Privacy Policy
Last updated: September 3, 2026
1. About this policy
code-config.com is a service operated by Lucky Fried Gains LLC ("we", "us", "our"). This Privacy Policy explains how Lucky Fried Gains LLC collects, uses, stores, and discloses personal information in connection with code-config.com, including this website, the web application at app.code-config.com, and the local client you run on your own computer.
Send privacy questions or requests to hello@code-config.com.
2. Information we collect
Depending on how you use code-config.com, we collect and process:
- your account email address and sign-in details. You sign in either with Google, through our authentication provider Supabase, or with a sign-in link we email to you;
- the toolkits, projects, computer records, settings, and other content you save in the service;
- when you connect a computer to your account, the IP address the request comes from and the location and network operator Cloudflare derives from it. We show these on the approval screen so you can recognize the request you are approving, and we use the IP address to apply rate limits that protect sign-in and computer enrollment from abuse;
- payment and subscription information. Paid plans are sold through Link, a merchant of record service operated by Stripe; your card details go to Stripe, and we receive your subscription status and the related account information Stripe reports to us;
- delivery details for the account and service email we send through Resend;
- network and request logs generated by Cloudflare, which hosts and fronts our services. Cloudflare also holds, in storage we control, the repository files we read to build the maps described in section 5 and the content you choose to share with the community;
- support messages and other communications you send us;
- product analytics information, described in section 6;
- community moderation records — a report you submit about published content, including the reason you pick and any details you write, together with the decisions our staff record about that content and who made them;
- a record of which version of our Terms and of this Privacy Policy your account accepted, and when; and
- the GitHub connection information described in section 5, where a workspace connects GitHub.
3. Local configuration and your computer
The local client writes tool configuration on the computer where you run it, and reads the toolkit state you have saved with us to do so; it reads the files in your project folders locally to do that work. What the client sends us is a record of each computer you connect, details about that computer and the version of the client on it, the folder paths where your projects live, and which toolkit a project uses. Sharing a toolkit with Community, described in section 5, sends the frozen mapping of which published GitHub repository items it uses, together with the toolkit's name and description; it never sends a file from your computer or a secret value.
Secret values stay in the secret store on your own computer. What code-config.com synchronizes is the names and bindings that point to them, so that a toolkit can say which credential a tool expects.
The toolkit records we hold contain the configuration you have saved. A toolkit you publish to Community is shown publicly: the name and handle of the workspace that published it, what the toolkit says about itself, what it is made of, the names of the credentials its tools ask for, and how many accounts have adopted it. Publishing a toolkit is an action you take deliberately.
4. How we use information
We use this information to operate the service, sync your declared toolkit state, support accounts and subscriptions, send transactional email, answer your requests, diagnose reliability problems, maintain security and prevent abuse, and understand how the product is used.
5. GitHub and repository features
A workspace can connect GitHub to use repository features. Connecting installs our GitHub App on a GitHub user account or organization that you choose.
- GitHub tells us which account the App was installed on and whether the installation covers all repositories on that account or a selected list of them. We keep that connection record together with who created it and when.
- The one-time user authorization we receive during setup is used to confirm that the installation belongs to the account you chose, and is revoked with GitHub once that check finishes. We hold the authorization information needed for the GitHub features your workspace enables.
- We ask GitHub for short-lived access as the operations you request need it. That access expires on GitHub's schedule.
- We read repository details and repository contents in order to build the map of components code-config.com supports, and we keep the resulting map.
- Sharing a toolkit with Community sends the frozen mapping of which published repository items it uses, and the toolkit's name and description; it never sends a file from your computer or a secret value.
We retain the installation record needed to maintain your GitHub connection until you disconnect it or GitHub reports it removed; a record of the connection and its removal is kept afterward.
6. Analytics
We collect product analytics on how our website and app are used, so we can see what people use and improve the product. Amplitude processes this for us. Where the law requires your consent, analytics starts only after you allow it. You can turn it off at any time, here or in the app's Privacy settings.
7. Cookies and local storage
code-config.com stores a small amount of information in your browser to remember your choices and to run the analytics described above: your analytics choice, how you like the site to look, which versions of our Terms and of this Privacy Policy your account has accepted, the workspace you are working in, and, while analytics is on, a value that lets analytics group the events from this browser. Some of it is written by this website and some by the web application at app.code-config.com. Your browser's own settings let you view, clear, or block it.
8. Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases.
| Purpose | Legal basis |
|---|---|
| Account creation and maintenance | Performance of a contract |
| Synchronization and product functionality | Performance of a contract |
| Subscriptions and payments | Performance of a contract and applicable legal obligations |
| Customer support | Performance of a contract and/or legitimate interests |
| Protecting code-config.com, users and systems | Legitimate interests |
| Reliability, debugging and service improvement | Legitimate interests where applicable |
| Analytics where consent is legally required | Consent |
| Accounting, tax and regulatory records | Legal obligation |
9. Service Providers and Other Recipients
We disclose or make information available to service providers and other third parties when necessary to operate code-config.com, process transactions, provide integrations, communicate with users, analyze product usage, maintain security, or comply with legal requirements. Depending on the activity, these companies may process information on our behalf or for purposes governed by their own terms and privacy obligations.
- Supabase — accounts, authentication, and our database;
- Google — sign-in;
- GitHub — repository features;
- Stripe — payments and merchant of record services, through Link;
- Resend — email;
- Cloudflare — hosting, storage, network and request logs; and
- Amplitude — product analytics.
We also disclose information where the law requires it, to protect our users, our systems, or our rights, and in connection with a merger, acquisition, financing, or other corporate transaction. We do not sell personal information.
10. Retention
We retain personal information for as long as reasonably necessary to provide code-config.com, maintain accounts and subscriptions, comply with legal and accounting requirements, resolve disputes, enforce agreements, maintain security, and complete our applicable backup and deletion processes. Different categories of information may be retained for different periods depending on these purposes.
For example, when a GitHub connection is disconnected we keep a record that the connection existed and that it was removed.
11. Deleting your account
When you request account deletion, we delete or de-identify information associated with your account as appropriate, subject to information we are permitted or required to retain for legal, security, accounting, dispute-resolution, backup, or other legitimate purposes.
Account deletion runs by request: email hello@code-config.com and we will handle it as described above.
12. Your rights
Depending on where you live, applicable law may give you rights regarding your personal information, including rights to request access, correction, deletion, restriction, objection, or portability, and to withdraw consent where processing is based on consent. You may submit a privacy request by contacting hello@code-config.com. We will respond as required by applicable law.
You can change your analytics choice at any time: use Cookie preferences in this site's footer, or open the Privacy section of account settings at app.code-config.com. Each site keeps its own choice.
The Privacy section of account settings also offers a download of your workspace configuration. For the other categories of personal information described in this policy, and for deletion, write to the address above and we will handle the request as described in this policy.
We may verify your identity before completing a request. You may also lodge a complaint with your local supervisory authority.
13. International transfers
Our service providers operate in the United States and other countries. Where information is transferred out of the EEA, the United Kingdom, or Switzerland, we rely on transfer mechanisms available under applicable law, which may include adequacy decisions, the EU-U.S. Data Privacy Framework, or standard contractual clauses, depending on the provider.
14. Changes to this policy
We may update this Privacy Policy as our services or legal obligations change. We will update the "Last updated" date when we do. If we materially change how we collect, use, or disclose personal information, we will provide additional notice where appropriate or required by law.
15. Contact
Lucky Fried Gains LLC · Email: hello@code-config.com