Privacy Policy

Effective date: August 2nd, 2026

Deep Code(we, us, or our) take your privacy seriously. Please read this Privacy Policy to learn how we treat your personal data. By using or accessing our Services in any manner, you acknowledge that you accept the practices and policies outlined below, and you hereby consent that we will collect, use and disclose your information as described in this Privacy Policy.

Remember that your use of Deep Code is at all times subject to our Terms of Service, which incorporates this Privacy Policy. Any terms we use in this Policy without defining them have the definitions given to them in the Terms of Service.

You may print a copy of this Privacy Policy by clicking the print button in your browser.

As we continually work to improve our Services, we may need to change this Privacy Policy from time to time. We will alert you of material changes by placing a notice on the Deep Code website, by sending you an email and/or by some other means. Please note that if you've opted not to receive legal notice emails from us (or you haven't provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes.

This Privacy Policy (Policy) outlines how Deep Code collects, uses, shares, and otherwise processes Personal Data from users, including developers, entrepreneurs, and visitors (User, you, or your) of our website, any software, platform (collectively, our Services). By using our Services, you acknowledge and agree to this Policy.

This Policy incorporates our Terms of Service. If you do not agree with the terms of this Policy, please discontinue your use of our Services. Existing users with contractual obligations should contact us to discuss applicable terms.

Definitions

  1. a. Data Protection Laws: Collectively, (i) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (the GDPR), UK GDPR and any implementing or supplementary legislation, and (ii) all U.S. federal or state privacy statutes in force during the Term together with other national laws governing the Processing of Personal Data. If the Customer is a UK entity, any reference to the GDPR shall be interpreted to include a reference to the UK GDPR.

  2. b. Personal Data: For purposes of this Policy, Personal Data (also called personal information under the California Consumer Privacy Act/Privacy Rights Act and similar U.S. state laws) means any information that relates to an identified or identifiable natural person or is reasonably capable of being linked to a particular consumer or household, as set out in the EU GDPR, UK GDPR, Canada's PIPEDA, the revised Swiss Federal Act on Data Protection, and all applicable U.S. federal or state privacy statutes. Personal Data may include, for example, your name, business email address, postal address, telephone number, username, unique device or browser identifiers, Internet-protocol (IP) address, authentication tokens, usage and telemetry logs, or other information generated through your use of our Services.

  3. c. Service Data: Any data relating to the use, support and/or operation of the Services, which is collected directly by Deep Code from the Customer's use of the Service. Service Data is used for Deep Code's security, billing, analytics, or product-improvement purposes. Service Data is not Personal Data.

Collection of Personal Data

We collect personal data when you use our Site and our Service. Personal data is any information that relates to you, identifies you personally or could be used to identify you including, but not limited to: your name, mailing address, email address, and telephone number. Any text or data you input into the Service ("Inputs") that include personal data will also be collected by us. We do not control, and are not responsible for, LLMs' handling of your Inputs or Outputs, including for use in their model training. To understand how your Inputs are used by LLMs, check their LLM Terms in the Third-Party Model Providers section below.

The types of personal data that we may collect include, but are not limited to: the personal data you provide to us, personal data collected automatically about your use of our Site or Service, and information from third parties, including our business partners.

Personal Data You Voluntarily Provide to Us

The personal data we collect from you may include:

Personal Data Collected Automatically

As you navigate through and interact with our Site or Service, we may use automatic data collection technologies to collect certain information about your device, browsing actions and patterns, including:

Model Provider Data Practices

When you submit Inputs through the Service, those Inputs are transmitted to the Model Provider you select, or that is selected through automatic routing, as applicable. Different Model Providers have different data practices, including with respect to whether they retain or use your Inputs and Outputs to train, fine-tune, evaluate, or improve their Models. Some Model Providers may use your Inputs and Outputs for model training or improvement. Before using a Model, you should review the applicable Model Provider's data practices, which are listed in the Third-Party Model Providers section below. Where disclosed to us, we label Models that do not use your data for training. If you do not want your Inputs used for model training, select a Model or Model Provider that commits to not using your data for that purpose.

Cookies and Other Tracking Technology

We use cookies and similar tracking technologies to collect personal data automatically as you interact with our Site, to personalize your experience, and to analyze the use of our Service. For detailed information about the types of cookies we use, their purposes, duration, and how you can manage your cookie preferences, please see our Cookie Policy.

Data Handling In Deep Code Desktop

If you access Deep Code through our desktop app (Deep Code Desktop) the data handling of Integrations applies. Certain actions may be taken locally on your device. Where no data is transmitted to Deep Code's servers or the Deep Code API, such processing does not constitute a submission of Customer Data to Deep Code and is not subject to this Policy. More information can be found in our Desktop App Terms.

