CodeRocket legal
Privacy policy
This policy explains what CodeRocket needs to recreate and host websites, protect accounts, provide guided changes, and manage subscriptions.
Last updated: July 17, 2026
1. Who is responsible
The operator of CodeRocket is responsible for personal data processed through coderocket.app. Privacy requests can be sent to contact@coderocket.app.
2. Data we process
- Account identity, email address, authentication provider, and profile preferences.
- Website names, source URLs, selected pages, access mode, and project settings.
- Public source text, images, links, visual settings, editable site documents, versions, and publishing status.
- Generation and editing requests, generated versions, model metadata, and usage records.
- Plan, Stripe customer and subscription identifiers, invoices, and payment status.
- Security, delivery, error, support, and operational logs.
- Optional analytics data, such as visited pages, navigation events, browser and device information, and approximate location, only after consent.
CodeRocket does not ask for payment card details directly. Stripe collects and processes payment information on its hosted pages.
3. Why we use it
We use this data to provide and secure the service, create requested website versions, publish approved versions, answer support requests, prevent abuse, administer subscriptions, and comply with legal obligations. Where consent is required, it can be withdrawn without affecting earlier lawful processing.
4. Website content and generated versions
Website recreation opens only public HTTPS pages and stores a bounded component document, not the source HTML or JavaScript. Owned-site mode may retain visible public copy and image URLs; inspiration mode removes source identity, images, and wording. When a user requests a first version or a change, bounded source content and relevant project context are sent to the configured AI provider. Common credential patterns are removed first. Passwords, access tokens, cookies, and secret headers must not be included in prompts or support requests.
5. Service providers
CodeRocket relies on service providers for hosting and networking, Supabase authentication and database services, Stripe billing, OpenAI-powered website generation, Google Analytics where consent is given, and transactional email. They process data only for the service they provide and under their own security and privacy commitments. International transfers may occur with appropriate contractual safeguards.
6. Retention
Generated website versions are retained while the website and account remain active so owners can recover earlier work. Temporary import captures expire automatically. Account, billing, security, and legal records may be kept longer when required for fraud prevention, dispute handling, tax, or legal compliance. Unpublishing a site removes its public version.
7. Security
CodeRocket uses tenant isolation, row-level database policies, encrypted HTTPS transport, hashed access tokens, signed billing webhooks, restricted service credentials, and safe URL validation. No internet service can guarantee absolute security, so suspected incidents should be reported promptly.
8. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection. You may also withdraw consent and complain to the competent data protection authority. Optional analytics can be turned off at any time from Cookie settings. We may need to verify other requests before acting on them.
9. Changes
Material changes will be reflected on this page with a new update date. If a change materially affects existing account data, CodeRocket may also notify account holders by email or inside the product.