1. API access data
CodeCobra records the email supplied when requesting a key, the API product, credit balance, key prefix and final characters, and a non-reversible hash of the full key. The full key is displayed once and is not stored in recoverable form.
2. Anonymous traffic measurement
Public pages set a first-party cc_visitor identifier for up to one year. It is used to count anonymous unique visitors. Page path, request time, and browser user-agent are recorded. Staff pages, API calls, health checks, static assets, and recognized automated crawlers are excluded from visitor analytics.
3. API and support records
API request logs include the product, endpoint, status, latency, credits used, key record, and request time. Contact and bug reports include the information submitted in their forms. Never submit secrets in a support or bug report.
4. Payments
Stripe processes paid checkout. CodeCobra records the resulting checkout reference, amount, selected credit package, and payment state, but does not store complete card details.
5. Retention and control
Operational and financial records may be retained for security, accounting, dispute handling, and service reliability. Anonymous visitor records are used only for aggregate traffic reporting. This policy requires legal review before general commercial launch.
6. Questions
Privacy questions can be submitted through the contact page.