Privacy Policy
Last Updated: August 15, 2026
This policy explains what we collect when you use CodeSpring, why we collect it, who else sees it, and what you can do about it. We have written it in plain English rather than legal boilerplate, because a policy you cannot read is not much use to you.
1. Who We Are
CodeSpring is operated by Volkis Ltd, a company registered in England and Wales with company number 13309940. Volkis Ltd is the data controller for the personal information described in this policy.
- Registered office: 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London, W1T 6EB
- Email: support@codespring.app
- Website: https://codespring.app
2. What This Policy Covers
This policy covers two things:
- Our website at codespring.app, including our marketing, pricing, checkout and class registration pages. Sections 3 to 8 deal mainly with this.
- The CodeSpring app, which you sign in to and use to plan and build software, together with the CodeSpring command line tool. Sections 9 to 14 deal with this.
Sections 15 onwards apply to both. Where something applies only to one of them, we say so.
3. Information You Give Us
- Your name and email address, when you create an account, register for one of our live classes, or contact support.
- Billing details, when you subscribe. Payments are taken by Whop, our payment provider. Card details are entered on Whop's checkout and are handled by Whop, not by us. We receive confirmation of the payment, the plan you bought, and your billing contact details.
- Anything else you choose to send us, such as the contents of a support email.
The information you give us inside the CodeSpring app, including your project content, conversations and uploads, is described in sections 9 and 10.
4. Information Collected Automatically on Our Website
When you use the website, we and the tools listed in section 5 collect:
- Your IP address, and an approximate location (country and region) worked out from it
- Browser type and version, device type, screen size and operating system
- Which pages you visit, which page referred you, and how long you stay
- Clicks, scroll depth, and which buttons and links you use
- The campaign parameters on the link you arrived through (utm_source, utm_medium, utm_campaign, utm_term, utm_content), which we store in your browser so we can tell which ad or post brought you here
- Errors and performance data
5. The Tracking Tools We Use
This is the complete list for our website. Nothing else is loaded on our marketing pages for tracking purposes. The providers we use inside the CodeSpring app are listed separately in section 14.
All of these load when the page loads. We do not show a cookie banner and we do not ask you to opt in first. Every tool below starts as soon as you open a page on codespring.app, and it starts for every visitor. Section 8 sets out what you can do about that.
Analytics
- PostHog (PostHog Inc.), for product analytics and session recording. It records the pages you view, clicks on our main buttons and links, scroll depth, how long you stay, the campaign parameters above, and a randomly generated identifier stored in your browser that lets us recognise the same browser across pages and visits. It also records your session, which we describe in full in section 6. Our PostHog data is sent to and stored on PostHog's European infrastructure at https://eu.i.posthog.com. We have turned off PostHog's automatic capture of every element on the page, so only the events we have defined ourselves are sent. We use it to see which pages get read and where people get stuck.
- Hotjar (Contentsquare), on our live class registration page only. Hotjar produces heatmaps and session recordings for the same purpose. It loads whenever that one page is opened, and it is not loaded anywhere else on the site.
Marketing and advertising
- Meta Pixel (Facebook and Instagram ads), pixel ID 822461710838084. It tells Meta that you visited a page on our site, along with your IP address, browser details and Meta's own cookie identifiers (_fbp and _fbc). Meta uses this to report which of our ads led to sign-ups, and to show you our ads on Facebook and Instagram.
- TikTok Pixel, pixel ID D3HODNJC77U8DNMA2BCG. It does the same job for our TikTok ads.
- Google tag (gtag.js), tag ID AW-17192976548, used for Google Ads conversion tracking and remarketing. We use Google Consent Mode v2, and the state we declare before Google's tag loads grants ad storage, ad user data, ad personalisation, analytics storage, functionality storage and personalisation storage.
- Hyros, loaded from t.codespring.app. Hyros does click attribution: it links the ad or link you clicked to what you later do on the site, so we can tell which ads pay for themselves. Hyros offers no opt-out control of its own, so the only thing that governs it is whether it loads at all, and it loads on every page.
Embedded content from other companies
Some of our pages embed a feature that another company runs. Using that feature means sharing data with them:
- WebinarJam (Genesis Digital LLC), for live class registration. If you register, the name and email you enter go to WebinarJam so they can send you the joining link.
- Whop, for checkout and subscription management. Whop handles your payment details. Whop's checkout also runs a Meta Pixel inside its own frame, set to the same pixel ID as ours, so Meta is told when a checkout is started and when a payment completes.
- YouTube (Google), for embedded videos. Playing an embedded video lets YouTube set its own cookies and collect data about what you watched.
