. Controller2. Scope3. Categories of personal data4. Purposes and legal bases5. Payment processing6. Analytics, advertising, and consent tools7. Cookies and local storage8. AI support chat9. Recipients and processors10. International transfers11. Retention periods12. Data subject rights13. Complaint to supervisory authority14. Automated decision-making15. Security16. Children
ScopePoland / European Union
Version24 May 2026
CompanyNova Group Sp. z o.o.

This Privacy Policy explains how Nova Group Sp. z o.o. processes personal data in connection with CodexFlow, the website at https://codexflow.io, and related checkout, license, delivery, support, analytics, security, and marketing operations.

1. Controller

The controller of personal data is:

Nova Group Sp. z o.o.
Żurawia 6/12 Lok. 745
00-503 Warszawa, Poland
Tax ID / VAT ID: PL7011215529
KRS: 0001117840
REGON: 529224431
Website: https://codexflow.io
Privacy contact: privacy@codexflow.io
Support contact: support@codexflow.io

2. Scope

This Policy applies when you visit the website, interact with CodexFlow pages, create or access an account, purchase or evaluate a digital product, receive a license or activation file, download protected materials, contact support, consent to analytics or marketing cookies, or communicate with CodexFlow.

CodexFlow is a developer workflow product. Unless expressly requested for support, you should not send repository secrets, passwords, private keys, card data, credentials, confidential customer data, or unnecessary sensitive personal data.

3. Categories of personal data

CodexFlow may process the following categories of personal data:

  • identification and contact data, such as name, email address, company name, VAT number, and billing details;
  • account and authentication data, such as account identifiers, login session data, access status, and security events;
  • order and payment-related data, such as selected tier, price, currency, payment status, transaction identifiers, tax status, invoice data, refund status, and dispute status;
  • license and fulfillment data, such as license tier, activation status, access token metadata, signed activation records, download records, hashes, manifest access, access timestamps, and evidence snapshots;
  • technical data, such as IP address, device identifiers, browser type, operating system, approximate location inferred from IP, logs, timestamps, referrer, and security signals;
  • website usage data, such as page views, consent choices, conversion events, product interactions, docs visits, and checkout funnel events;
  • support data, such as messages, attachments, issue history, refund requests, complaint records, and responses;
  • marketing and advertising data, such as campaign source, ad click identifiers, consent status, remarketing eligibility, and conversion metadata where permitted;
  • compliance and fraud-prevention data, such as risk signals, audit logs, payment-provider metadata, and security records.

4. Purposes and legal bases

CodexFlow processes personal data for the following purposes:

PurposeExamplesLegal basis
Providing the website and digital productaccount access, secure customer page, license delivery, activation file, payload access, install documentationperformance of a contract or steps before a contract
Processing orders and paymentscheckout, payment confirmation, invoices, refunds, disputes, payment evidenceperformance of a contract, legal obligation, legitimate interests
License and access managementtier rights, activation, secure downloads, access revocation, evidence logsperformance of a contract, legitimate interests
Customer support and complaintsresponding to support, access, refund, and complaint requestsperformance of a contract, legitimate interests, legal obligation
Tax, accounting, and complianceinvoices, accounting records, VAT records, statutory retentionlegal obligation
Security and fraud preventionabuse detection, access logs, suspicious payment handling, incident responselegitimate interests, legal obligation
Analytics and product measurementtraffic measurement, funnel analysis, aggregate performance statisticsconsent where required; legitimate interests for strictly necessary or privacy-preserving measurement where lawful
Advertising and remarketingX conversion tracking, Google Ads conversion tracking, remarketing, campaign performanceconsent where required
Consent managementrecording and honoring cookie and tracking choiceslegal obligation, legitimate interests
Legal claims and enforcementchargeback evidence, dispute handling, license misuse responselegitimate interests, legal obligation

5. Payment processing

CodexFlow does not store full card details. Payments may be processed by Stripe, Worldline, or another payment provider shown at checkout. Payment providers may collect and process card details, payment authentication data, fraud-prevention data, billing data, transaction identifiers, and compliance records.

Payment providers may act as processors for some activities and as independent controllers for activities they determine themselves, such as payment security, fraud prevention, compliance, reporting, and legal obligations.

6. Analytics, advertising, and consent tools

CodexFlow may use Cookiebot CMP, Google Consent Mode v2, GA4, X conversion tracking, Google Ads conversion tracking and remarketing, Plausible Analytics, PostHog, Clerk, Stripe, Worldline, and similar tools.

Where consent is required, analytics, advertising, remarketing, and non-essential storage are used only according to your consent choices. You can change or withdraw consent by reopening the cookie settings widget available on the website.

Google Consent Mode v2 may send consent signals to Google services, including consent status for analytics storage, advertising storage, ad user data, and ad personalization, depending on configuration and your choices.

7. Cookies and local storage

The website uses cookies and similar technologies for essential website operation, consent management, authentication, payment security, analytics, advertising, fraud prevention, and support of digital delivery. Details are provided in the Cookies Policy.

