Privacy Policy
Last Updated: February 14, 2026
1. Introduction
CodeCrew ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our software development services and Slack application.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, company name, billing information
- Project Information: Requirements, specifications, feature requests, bug reports
- Communication Data: Messages sent through Slack, support requests, feedback
- Payment Information: Processed securely through our payment processor (we do not store credit card details)
2.2 Automatically Collected Information
- Usage Data: How you interact with our services, features used, time spent
- Technical Data: IP address, browser type, device information, operating system
- Slack Workspace Data: Workspace ID, channel names, user IDs (we do not store message content unless explicitly authorized)
2.3 Code and Repository Metadata
- Repository Metadata: Repository names, commit messages, pull request titles, branch names
- We Do NOT Store: Your source code, proprietary algorithms, or business logic
- Access: Our developers and AI agents access your repositories only during active development with your explicit authorization
3. How We Use Your Information
We use your information to:
- Provide software development services and AI-amplified squad coordination
- Facilitate communication between you and your development squad
- Process payments and manage subscriptions
- Improve our AI models and development workflows (only with anonymized data)
- Send service updates, sprint reports, and important notifications
- Provide customer support and respond to inquiries
- Comply with legal obligations and enforce our terms
4. Slack Integration and Permissions
4.1 Slack Scopes and Access
Our Slack application operates in two modes and requests the following permissions:
- Bot Mode: Read and send messages in channels where the bot is explicitly added or mentioned
- Assistant Mode: When enabled, read and respond to messages in private DMs to provide AI-powered assistance with code drafting, reviewing, and development questions
- User Information: Access user profiles, email addresses, and workspace details
- File Access: Read and share files related to development tasks
- Reactions & Pins: Manage reactions and pinned messages for task tracking
4.2 Message Access by Mode
- Bot Mode: Reads messages only in public/private channels where @CodeCrew is explicitly added or mentioned
- Assistant Mode: Reads messages in private DMs when you interact with the assistant to help draft messages, review code, or answer development questions
- Control: You control which mode is active and can disable assistant mode at any time via workspace settings
4.3 What We Do With Slack Data
- Process commands and requests related to your development projects
- Coordinate communication between you and your squad
- Track project progress and deliverables
- Send automated updates about sprints, deployments, and code reviews
- In assistant mode: Help draft messages and review code snippets shared in DMs
4.4 What We Don't Do
- Read messages in channels or DMs where CodeCrew is not active or mentioned (bot mode)
- Access DMs if assistant mode is disabled
- Share your Slack data with third parties for marketing purposes
- Use conversations for AI training without explicit consent and anonymization
- Store message content permanently (processed in real-time only)
5. Data Sharing and Disclosure
5.1 We Share Information With:
- Your Development Squad: Human developers assigned to your project
- Service Providers: Hosting (AWS), payment processing (Stripe), analytics (minimal, anonymized)
- AI Model Providers: OpenAI, Anthropic (only with anonymized, non-proprietary data)
- Legal Requirements: When required by law, subpoena, or to protect our rights
5.2 We Do NOT:
- Sell your personal information or source code to third parties
- Share client data between different customer projects
- Use your proprietary code to train public AI models
6. Data Security
We implement industry-standard security measures:
- Encryption: All data encrypted in transit (TLS) and at rest (AES-256)
- Access Controls: Role-based access, multi-factor authentication for team members
- Code Repository Security: OAuth tokens securely stored, rotated regularly
- Monitoring: Continuous security monitoring and incident response procedures
- Compliance: SOC 2 Type II certified (in progress), GDPR compliant
7. Data Retention
- Account Data: Retained while your subscription is active and 90 days after cancellation
- Project Data: Retained for the duration of service plus 30 days for hand-off
- Communication Logs: Retained for 1 year for support and quality purposes
- Billing Records: Retained for 7 years for tax and legal compliance
- Repository Access: Revoked immediately upon subscription cancellation
8. Your Rights and Choices
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Data Portability: Receive your data in a structured, machine-readable format
- Opt-Out: Unsubscribe from marketing emails (service emails still sent)
- Revoke Access: Remove Slack app or GitHub/GitLab integrations anytime
To exercise these rights, contact us at privacy@usecodecrew.com
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by the European Commission
- Data processing agreements with all service providers
- Compliance with GDPR for EU customers
10. Children's Privacy
CodeCrew is not intended for individuals under 18. We do not knowingly collect information from children. If you believe we have collected information from a child, contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via:
- Email notification to your registered address
- Slack notification in your workspace
- Prominent notice on our website
Continued use of our services after changes constitutes acceptance.
13. California Privacy Rights (CCPA)
California residents have additional rights under CCPA:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt-out of sale (we do not sell data)
- Right to deletion
- Right to non-discrimination for exercising privacy rights