Privacy Policy
Last updated: 7 August 2026
1. Who we are
SAASCODE, LLC, a limited liability company formed in Delaware, United States (file number 10701106), operates saascode.ai and is the controller of the personal data described here.
131 Continental Drive, Suite 305, Newark, DE 19713, United States support@saascode.ai
For privacy questions, requests, or complaints, email support@saascode.ai. A person reads that mailbox.
2. What this covers
This policy covers saascode.ai: the website, your account, purchases, downloads, support, the newsletter, and our AI assistant.
It does not cover the software you buy from us. Once you download our source code and deploy it, you run that application. Any data your own users put into it is yours to handle — we have no access to it and are not the controller of it. Your deployment needs its own privacy policy.
It also does not cover the payment itself. See section 5.
3. What we collect
We collect only what a given interaction needs. We do not buy data about you, and we do not build advertising profiles.
When you create an account Email address, and a hashed password if you register with one. If you sign in with a third-party provider, we receive your email address, name, and profile image where the provider supplies them — never your password with that provider. We also store your account creation date and sign-in timestamps.
When you buy something Your account identifier, which products you bought, when, at what price, and the transaction reference from our payment provider. We do not collect, see, or store your card number, CVC, or bank details. Those go directly to the payment provider.
When you download A record that your account requested a download of a given product version, with a timestamp. We use this to enforce your entitlement and to investigate abuse or a disputed charge.
When you open a support ticket or use the enquiry form Your name and email, the message you write, anything you attach, and the products in your account so we can help you in context.
When you subscribe to the newsletter Your email address, the date you subscribed, and confirmation that you clicked the link in the confirmation email. Also whether you opened or clicked our emails, so we can tell whether they are worth sending.
When you chat with Ada, our AI assistant The messages you send and the responses generated. Do not put passwords, keys, or anything confidential into the chat.
Automatically, as you use the site Your IP address, browser and device type, pages visited, referring page, and timestamps. We also store a randomly generated visitor identifier, a session identifier, and the campaign or referring page you first arrived from, in your browser's local storage — see section 9. Error reports when something breaks — which include technical context about the failure and, where it happened while you were signed in, your account identifier.
What we deliberately do not collect: payment card data, government identifiers, precise location, or any special category data (health, biometrics, political or religious views, and so on). Please do not send it to us.
4. Why we use it, and on what legal basis
Where the GDPR or UK GDPR applies to you, these are our legal bases.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account | You cannot download without one | Performance of a contract |
| Process your purchase and grant your entitlement | It is what you paid for | Performance of a contract |
| Issue and enforce download links | To deliver only to people who bought | Performance of a contract |
| Notify you about a product update or a service change | Part of what a purchase includes | Performance of a contract |
| Answer support tickets and enquiries | To help you | Contract, or legitimate interest for pre-sale enquiries |
| Run the AI assistant | To answer questions on the site | Legitimate interest in supporting visitors |
| Send the newsletter | You asked for it | Consent |
| Keep the site secure, rate-limit abuse, investigate fraud and chargebacks | To keep the service working and honest | Legitimate interest |
| Monitor errors and fix them | To keep the product working | Legitimate interest |
| Measure how the site and catalog are used | To understand what is useful and improve it | Legitimate interest |
| Keep purchase and tax records | We are required to | Legal obligation |
Where we rely on legitimate interest, we have weighed it against your rights, and you can object — see section 8.
Where we rely on consent, you can withdraw it at any time. That does not affect anything done before you withdrew.
5. Who we share it with
We do not sell your personal data and we do not share it for anyone else's marketing.
We use these service providers. Each receives only what its job requires.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Account data, purchase records, support tickets, download entitlements | United States |
| Vercel | Hosting and delivery of the website | IP address, request metadata, anything you submit passes through | United States and global edge network |
| Vercel Web Analytics | Measures page views and product events, without cookies | Page and event data, coarse device and country information | United States and global edge network |
| Cloudflare | DNS and email routing | Request and DNS metadata, email in transit | Global network |
| Resend | Transactional and newsletter email | Email address, message content, delivery and open events | United States |
| OpenRouter | Routes AI assistant messages to a language model | Your chat messages and the context of the conversation | United States |
| Sentry | Error monitoring | Technical error context, IP address, account identifier where signed in | United States |
| Upstash | Rate limiting | IP address and request counters | United States |
| Creem (Armitage Labs OÜ) | Payments, as merchant of record | Your name, email, billing country, card details you enter at its checkout, transaction data | European Union |
About payments specifically. Creem is the merchant of record for your purchase: it is the legal seller for that transaction, and it is an independent controller of the payment data you give it, under its own privacy policy. It tells us that a payment succeeded and for what — not your card details. If we add another merchant-of-record provider, we will list it here.
