This policy explains how Shannon Labs, Inc. (“we” or “us”) handles information when you use Codewhale, a Shannon Labs product.
Information we collect
We collect the identity information needed to create and protect your account, including your GitHub identity, display name, and a primary verified email when GitHub makes one available. We also store product information you create, such as preferences, projects, conversations, Work runs, approvals, usage totals, purchased-balance and payment receipts, and security or operational receipts. Codewhale does not store full payment-card details.
How we use it
We use this information to authenticate you, operate and secure Codewhale, preserve your requested product state, provide support, and—only when you have enabled the relevant communication—send product or waitlist updates. We do not sell personal information.
Storage and processing
Codewhale is one global product. There is no residency selector, no region-specific account, and no promise that your account data stays in a particular jurisdiction. Account authentication and session state is stored in Cloudflare Durable Objects, today configured in Cloudflare’s US jurisdiction; that placement is an operational choice we may change, and we will update this policy when we do. Durable product state is owned by Codewhale’s private product runtime. Cloudflare may perform TLS, request routing, and cryptographic processing on its global edge, so we do not describe edge processing as US-only. Hosted compute is a separate system from account storage and, when enabled, identifies its placement before launch.
Service providers
We use these service providers to run Codewhale. Each processes information only as needed to provide its service to us.
Stripe processes payments, calculates sales tax, and handles receipts, refunds and payment disputes when you make a purchase.
Vercel AI Gateway routes the Codewhale-managed AI requests paid for from your AI balance, and DeepInfra, the model provider it uses today, serves the model and processes each request. Any other managed route uses the provider or gateway the product identifies, as described below.
Cloudflare hosts the Codewhale web app and API, routes and secures requests, and stores account authentication and session state.
Supabase provides sign-in and the database that holds your account and product records.
PostHog may receive the anonymous usage totals described under Settings, Usage data, and only while that setting is on: whole-number counts and a random install identifier that is not tied to your account, never your content.
Resend delivers email we send you.
Services you connect yourself, such as GitHub or your own model provider, handle information under their own terms.
Payments
When you buy a pack, you pay on a checkout page hosted by Stripe. Your card details go to Stripe and never reach Codewhale’s servers. To open checkout we give Stripe your account identifier and, when we have it, your email address; Stripe collects the billing details it needs to take the payment and calculate tax. We keep a record of each purchase: Stripe’s identifiers for you and for the payment, what you bought, the amounts charged (price, Platform fee and tax), the payment’s status, and any refund or dispute. We use these records to grant and account for your balance, answer your questions, prevent fraud, and meet tax and accounting duties, and we keep them as long as those duties require, including after account deletion. Stripe also uses payment information under its own privacy policy, including to prevent fraud.
Model providers and repositories
When you use bring-your-own-key inference, Codewhale sends the content needed for the request to the provider you connect, under your provider agreement. When you use managed inference, Codewhale sends the required prompt, context, tool results, and response data through the model provider or gateway identified by the product. Managed operator credentials remain inside Codewhale's trusted broker and are not exposed to you or to a provider sandbox. Provider retention, training, and regional processing are governed by the selected provider's terms and disclosed controls. Repository access is limited to the grants you approve with the source provider.
On-demand execution providers
When a managed run starts a cloud sandbox, Codewhale sends the repository content, instructions, environment values, and session data needed for that work to the execution provider and region identified before launch. The sandbox is ephemeral capacity acquired for that run and released afterward. Computer Use, when available, provides interactive control inside the live sandbox. Durable account, Agent, task, repository binding, artifact, and explicitly retained workspace state is stored separately. Provider-backed resources are not treated as deleted until the provider confirms deletion.
Retention and deletion
You can review export and deletion controls after signing in under Account, Data & privacy. Content is deleted according to the displayed retention and deletion process. Privacy-minimal security, audit, deletion, and financial receipts may be retained when necessary to prove an action, prevent abuse, or meet legal obligations. Provider-backed resources are not treated as deleted until the provider confirms deletion.
Questions and requests
Use Account, Data & privacy after signing in to request an export or deletion. For anything else, or if you cannot sign in, email [email protected].
Changes
This version replaces the policy effective August 21, 2026. It adds who we are, the service providers we use, how payments are handled, and how to contact us. We may update this policy as the product and its processors change. The effective date above identifies the version that applies.
Anonymous usage counting
Codewhale counts anonymous product usage by default. On this website that means plain totals of page views, documentation views, install-command copies, sign-in and sign-up link clicks, and error pages shown, sent with a random install identifier that rotates every 90 days to Codewhale’s own endpoint; Codewhale may pass those totals to PostHog as a processor. No page addresses, referrers, account, or content are included. In the Codewhale runtime and app the same rule covers aggregate version, platform, session, feature, and error counts, which never include conversations, code, prompts, files, repository or branch names, model content, or credentials. You can turn counting off at any time: for this browser on this page, in the app under Settings, or in the runtime with `codewhale config set telemetry false` or CODEWHALE_TELEMETRY=0. An opt-out is kept and never silently reversed, and presenting this notice does not record any acceptance on your behalf.
Usage counting on this site
This site counts page views, documentation views, install-command copies, sign-in and sign-up link clicks, and error pages shown as plain totals. Counting is on by default. Only those totals leave your browser — no page addresses, referrers, account, or content — sent to Codewhale's own endpoint, which may pass them to PostHog. A random install id, unrelated to you, rotates every 90 days.
Turning it off is kept in this browser and clears any queued counts and the install id. Nothing here records that you accepted anything.
In the Codewhale app, use Settings → Usage data. In the terminal runtime, run codewhale config set telemetry false or set CODEWHALE_TELEMETRY=0.