6. Session Recording
We use PostHog session recording both on our website and inside the CodeSpring app. A recording is a replayable reconstruction of what you did, which we can watch back afterwards. How it is turned on and off differs between the two, so we describe them separately.
On our website
Session recording in PostHog runs from the moment a page loads. We do not ask you to turn it on first.
What is captured
- The pages you open and their contents as they appeared on your screen
- Mouse movement, clicks and taps
- Scrolling, window resizing and navigation between pages
- The timing of all of the above, so the visit can be replayed at the speed it happened
What is not captured
- Values you type into form fields. The recorder masks input values and replaces them with placeholder characters in your browser, before anything is sent to PostHog. Password fields are never captured.
- Anything outside the browser tab our site is open in. It is not a video of your screen, and it cannot see your other tabs, your other windows, your files or your camera.
- Contents of a frame served by another company. Our recorder is set to include embedded frames where that is technically possible, but a third-party embed such as the Whop checkout does not pass its contents back to us.
Text that was already displayed on the page is captured as it appears, so anything the page shows you is visible in the replay.
Why we do it. To find the places where the site confuses people, and to understand bug reports we could not otherwise reproduce.
How to stop it. Blocking the PostHog script in your browser stops the recorder, because the recorder is that script. A content or tracker blocker, or your browser's own tracking protection, will do it. You can also email support@codespring.app and ask us not to record your visits.
If you want recordings of your visits deleted, email support@codespring.app and we will delete them.
In the CodeSpring app
Session recording is enabled in the app. We use it to understand how the product is used, to see where people get stuck, and to diagnose problems and bug reports. The recording covers the app in the browser tab you have it open in: the screens and panels you open and their contents as they appeared to you, mouse movement, clicks, scrolling, navigation, and the timing of all of it. Because it reconstructs the app as it appeared on your screen, your project content and conversations are visible in the replay. This is separate from the website recording described above, and it is covered by a different legal basis, set out in section 15.
If you want recordings of your app sessions deleted, or would prefer your sessions not to be recorded, email support@codespring.app.
7. Cookies and Similar Technologies
On our website we use cookies and your browser's local storage. There is no cookie banner and there are no cookie categories to choose between. Everything described below is set when you open a page.
- Analytics. PostHog and, on the live class registration page, Hotjar, as described in sections 5 and 6, including session recording. PostHog stores a randomly generated identifier for your browser and the campaign parameters you arrived with.
- Advertising. Meta Pixel, TikTok Pixel, the Google tag and Hyros, as described in section 5. These set the advertising identifiers those platforms use, including Meta's _fbp and _fbc, Google's _ga and _gcl, and TikTok's _ttp.
- Necessary. The site's light or dark appearance follows your operating system setting and is not stored at all.
We do not ask first. Until August 2026 these scripts were held back until you accepted them in a cookie banner. That banner has been removed. The scripts now load on page load, for every visitor, without asking you first, and there is no setting on this site that turns them off. If you would rather they did not run, section 8 sets out the controls that do work, and you can object to us directly.
In the CodeSpring app, we use cookies and local storage that are necessary to run it: keeping you signed in, holding your session, and remembering workspace preferences such as which project you last had open. The app also runs PostHog product analytics and session recording, described in sections 6 and 14. The advertising tools in section 5 are not loaded in the app.
8. How to Object or Opt Out
There is no on-site switch. These are the controls that actually work, and we would rather tell you about them than pretend otherwise.
- Your browser. Block or delete cookies for codespring.app in your browser settings, and block third-party cookies generally. Deleting the cookies also clears the identifiers PostHog, Meta, Google and TikTok have stored for your browser.
- Tracking protection or a content blocker. Safari, Firefox and Brave block many of these scripts by default, and a content blocker extension will block the rest. Because every tool in section 5 is a script loaded from another company's domain, blocking the script is what stops the tool: it cannot run and it cannot send anything.
- Meta. Change what Facebook and Instagram do with data about your visits in your Meta account, under Ad preferences in the Accounts Centre.
- Google. Turn off ad personalisation in Google's My Ad Center on your Google account.
- TikTok. Change your ads and data settings in your TikTok account privacy settings.
- Ask us. Email support@codespring.app and tell us you object to being tracked on the website, or ask us to delete the analytics data and session recordings we hold for your visits. We will do it. This is also how to exercise the rights in section 19.
Our Terms are separate from this. Accepting our Terms of Service when you create an account has nothing to do with the tracking described above, and we do not treat it as permission for it. Objecting to tracking does not change your agreement to the Terms.
9. Your Account and How You Sign In
You can sign in to CodeSpring with Google, with GitHub, or with an email magic link sent to your address.
- If you use Google or GitHub, we receive your name, email address, profile picture and the account identifier that provider uses for you. We never see your password for those accounts.