Children's Data

Deep Code's Services are not intended for individuals under the age of eighteen (18), and we do not knowingly collect or solicit Personal Data from anyone under this age, unless as part of a program with a partner, the child has obtained consent or authorisation from a parent or guardian before they can use the Services. By using our Services, you represent that you are at least 18 years old or the age of majority in your jurisdiction. If we discover that we have collected Personal Data from a minor without verifiable parental consent, we will promptly delete that information. If you believe we may have collected such data, please contact us at [email protected].

Sensitive Data

Deep Code does not intentionally collect special-category or sensitive Personal Data, such as biometric identifiers, health information, or precise geolocation, and instructs customers not to upload such information. This definition will be interpreted to include any equivalent term under other privacy laws that come into force during the life of this Policy.

We process Personal Data for the following purposes:

Deep Code does not engage in automated decision-making that produces legal or similarly significant effects on individuals (GDPR Art 22). We collect only the Personal Data necessary for these purposes and retain it in line with the schedule in the Policy. You can exercise your opt-out or objection rights to certain processing activities as described in this Policy.

How we use your Personal Data

Deep Code processes Personal Data only where a valid legal ground applies under each privacy regime that governs our Services.

Legal bases we rely on:

Data Usage

We do not use Personal Data for training.

International Data Transfers

For customers in the EEA, UK, or Switzerland, we may transfer Personal Data to the United States or other jurisdictions whose privacy laws have not not been deemed adequate by European or Swiss authorities. Deep Code safeguards these transfers through the following legally recognized mechanisms:

Investigations

Deep Code may investigate and disclose information, as permitted by law, if we believe in good faith that such action is:

Disclosures will comply with Data Protection Laws and be limited to what is necessary.

Log Data

When you use our Services, Deep Code automatically collects operational telemetry (Log Data) that helps us secure and improve the platform. Log Data may include:

Log data is retained for up to ninety (90) days, unless required by law, to monitor performance, troubleshoot issues, and improve user experience.

Cookies and Other Tracking

Deep Code and selected third-party partners use cookies, pixels, and similar technologies (Cookies) to operate, secure, and analyze our Services. We deploy four types of Cookies:

You can manage or withdraw your Cookie preferences at any time by (i) clicking the Cookie Preferences button in our Cookie Policy, (ii) changing your browser controls, or (iii) enabling an authorized browser signal such as the Global Privacy Control. Disabling non-essential Cookies will not affect core functionality but may limit analytics-based improvements. Cookie-derived identifiers are retained only for the period necessary to fulfil the purposes above and never longer than thirteen (13) months for analytics cookies after which they are deleted or irreversibly anonymized.

Information Security and Accuracy

Deep Code is committed to protecting your Personal Data and maintaining its accuracy. We implement reasonable industry standard safeguards, including:

Deep Code keeps a record of processing activities in line with GDPR Article 30(2) and performs regular risk assessments to adapt these measures as threats evolve. If you believe your account information is inaccurate, contact us as set out in this Policy and we will correct it promptly. We implement reasonable security measures (e.g., encryption in transit/rest, access controls) to protect your Personal Data, but our Services rely on third-party providers like Cloudflare(for Deep Code Desktop), DeepSeek, and OpenRouter (for AI Gateway). We cannot guarantee uninterrupted availability, security, or performance of these providers, and data interruptions, delays, or losses may occur due to their actions or events beyond our control (including force majeure). For Deep Code Desktop, certain provisioned resources may not be immediately terminable via API; you remain responsible for any data hosted there until fully decommissioned. In cases of misuse or abuse (e.g., excessive data uploads causing cost spikes), you agree to indemnify us for related privacy or security claims arising from third-party provider interactions, as detailed in our Terms of Service. We use commercially reasonable efforts to notify you of material security incidents involving your data but disclaim liability for third-party failures.

Retention of Your Information

We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including:

Our Services may include links or integrations (for example, GitHub, Cloudflare, CI/CD tools, or payment providers) that are not controlled by Deep Code.

Your interactions with Third-Party Services are governed by their own privacy policies and terms. We encourage you to review those policies before providing Personal Data, as Deep Code is not responsible for the privacy or security practices of external sites or integrations.

Notice and Communications

By using the Services, you consent to receive transactional or administrative electronic communications from Deep Code - such as account alerts, security notifications, and billing messages. You may opt out of non-essential marketing e-mails at any time via the unsubscribe link or your account settings; this will not affect core service communications. To send formal privacy notices to Deep Code, e-mail [email protected] or post to the address in this Policy. Deep Code may provide legal or privacy notices to you via e-mail, in-product banners, or any other method allowed by law.