We may also disclose data where the law requires it, to respond to a valid legal request, to enforce our Terms, or to protect our rights, security, or someone's safety. If we are ever part of a merger or acquisition, data may transfer to the acquirer, subject to this policy.
6. International transfers
We are in the United States and our providers are mostly in the United States and the European Union. If you are outside those places, your data will be transferred to them.
For transfers of EU, UK or Swiss personal data to the United States, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), and on each provider's own transfer safeguards, including certification under the EU-US Data Privacy Framework where the provider holds one.
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account is open, then 12 months after you close it |
| Purchase and tax records | 7 years from the transaction — we are required to keep these, and they survive account deletion |
| Download logs | 24 months |
| Support tickets | 24 months after the ticket is closed |
| Newsletter subscription | Until you unsubscribe, plus a suppression record so we do not email you again by mistake |
| AI assistant conversations | 30 days |
| Error telemetry | 90 days |
| Server and security logs | 90 days |
After these periods we delete or irreversibly anonymise the data. Anything under an active legal hold or dispute is kept until it is resolved.
8. Your rights
Wherever you are, you can ask us to:
- Access the personal data we hold about you, and get a copy.
- Correct anything inaccurate.
- Delete your data. Note that purchase and tax records have to stay for the period in section 7.
- Export your data in a portable, machine-readable format.
- Restrict or object to processing based on legitimate interest, including our use of your data for security analysis.
- Withdraw consent, at any time — every newsletter has a one-click unsubscribe link.
Email support@saascode.ai. We will verify that the request comes from the account holder, and reply within 30 days. It is free, unless a request is repetitive or clearly excessive.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
If you are in the EU or UK, you can complain to your local data protection authority. We would appreciate the chance to fix it first.
If you are in California, you have the rights above under the CCPA/CPRA, plus the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined, and we have not in the last 12 months.
9. Cookies and similar technology
We keep this minimal.
- Essential cookies — keep you signed in, keep your session secure, and protect against cross-site request forgery. The site does not work without them, so they are set without asking.
- Preference storage — remembers things like your theme choice, in your browser.
- Analytics storage — three values kept in your browser's local storage: a randomly generated visitor identifier that persists between visits, a session identifier, and the campaign or referring page you first arrived from. They carry no name, email, or anything else that identifies you, and they are never handed to an advertiser.
We do not run advertising trackers, and we do not follow you across other websites. We do use one analytics product — Vercel Web Analytics — which measures page views and a small set of product events without setting cookies. Alongside it we record those same events in our own database, tied to the visitor identifier above, so we can tell which parts of the catalog are actually useful.
Our providers may set strictly necessary cookies for security and load balancing. You can block cookies and clear local storage in your browser; if you block the essential ones you will not be able to sign in or download.
10. Children
saascode.ai is a tool for people building software and is not directed at children. You must be at least 16 to hold an account, or older where your country requires it. We do not knowingly collect data from children. If you believe a child has given us data, email support@saascode.ai and we will delete it.
11. Security
We use encryption in transit, hashed passwords, access controls on our infrastructure, private storage with short-lived signed links rather than public files, and rate limiting on sensitive endpoints. Access to production data is limited to those who need it.
No system is perfectly secure and we will not claim otherwise. If a breach affects your personal data and presents a risk to you, we will notify you and the relevant authority as the law requires.
12. Changes to this policy
We may update this policy. The "Last updated" date at the top always shows the current version.
For material changes we will give notice by email or through a notice on the site before they take effect. Where a change requires your consent, we will ask for it.
13. Contact
SAASCODE, LLC 131 Continental Drive, Suite 305 Newark, DE 19713, United States support@saascode.ai
