Privacy
CoDesk reads your business tools to answer questions about them. This page says exactly what that involves.
Who we are
CoDesk is operated by Pulse Pilot AI, LLC, 1544 Rosa Cir, Webster, NY 14580, United States. For anything on this page, reach us through our contact page.
What we collect from you directly
- Your account. Name, work email, and a password if you set one. You can sign in with Google, with an email and password, or with a one-time link sent to your email; we store only what the method you choose requires.
- Your workspace. The company name you pick, your role, and who else you invite.
- What you ask. Your questions and the answers returned, so a conversation can continue and you can come back to it.
What we read from your connected tools
When you connect a tool, CoDesk reads from it to answer your questions. It can only ever see what the credentials you supply can see; connecting a tool does not widen anyone’s access to it.
- Project and issue records, including status, assignment and history.
- Code activity: changes, reviews and releases.
- Messages in the channels you choose to connect.
- Meeting transcripts and the action items drawn from them.
Some of this is fetched at the moment you ask and not retained. Messages, transcripts, documents you upload, and issue discussions are indexed so they can be searched by meaning, which means we hold a processed copy inside your workspace.
When you disconnect a tool, CoDesk stops reading from it immediately and the stored credential is destroyed immediately. Content already indexed stays searchable in your workspace — answers about past meetings survive a tool change — until a workspace admin deletes it or asks us to. When a workspace is deleted, everything we hold for it is removed within 30 days.
Google user data
Gmail and Google Calendar work differently from the workspace-level tools above: each person connects their own Google account, and their questions read only their own mailbox and calendar. Nobody else’s questions can read yours.
- What we request. Read access to Gmail (
gmail.readonly), permission to save drafts and send email from your account (gmail.compose), and read-only access to Google Calendar (calendar.readonly). CoDesk cannot delete or modify existing messages, and cannot change calendar events. - When we write. Only when you click. If you ask CoDesk to draft an email, it shows you the draft to edit. Nothing leaves the app unless you choose Save to Gmail Drafts or Send, and what is saved or sent is exactly the text you reviewed. CoDesk never sends on its own, on a schedule, or in bulk.
- How it is used. When you ask a question that needs your email or calendar, CoDesk fetches the relevant messages or events at that moment and uses them solely to produce your answer. Google content is not added to the search index and is not retained beyond the answer itself; the answer, including anything it quotes, is kept in your chat history like any other answer.
- How it is stored. The only Google data we store is your OAuth token, encrypted at rest, so you do not have to reconnect for every question.
- How it is shared. Content fetched to answer your question is processed by our model provider (Anthropic) solely to generate that answer. It is never used to train models and never shared for advertising or sold.
- Revoking access. Disconnect any time from Settings → Your profile, which destroys the stored token, or from your Google account’s security settings.
CoDesk’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we never do
- We do not use your business data to train models, ours or anyone else’s.
- We do not sell your data or share it for advertising.
- We do not let one workspace see another’s data. Separation is enforced in the database, not only in the application.
- We do not change anything in your tools by ourselves. CoDesk can prepare a draft, but it only reaches your systems when a person approves it, and we record who did.
Who else processes your data
Running CoDesk means passing data through a small number of other services:
- Supabase — hosts the database and handles sign-in.
- Anthropic — the model that reads retrieved records and writes the answer.
- Voyage AI — turns messages and transcripts into the form that makes search-by-meaning possible.
- Vercel — hosts and serves the application.
- The tools you choose to connect, which you already have your own relationship with.
If your compliance review needs region details or a data-processing agreement, ask us through the contact page and we will provide specifics for each provider.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it — deletion requests are honored within 30 days. Because most of what CoDesk reads lives in your own tools, deleting your workspace removes what we hold rather than anything of yours at source.
Security
Access is scoped per workspace and enforced at the database level. Credentials for connected tools are stored encrypted. Every question, every record read and every action approved is logged, so an answer can be taken apart months later. If a security incident affects your data, we will inform affected workspace owners promptly.
Changes
If we change this policy in a way that matters, we will tell workspace owners rather than quietly updating the date at the top.