Governing Law & Venue

This Policy is governed by and governed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law principles. However, if you are located in a jurisdiction that grants you mandatory consumer protection or data protection rights under local law, those provisions will take precedence to the extent they conflict with this Policy. For residents of the European Economic Area (EEA), United Kingdom (UK), or Switzerland, international data transfers are subject to the EU Standard Contractual Clauses governed by Irish law with the courts of Dublin as the chosen forum, the UK International Data Transfer Addendum governed by the laws of England and Wales with the courts of London as forum, and the Swiss Addendum governed by Swiss law with the FDPIC as the competent authority. Any other disputes arising under this Policy shall be exclusively resolved in the state or federal courts located in Wilmington, Delaware, unless otherwise required by applicable mandatory law. We disclaim warranties on data accuracy/security in AI outputs or third-party services. See Terms for IP ownership (you own Customer Data/AI Output; we own Usage Data).

Residents of the United States, Canada, EEA, United Kingdom, and Switzerland

This section supplements the rest of the Policy and applies to individuals located in the United States - including California, Colorado, Connecticut, Virginia, Utah, Florida, Nebraska, and any other state with an active consumer-privacy statute, as well as Canada, the EEA, the United Kingdom, and Switzerland. Deep Code collects the personal information categories below when you use the Services:

Depending on where you live, you may have some or all of the rights listed below (subject to legal limits). You can exercise them by e-mailing [email protected]; Deep Code will verify your identity and respond within 30 days or the period required by your local law.

Deep Code will not discriminate against you for exercising your privacy rights. If you believe a request has been wrongly denied, U.S. residents may file an appeal by replying to our decision within sixty days; EEA, UK, or Swiss residents may contact their supervisory authority (the Irish DPC, the UK ICO, or the FDPIC).

Changes to This Policy

Deep Code reserves the right to update or revise this Privacy Policy to reflect changes in our practices, legal requirements, or the Services themselves. We will post any revised Policy at https://deepcode.zip/legal/privacy-policy and indicate the Effective date at the top of the document. For material changes that reduce your rights or expand our processing purposes, we will provide at least thirty (30) days' advance notice by e-mail or in-product banner. Your continued use of the Services after the new Policy takes effect constitutes acceptance of the revised terms.

Severability

If any provision of this Policy is found to be unlawful, void, or unenforceable under applicable law, that provision will be interpreted to achieve its intent as closely as possible, or, if impossible, deemed severed, and the remaining provisions will remain in full force and effect.

Contact Details

If you have questions, concerns, or wish to exercise your privacy rights, please contact us. We have appointed a Data Protection Officer (DPO) that you can contact at:

We aim to respond to verified data-subject requests within thirty (30) days, or longer where permitted under applicable law, in which case we will notify you of the delay and reason. If you believe your inquiry has not been satisfactorily resolved, you may lodge a complaint with your local supervisory authority, the Irish Data Protection Commission, the UK Information Commissioner's Office, or the Swiss FDPIC, as appropriate.

Additional U.S. State Disclosures and Legal Bases for Processing Under the GDPR

The GDPR and some U.S. state privacy laws require specific disclosures. The below provides additional information about the categories of personal data we collect and how we use and disclose that information. You can read more about the personal data we collect and where we collect it from in the "Collection of Personal Data" above, how we use personal data in "How We Use Your Personal Data" above, and how we retain personal data in "Retention of Your Information" above.

Categories of Personal DataUse of Personal DataDisclosure of Personal Data

We collect the following information, as described above:

  • Identifiers, such as your name, contact details, IP address, and other device identifiers
  • Commercial information, such as your transaction history
  • Network activity information, such as how you interact with our Service
  • Communication information, such as your contact information when you send us email
  • Geolocation data, such as the general area from which your device accesses our Service based on information like its IP address, or precise location information you choose to provide
  • Your account credentials

We use this information for the following purposes, as described above:

  • Provide, analyze, and maintain our Service, and where applicable, for Model training and improvement by Model Providers. The legal basis is to perform a contract with you.
  • Improve and develop our Service and conduct research. The legal basis is a legitimate interest.
  • Communicate with you, including to send you information about our Service and events. The legal basis is your consent.
  • Prevent fraud, illegal activity, or misuses of our Service, and to protect the security of our systems and Service. The legal basis is legitimate interest and legal obligation.
  • Comply with legal obligations and protect the rights, privacy, safety, or property of our users, OpenRouter or third parties. The legal basis is legitimate interest and legal obligation.

We may disclose this information in the following circumstances, as described above:

  • Vendors, service providers, and affiliates to process in accordance with our instructions, including to Model Providers
  • Government authorities or other third parties for the legal reasons described above
  • Parties involved in corporate transactions
  • Other users and third parties you interact or share information with

Third-Party Model Providers

Our Services integrate with the following third-party model providers. Please review their Terms of Service and Privacy Policy for information about how they handle your data.

ProviderTerms of ServicePrivacy Policy
DeepSeek https://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html
OpenRouterhttps://openrouter.ai/termshttps://openrouter.ai/privacy

Entire Agreement

This Policy, together with the Terms of Service constitutes the entire agreement between you and Deep Code regarding privacy and data protection in connection with the Services.