- If you use a magic link, we hold your email address and a short lived sign-in token.
- Your account record holds your name, email address, profile picture and the provider identifiers above.
- If you are part of an organisation or team, we record which organisation your account belongs to, your role in it, and who else is a member.
- You can create API keys to use CodeSpring programmatically. We store a record of each key against your account and log when it is used.
- We record your IP address and browser or client user agent against your sessions, and against events sent by the CodeSpring command line tool.
Signing in with GitHub also grants repository access, which is described in section 12.
10. Information in the App
While you use CodeSpring, we store:
- Project content. The mind maps, features, PRDs, tasks, notes and wireframes you create, and the projects and workspaces they sit in.
- Conversations. Your chat conversations with CodeSpring and the individual messages in them.
- Uploads. Files and images you upload, and the text we extract from uploaded documents so that the app can work with their contents.
- Usage and credits. Which features you used and when, and the credits your account has been granted and consumed.
- Support. Support tickets and the messages in them, whether you open them in the app or by email.
- Billing records. Described in section 13.
- Technical records. The session and command line tool records described in section 9, and error and performance data.
11. AI Features
CodeSpring's AI features are powered by models run by OpenAI. To provide them, we send OpenAI the material the feature needs in order to produce a result. Depending on what you are doing, that includes:
- The content of your conversations, including the messages you write and the earlier messages in that conversation
- Your project and mind map data, such as features, notes, PRDs and tasks, where the feature works from them
- Images you upload
- Text extracted from documents you upload
This happens when you use a feature that needs it. OpenAI processes the content on our instructions in order to return the result to you. AI output can be inaccurate or incomplete, so please review anything you rely on.
12. GitHub and Other Services You Connect
GitHub. Signing in with GitHub grants CodeSpring access to your repositories. CodeSpring uses that access to read repository metadata, so it can understand the project you are working on, and to write CodeSpring generated files, such as PRDs and plans, into the repositories you choose. You decide which repositories to use. You can review and revoke CodeSpring's access at any time from your GitHub account settings.
Integrations you connect yourself. CodeSpring lets you connect third-party services, including MCP servers, to your workspace. When you connect one, the project content that integration works with is shared with that service. Those connections are made by you and controlled by you, the provider's own terms and privacy policy apply to what they do with the data, and we are not responsible for their handling of it. Disconnect an integration if you no longer want content shared with it.
Web search and page fetching. If you use a feature that searches the web or reads a web page, the query or the address you asked for is sent to Firecrawl, which performs the search or fetch and returns the result.
13. Payments
Payments are taken by Whop, our payment processor. Your card details are entered on Whop and are handled by Whop. They never reach CodeSpring and we never store them. What we store is the email address used for the purchase, Whop's identifiers for the customer and the purchase, and the amount and currency paid. We use this to give you the plan you bought, to handle renewals, refunds and disputes, and to keep our accounting records.
14. The Providers We Use to Run the App
These companies handle data on our instructions so that we can run CodeSpring:
- OpenAI, for the AI features described in section 11.
- PostHog, for product analytics and session recording inside the app, described in section 6.
- Resend, for transactional email such as sign-in links, invitations and notifications.
- Intercom, for in-app support chat. Messages you send us there, and your name and email address, are held by Intercom.
- Cloudflare R2, for storing the files and images you upload.
- Firecrawl, for web search and page fetching when you use those features.
- Whop, for payments and subscriptions, described in section 13.
- Render and Amazon Web Services, for hosting the application and its database.
Each of them acts as our processor: they handle the data in order to provide their service to us, under a contract with us.
15. How We Use Your Information, and Our Legal Basis
Under UK and EU data protection law we need a lawful basis for each thing we do with your data. Ours are:
- Running your account, providing the service and taking payment. This includes storing your project content, running the AI features on the content you give them, connecting the repositories and integrations you ask us to connect, and tracking your credit usage. Basis: performance of our contract with you.
- Answering support requests. Basis: performance of our contract, or our legitimate interest in helping people who contact us.
- Website analytics, website session recording, advertising measurement and retargeting. We no longer ask for your consent to these, so we are not relying on your consent as the basis for them. The tools in section 5 load on page load for every visitor. You can object, and you can stop them, as described in section 8.
- Product analytics and session recording inside the app. Basis: our legitimate interest in understanding how the product is used, fixing problems and improving it. You can object to this, as described in sections 6 and 19.
- Keeping the service secure, preventing fraud and abuse, and defending disputes and chargebacks. Basis: our legitimate interest in protecting the business and our other customers.
- Sending you marketing emails. Basis: your consent, or our legitimate interest in telling existing customers about closely related products. Every email has an unsubscribe link.
