Legal
Privacy Policy
How we handle your information — and why we handle so little of it
This Privacy Policy explains how Cody Labs LLC ("we," "us," or "our") collects, uses, stores, and protects information when you use CODY, our mobile reflection application (the "App"). We built CODY with a foundational principle: your data belongs to you. We collect the minimum necessary to run the app, we keep it on your device, and we never sell it.
1. Who This Policy Applies To
CODY is built for teens and young adults — we design the experience around ages 13 to 21. Anyone aged 13 or older may create an account; there is no upper age limit. We do not knowingly allow children under 13 to create accounts or use the App. If we discover that a user is under 13, we will delete their account and any associated data promptly.
If you are between 13 and 17, a parent or legal guardian may need to consent to your use of the App depending on applicable laws in your jurisdiction. We encourage parents to review this policy with their teens.
2. Information We Collect
2.1 Information You Provide Directly
During onboarding and use, you provide:
- Name or nickname
- Date of birth (used only to verify minimum age and compute your age for personalization)
- Email address (for account creation and password reset)
- Interests (optional, used to personalize your experience)
- Trusted Adult contact information (name, relationship, and email address). This is optional and is not required to use the App. You can add or update it anytime in your Profile under "Who has your back." This contact is stored on your account but is not currently connected to any active feature — CODY does not contact this person. We retain it so that features we may build in the future, aligned with helping you strengthen real-world connections, can use it with your involvement. We will update this policy and tell you before any such feature goes live.
- Profile photo (optional)
- Conversation content — what you type during reflection sessions
2.2 Information Generated Automatically
As you use CODY, the App generates:
- Conversation summaries (generated at the end of meaningful sessions) — stored locally on your device
- Behavioral insights (generated only when patterns are detected across multiple sessions) — stored locally on your device
- Monthly recap letters (generated after a full month with sufficient activity) — stored locally on your device
- Session metadata — opening and closing sentiment, an emotional arc, session length, and topics
- A crisis flag — stored only on your device as part of your local conversation record; it is not copied to our server (see Section 6)
A copy of the session metadata above (sentiment, emotional arc, session length, and topics) is also stored on our secure server, linked to your account so that only you can access it, and permanently deleted when you delete your account. The crisis flag is not part of this server copy. It never includes the words you typed.
2.3 Analytics Data We Collect
We collect de-identified, aggregate analytics to improve the App. This event data:
- Is tied only to a hashed (one-way) version of your Firebase user ID — not to your name or email
- Includes: age range (not exact age), gender category (bucketed, not exact), session duration, opening and closing sentiment values, mood entries you log (the mood label only), and bookmarks you add
- Does not include the content of your conversations, your name, or your email
Crisis detection is handled separately and is described in Section 6.2. The crisis-path event we record carries no user ID and is not part of the hashed-ID analytics described here.
Separately, the per-session record described in Section 2.2 (sentiment, emotional arc, session length, and topics) is stored linked to your account rather than to a hashed ID — so that you can access it and we can fully delete it when you delete your account.
We use Google Firebase / Firestore for this storage. See Section 5 for third-party details.
2.4 Information We Do NOT Collect
- Full conversation transcripts — we do not store these off your device; they stay on your device, except for the limited message-feedback case described in Section 2.5
- Your password (managed entirely by Firebase; we never see it)
- Your precise location
- Contacts from your phone
- Photos or media beyond a profile picture you choose to upload
- Any data from children under 13
2.5 Message Feedback You Choose to Send
If you flag a specific CODY response — for example, marking it unhelpful or wrong — that message and the few messages immediately before it are sent to our team so we can review and improve CODY's responses. This happens only when you choose to flag a message; we do not send any other conversation content.
3. How We Use Your Information
3.1 To Run the App
- Authenticate your account and maintain your session
- Generate AI-powered reflection responses tailored to your conversation
- Create conversation summaries, insights, and monthly recaps
- Enable you to resume past conversations
- Deliver crisis detection and resource surfacing (see Section 6)
3.2 To Improve CODY
- Analyze de-identified, aggregate usage patterns to improve the quality of the reflection experience
- Understand how teens engage with the App at a population level
3.3 What We Never Do With Your Information
- We never sell your data to advertisers or data brokers
- We never use your data to serve targeted advertisements
- We never share your conversation content with third parties
- We never use your data to train AI models without your explicit, separate consent
4. Where Your Data Lives
Almost all of your personal data is stored locally on your device. This includes your profile, conversation summaries, insights, recaps, and name preferences.
You may back up your CODY data to your personal iCloud account. This backup is stored in your iCloud — we have no access to it. Cody Labs never receives or holds your backup file.