8. AI support chat

If you use the CodexFlow support chat, CodexFlow may log the chat transcript, raw IP address, hashed IP address, session identifier hash, page path, topic, model metadata, security guardrail status, fallback status, and approximate token usage. These logs are used to provide support, investigate abuse, improve installation guidance, protect the service, and diagnose delivery or checkout issues.

Chat messages may be processed by OpenAI or another AI model provider configured for the support assistant. Do not paste passwords, card details, private keys, API keys, raw activation files, raw license files, repository secrets, or other confidential material into chat. CodexFlow applies automated redaction and guardrails for common sensitive patterns, but customers remain responsible for avoiding unnecessary secrets in support messages.

Support chat transcripts and raw IP addresses are typically retained for up to 1 year, unless a longer period is needed for security investigation, dispute handling, legal claims, or compliance. After the retention period, CodexFlow may redact transcript contents and raw IP addresses while retaining aggregate metadata for security and operational reporting.

9. Recipients and processors

Personal data may be shared with:

  • payment providers, including Stripe and Worldline;
  • authentication and account providers, including Clerk where enabled;
  • consent management providers, including Cookiebot;
  • analytics and advertising providers, including X, Google, Plausible, and PostHog where enabled;
  • hosting, database, storage, security, logging, and infrastructure providers;
  • email and transactional messaging providers;
  • customer support, accounting, legal, tax, compliance, and fraud-prevention service providers;
  • public authorities, courts, payment schemes, banks, or regulators where legally required;
  • professional advisers and service providers supporting CodexFlow operations.

Data is shared only where needed for the purposes described in this Policy.

10. International transfers

Some providers may process data outside the European Economic Area. Where required, CodexFlow relies on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, transfer impact assessments, supplementary security measures, or another lawful transfer mechanism.

11. Retention periods

CodexFlow keeps personal data only as long as needed for the purpose for which it was collected, unless a longer period is required or permitted by law.

Data categoryTypical retention
Account datafor the life of the account and a reasonable period after closure
Order, invoice, and accounting recordsfor the period required by tax and accounting law, usually at least 5 years from the end of the relevant tax year
License, activation, fulfillment, and access evidencefor the license period and limitation periods for claims, refunds, chargebacks, and disputes
Payment, refund, and dispute metadatafor payment-provider, accounting, anti-fraud, and legal-claim periods
Support and complaint correspondencefor the time needed to handle the case and limitation periods for related claims
AI support chat transcripts and raw IP addressestypically up to 1 year, unless longer retention is needed for investigation, disputes, legal claims, or compliance
Security logstypically 6 to 24 months, unless longer retention is needed for investigation or legal claims
Analytics dataaccording to tool settings and consent choices, commonly 13 to 24 months
Marketing consent and cookie consent recordsfor as long as needed to prove and respect consent choices
Newsletter or marketing contact datauntil consent is withdrawn or objection is made, unless retention is needed to prove compliance

12. Data subject rights

Subject to conditions under GDPR and applicable law, you may have the right to:

  • access your personal data;
  • receive a copy of your data;
  • correct inaccurate data;
  • request erasure of data;
  • restrict processing;
  • object to processing based on legitimate interests;
  • withdraw consent where processing is based on consent;
  • request data portability;
  • object to direct marketing;
  • lodge a complaint with a supervisory authority.

To exercise rights, contact privacy@codexflow.io. CodexFlow may need to verify your identity before acting on a request.

13. Complaint to supervisory authority

If you believe your data protection rights have been violated, you may lodge a complaint with the President of the Personal Data Protection Office in Poland.

14. Automated decision-making

CodexFlow does not intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects for customers.

Payment providers, fraud-prevention tools, advertising systems, and security tools may use automated risk or eligibility signals. These tools support payment security, fraud prevention, ad measurement, and platform integrity.

15. Security

CodexFlow applies administrative, technical, and organizational measures designed to protect personal data, including access controls, protected delivery flows, hashed or masked identifiers where appropriate, logging, secure payment-provider handling, and restricted access to operational systems.

No internet service can guarantee absolute security. Customers should protect their own accounts, devices, repositories, access links, activation files, and secrets.

16. Children

CodexFlow is intended for developers and business or individual users capable of entering into a contract. It is not directed to children.

17. Changes to this Policy

CodexFlow may update this Privacy Policy when the website, product, providers, legal obligations, or data practices change. The current version is identified by the date at the top of this page.

CodexFlow

The operating system for Codex users: 2,000+ specialist skills, 11 agents, persistent memory, safe commands, and signed delivery.

Signed payloadsLocal filesGit review

Product

WorkflowInstall layerUpdatesPricing

Resources

DocsInstall guideSecurityTroubleshooting

Legal

TermsPrivacyCookiesRefundsSecurityImprintAll legalContact

Independent toolkit for Codex users. Not affiliated with, endorsed by, or sponsored by OpenAI.

Operated by Nova Group Sp. z o.o.

CodexFlow Support

Install, pricing, license, security

CF

I can help install your CodexFlow package, explain pricing, or answer security and license questions.

Messages may be logged for support and security. Do not paste secrets, license files, card details, or private keys.

Email supportPricingInstall docs