- Keeping accounting and tax records. Basis: a legal obligation we have as a UK company.
16. Who We Share It With
We do not sell your personal information for money. We share it with:
- The website tools named in section 5, in the circumstances described there
- The providers named in section 14, who process data on our instructions in order to run the app
- Whop, our payment provider, for checkout, subscriptions and dispute handling
- GitHub and any integrations you connect yourself, as described in section 12
- Other members of your organisation or team, who can see the projects and content shared in that workspace
- Professional advisers, such as accountants and lawyers, where we need their advice
- Authorities and other parties where the law requires it, or where we need to establish or defend a legal claim
- A buyer or successor, if the business or its assets are sold or reorganised
Be aware that the advertising platforms listed in section 5 receive data about your visit as soon as you open a page, and use it for their own purposes as well as ours, including building advertising profiles. Some privacy laws treat that as “sharing” or even as a “sale” of personal information. Blocking those scripts in your browser prevents it, as described in section 8.
17. International Data Transfers
We are based in the United Kingdom. PostHog data from our website is sent to PostHog's European Union infrastructure. Most of our other website providers, including Meta, Google, TikTok, Hyros, Whop, WebinarJam and Contentsquare's Hotjar, are based in or transfer data to the United States and other countries outside the UK and EEA.
The CodeSpring app is hosted in the United States. Our application servers and database run on Render and on Amazon Web Services in the us-east-1 region, and the files you upload are stored on Cloudflare R2. OpenAI, Resend, Intercom, Firecrawl and Whop are also based in or transfer data to the United States. This means your account details, project content, conversations and uploads are stored and processed outside the UK and the EEA.
Where that happens, we rely on the transfer safeguards the provider offers, which are usually the UK International Data Transfer Addendum, the European Commission's Standard Contractual Clauses, or the provider's own certification under the EU-US and UK-US Data Privacy Framework. If you want to know which safeguard applies to a particular provider, email us and we will tell you.
18. How Long We Keep It
- Account and billing records. For as long as your account is open, and afterwards for as long as we need them for tax, accounting and legal reasons. UK company and tax records are generally kept for six years.
- Project content, conversations and uploads. For as long as your account is open, so that your work is there when you come back to it. Content you delete inside the app is removed from your workspace.
- Analytics events and session recordings. These are held by PostHog and Hotjar and are deleted automatically at the end of the retention period that applies to our plan with each of them. We do not keep separate copies. You can ask us to delete recordings of your visits or sessions sooner.
- Support tickets and emails. For as long as we need them to deal with your request and any follow-up.
- Cookies and identifiers in your browser. Each cookie in section 7 lasts for the period the tool that set it uses, and stays until it expires or you clear your browsing data. Clearing it is described in section 8.
Deleting your account. To have your account and the content in it deleted, email support@codespring.app from the address on your account. We will confirm when it is done. Deletion is permanent and we cannot restore project content afterwards. We keep the billing and tax records the law requires us to keep.
19. Your Rights
If you are in the UK or the EEA, you have the right to:
- Ask for a copy of the personal data we hold about you
- Have inaccurate data corrected
- Ask us to delete your data
- Ask us to restrict how we use it
- Object to processing we carry out on the basis of legitimate interests, and object to direct marketing at any time
- Receive the data you gave us in a portable format, or have it sent to another provider
- Withdraw consent at any time, for anything we do on the basis of consent
To use any of these rights, email support@codespring.app. We will respond within one month. We may need to check who you are before we act, so that we do not hand your data to someone else. Deleting your account and the content in it is covered in section 18.
If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk, or to the data protection authority in your own country. We would rather you told us first so we can put it right.
20. Security
We use technical and organisational measures to protect your information, including encrypted connections, access controls on our systems, and limiting who on our side can see what. No method of transmission or storage is completely secure, so we cannot promise absolute security.
Authorised CodeSpring personnel can access account and project data where it is needed to provide support, investigate a problem or meet a legal obligation.
21. Children
CodeSpring is not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us their information, email support@codespring.app and we will delete it.
22. Links to Other Sites
Our pages link to sites we do not run. Once you follow a link, that site's own privacy policy applies, and we are not responsible for what they do with your data.
23. Changes to This Policy
We update this policy when what we do changes. The date at the top tells you when it last changed, and the current version is always the one on this page. If we start using a new tracking tool on the website, it goes in section 5 before it is switched on. If we start using a new provider to run the app, it goes in section 14.
24. Contact Us
Questions about this policy, or about your data:
Volkis Ltd (trading as CodeSpring), registered in England and Wales, company number 13309940
Registered office: 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London, W1T 6EB
Email: support@codespring.app
Website: https://codespring.app