The data that leaves your device is:
- De-identified analytics described in Section 2.3 (no conversation content)
- The per-session record described in Section 2.2 — sentiment, emotional arc, and crisis flag — linked to your account
- An encrypted copy of your profile (name, date of birth, interests, and Trusted Adult contact if you have added one), stored on our secure server so you can recover it if you reinstall the App. It is encrypted at rest. The Trusted Adult contact is stored as part of this profile only; it is not used to contact anyone.
- Conversation content needed to generate AI responses, which is processed transiently by our secure Cloud Run server and not stored off your device — except a flagged message and its immediate context if you choose to send feedback (Section 2.5)
5. Third-Party Services
CODY uses a limited set of third-party services to operate. We do not use advertising networks, data brokers, analytics platforms that build user profiles, or any third-party services beyond those necessary to run the App.
- Google Firebase / Firestore — account authentication and de-identified analytics storage
- Anthropic Claude — AI model powering reflection responses, accessed via our secure server; conversation content is not retained by Anthropic after processing
- Google Cloud Run — secure server infrastructure for AI processing
- Apple iCloud — optional user-controlled backup (we have no access)
6. Crisis Detection
CODY includes a safety feature designed to surface support resources when serious concerns arise. The teen is always in control.
6.1 How Crisis Detection Works
CODY's AI monitors conversations for signals across seven defined categories of concern (including self-harm, suicidal ideation, and unsafe home environments). When a signal is detected, the App surfaces crisis resources and hotlines on-screen so you can reach real-world help. CODY does not contact anyone on your behalf and does not send any message to your Trusted Adult or any other person.
6.2 Crisis Event Logging
CODY does not keep a per-user crisis log. When crisis detection occurs during a chat session, no crisis record is sent to our servers — the category of concern is stored only on your own device, as part of your conversation record, and never transmitted to us.
Separately, when a crisis signal fires on the mood-logging path, we record a single de-identified event for safety accountability. This event contains only a timestamp, a flag that a crisis path fired, and which path it came from. It is deliberately kept stricter than ordinary analytics: it carries no user ID, no email, no crisis category, and no link to any account or session. It cannot be traced back to you.
7. Data Retention and Deletion
- Conversations older than 30 days are automatically deleted from your device unless you bookmark them
- Your profile and account data persist until you delete your account
- De-identified analytics are retained indefinitely (these event records contain no direct personal identifiers)
- The de-identified crisis-path event described in Section 6.2 is retained for up to 3 years. Because it contains no user identifier or account linkage, it cannot be tied back to you or deleted on an individual basis.
7.1 Deleting Your Data or Account
You may delete all your local data or your full account at any time from the Profile screen — no need to contact us. Account deletion permanently removes your Firebase account, your server-side profile and session data stored in Firestore, and all data stored locally on your device. It does not automatically delete your iCloud backup — you must delete that separately from your iCloud settings.
To request deletion of de-identified analytics data, contact us at privacy@codylabs.co. As described in Section 6.2, the crisis-path event contains no personal identifiers and cannot be individually deleted.
8. Children's Privacy
CODY is designed for teens ages 13 and older. We do not knowingly collect personal information from children under 13. Users are required to enter their date of birth during onboarding, and we reject accounts where the date of birth indicates the user is under 13.
If we discover a user is under 13, we will immediately suspend their account and delete all associated personal information.
8.1 Parental Rights for Teen Users (Ages 13–17)
If your child is between 13 and 17 and uses CODY, you have the right to request access to, correction of, or deletion of their personal information. Contact us at privacy@codylabs.co. We will respond within 30 days.
9. California SB 243 Compliance
California SB 243 establishes requirements for companion chatbot operators with respect to minors. CODY operates transparently under this framework:
- CODY clearly discloses to all users that they are interacting with an AI system, not a human
- CODY maintains a documented crisis detection and referral protocol
- CODY implements measures to prevent the generation of harmful content involving minors
- Beginning July 1, 2027, we will file required annual reports with California's Office of Suicide Prevention
10. Your Privacy Rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your data, and to object to certain processing. California residents have additional rights under CCPA/CPRA.
To exercise any of these rights, contact us at privacy@codylabs.co. We will respond within 30 days. Note that self-serve deletion is available directly in the app.
11. Security
- All data in transit is encrypted via HTTPS/TLS
- Firebase authentication manages your credentials — we never store passwords
- Conversation content processed by our AI server is not logged or retained after generating a response
- Sensitive data on your device is stored using iOS secure storage
12. Changes to This Policy
When we update this policy, we will update the Effective Date and notify you in-app. For material changes, we will ask for your acknowledgment before they take effect.
13. Contact Us
Cody Labs LLC
Privacy inquiries: privacy@codylabs.co