Skip to main content

Privacy Policy

Last updated: July 2026

Cody (the free GitHub Action) and Cody Pro (GitLab and Azure DevOps) run entirely inside your own CI/CD pipeline. We do not operate a server that your code passes through.

What data is processed

When Cody runs, it reads the diff and description of the pull/merge request being reviewed and sends that text directly to the AI provider you configure (Anthropic or OpenAI), using an API key you supply. That request is made from your own pipeline runner (GitHub Actions, GitLab CI, or your Azure DevOps build agent) — Cody Labs does not receive, log, or store this data.

License verification (Cody Pro for Azure DevOps)

The Azure DevOps extension verifies your license key against Gumroad's public license-verification API at pipeline run time. This check sends only the license key and our Gumroad product identifier — no source code, diffs, or repository data are included in this request.

Third parties

  • Anthropic and OpenAI process the code you send them under their own privacy policies and data-retention terms. Review their documentation if you have specific compliance requirements.
  • Gumroad processes your purchase and license key issuance under its own privacy policy.

Data we do collect

Standard, non-identifying web analytics for this site (page views on codylabs.pages.dev). We do not collect telemetry from the Cody tools themselves.

Contact

Questions about this policy: open an issue on GitHub.