Subprocessors

Placeholder: the binding list will follow together with the Privacy Policy. These are the service providers Codo uses to run the service.

Hetzner Online GmbH

Purpose
Hosting: the server that runs the Codo app and API, its database and backups
Data
All data stored by Codo
Location
Data center [Placeholder]

Cloudflare, Inc.

Purpose
DNS, encryption (TLS) and the network path to our server – all traffic to codo.codes and app.codo.codes passes through Cloudflare; bot protection (Turnstile); encrypted off-site backups
Data
Network traffic including IP addresses; encrypted backups
Location
Global network; United States [Placeholder]

GitHub, Inc. (Microsoft)

Purpose
Sign in with GitHub; access to the repositories you connect through the Codo GitHub App
Data
GitHub account ID, name and email address; metadata of connected repositories
Location
United States [Placeholder]

Email delivery [Placeholder]

Purpose
Sending sign-in codes and notifications by email
Data
Email address and message content
Location
[Placeholder]

Error tracking [Placeholder]

Purpose
Error reports from the app, the server and the connector – cleaned of file paths, prompts and code
Data
Technical error data
Location
[Placeholder]

Status service [Placeholder]

Purpose
Uptime monitoring and a status page
Data
No personal data intended
Location
[Placeholder]

Not subprocessors

Anthropic (Claude Code), OpenAI (Codex) and Anysphere (Cursor) are not Codo subprocessors. You use these tools under your own accounts and contracts. Codo’s servers do not send your data to them; features that use them run on your computer with your own account or API key, which never reaches Codo’s servers.

Changes

We will update this list before a new subprocessor starts processing personal data. [Placeholder]