← Codethio

Privacy Policy

Codethio · Updated September 5, 2026

Controller: Denilson Padilha de Morais (Codethio). Contact: [email protected].

1. Scope

This policy applies to the Codethio website, demos, applications, automation services and integrations that refer to it. Each feature explains its purpose and required permissions. Describing an integration here does not mean it is available in every product or authorize access by itself.

2. Data and purposes

3. Google, Gmail and Google Workspace

Connecting a Google account requires the authorization presented by Google. We do not ask for your Google password. Permissions must be limited to features offered and chosen by you; authorization does not provide unrestricted access to all account services.

Depending on the enabled feature and permission, a Gmail integration may use email addresses, recipients, subjects, bodies, attachments, message identifiers and labels to send emails, retrieve messages and attachments, organize messages, summarize content and prepare AI-assisted replies. Reading, modifying and sending are separate capabilities and must be explained when connecting. Other Google services, such as Calendar or Drive, require information about specific data and purposes before access.

Google data and content derived from it may only be used to provide or improve requested, user-facing features. We do not use it for advertising, selling data, credit assessment or training general-purpose AI models. We do not allow people to read this content except with affirmative permission for specific data, for security, to meet legal obligations, or under the aggregated-use exceptions allowed by Google's policy.

Codethio's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including Limited Use requirements. Transfer to providers is only permitted for the authorized function, security, legal compliance or another circumstance expressly permitted by that policy.

4. Artificial intelligence

AI features may process content needed to answer, summarize or prepare a requested action. For Google integrations, sending content to an AI provider requires clear information about the provider, data and function, as well as corresponding authorization; authorizing Gmail does not automatically mean agreeing to every AI use.

In the WhatsApp demo, OpenAI processes content needed for the reply without the phone number field and with Responses storage disabled. Information typed in messages may be included in this content. Do not send passwords, documents or sensitive personal data to the demo.

5. Storage, security and providers

AI features using Google data must identify their provider before activation. This policy does not authorize transfers to an undisclosed provider. Data required for the service is processed in Codethio's systems and those of the providers involved. The demo currently uses Cloudflare (hosting, protection and Turnstile), Supabase (database), Meta (WhatsApp and Flows) and OpenAI (AI). Google is involved when a Google connection is authorized. Other providers for integration data must be disclosed in the relevant feature before transfer.

In the demo, phone numbers and message content are encrypted; derived identifiers recognize returning visitors, and the dashboard shows only the last four phone digits. Administrative access is restricted. Integration credentials must not be exposed on public pages or shared with unauthorized parties. Providers may process data outside Brazil, subject to applicable protection and international transfer conditions.

6. Retention

Contact data is kept as long as needed for support, the business relationship and applicable obligations. For integrations, content and credentials must be limited to what the authorized function needs, and specific retention periods must be disclosed before use. This policy does not authorize indefinite storage of Google account content.

The demo session has a configurable duration shown by the website timer and is not extended by interactions. Connection codes expire after five minutes. Messages and results are subject to cleanup within seven days; operational events within 30 days; identity is removed after 30 days without activity. Cleanup runs every minute. Deletion requested through the site removes linked records sooner. Cost estimates detached from identity may remain.

Records strictly necessary for legal obligations, fraud prevention or exercising rights may be retained with restricted access. Copies and records held by providers also follow those services' controls and retention periods.

Deleting data does not renew free limits. To prevent abuse through deletion and registration, we temporarily retain an HMAC-protected identifier, used segments and the current cycle deadline. This record does not contain plaintext phone numbers, messages or results. It is removed after the cycle deadline; security blocks may be retained for up to 30 days after deletion. The identifier is pseudonymized, not anonymous, and access is restricted.

7. Cookies and measurement

The demo uses a necessary, secure, HttpOnly cookie to identify the session. The site has measurement integrations such as Google Analytics and Cloudflare Analytics. Browser controls let you manage cookies; restricting necessary cookies may prevent connection. Data from connected Google accounts is not intended for website advertising or analytics tools.

8. Rights and choices

Under applicable law, including Brazil's LGPD, you may request confirmation of processing, access, correction, sharing information, portability where applicable, objection, withdrawal of consent and deletion. Processing may be based on fulfilling requests or contracts, consent where required, legal obligations and legitimate security and operational interests, respecting your rights.

You can revoke Google access in Google Account Connections. Revoking access does not automatically delete data already processed: see deletion instructions or contact us above. We may request only the information needed to verify ownership.

9. Changes

Updates will be published here. New integration purposes or permissions require prior information and new authorization where applicable. This policy does not replace product-specific notices.