CapabilitiesUse CasesFeaturesPricingBlogDocsSupport
CodeCobra
CapabilitiesUse CasesFeaturesPricingBlogDocsSupport

Privacy Policy

Effective September 10, 2026 · Last updated September 10, 2026

CodeCobra connects to your live Odoo database and works inside it. That means you are trusting us with credentials and with your business data, so this page says plainly what we collect, how we protect it, who can see it, and how to get rid of it. No defined terms, no cross-references.

1. Who we are

CodeCobra is operated by Rooteam.com Inc, the data controller for the information described here.

Rooteam.com Inc
1449 37th Street, Suite 210
Brooklyn, NY 11204
United States
info@codecobra.ai

2. What we collect

Account information

Your name, business email address, organization name, and — if you sign in with Google or GitHub — the identity token that provider gives us. If you buy credits, we keep a record of the transaction.

Connection credentials

The Odoo API keys, passwords, database names and URLs you give us so CodeCobra can reach your system, plus any GitHub authorization you grant. We collect these for one reason: to do the work you ask for. See section 3.

Your work

Everything you do in a task — what you type, files you attach, code CodeCobra writes, data it reads back from your Odoo instance while answering a question, and the deliverables it produces such as spreadsheets, documents and dashboards.

Technical records

Usage and token counts for billing, error logs, IP address, browser and operating system. We use Google Analytics on our public website to understand which pages people find useful.

3. How we protect your connection credentials

This is the part that matters most, so here is what actually happens rather than a summary.

  • Encrypted before storage. Every credential is encrypted the moment you submit it, using AES-128-CBC with HMAC-SHA256 authentication. We never write a credential to our database in plaintext.
  • Separate keys per system. Odoo credentials, GitHub tokens and two-factor secrets are each encrypted under their own key, so exposure of one does not compromise the others. Keys can be rotated without downtime.
  • Never readable through our API. Once saved, a credential cannot be read back — not by you, not by our own interface. The API will only tell you whether a connection has a credential attached, never what it is.
  • Decrypted only in memory, only for your work. A credential is decrypted only when a task you started needs it, and only for the duration of that turn.
  • You set the ceiling. Every Odoo connection carries a Read, Write or Delete permission level that you choose. CodeCobra cannot exceed it — a task can be given less access than the connection allows, never more — and destructive operations prompt you for approval even at higher levels.

Two things worth being precise about. Encryption protects your credentials if the database is ever compromised — but we hold the keys, and we are not going to claim we couldn't decrypt them. Any hosted service that tells you otherwise is overselling. And a permission level governs what CodeCobra is allowed to do, not which records it can see; if you need it scoped to particular models or records, that is set on the Odoo side with groups and record rules.

4. Who can access your data

No one on our team reads your chats, your code or your data. There is no support console, no admin view and no internal tool anywhere in CodeCobra that displays customer content — we never built one. Support runs on system health and error telemetry. If a problem can only be diagnosed by looking at something specific, we ask you first, every time.

We store your conversations for one reason: so you can come back and read them.

The controls behind that:

  • Your credentials are encrypted at rest — Odoo passwords and API keys, GitHub tokens, two-factor secrets. Reading the database is not enough to reveal them.
  • Each task runs in its own isolated container with its own storage, destroyed when the task is deleted or goes idle.
  • Per-connection permission levels and approval prompts for destructive operations.
  • Access within an organization is governed by the roles and teams you configure, and organization owners can require two-factor authentication for all members.
  • Infrastructure credentials — the keys that operate our servers and database — are held by a small number of people and used to run the platform, not to look inside it.

5. AI providers, and model training

We never use your data to train models. Not your code, not your prompts, not your business data, not your credentials — not for our own models, and not for anyone else's.

Running CodeCobra means sending your prompts and the relevant context to third-party AI infrastructure providers that host the models. Every one of them is bound by a data processing agreement that prohibits using your data to train models. A current list of our subprocessors is available on request at info@codecobra.ai.

6. How long we keep things

  • Active work stays available as long as you are using it. Your chats, plans, code and deliverables are stored so you can come back to them.
  • Idle tasks are purged after 90 days. If a task has had no activity for 90 days, we delete its stored workspace and files. The task itself remains in your list and can be reopened from scratch.
  • Billing records are kept for as long as tax and accounting law requires.

7. Deleting your data

You can delete any task at any time. When you do, we destroy the chat and its messages, any files you attached, everything CodeCobra produced, the stored workspace, and the container the task ran in. That deletion is queued durably and completes even if our systems restart partway through.

The one thing that survives is the billing record: we keep the usage and cost figures for accounting, with the link to the deleted task removed. We cannot reconstruct your work from them.

You can also remove a stored credential at any time from the project it belongs to. To close your account entirely, email us and we will handle it.

8. Why we are allowed to process this

Under the GDPR, our legal bases are:

  • Performing our contract with you — running the service you signed up for, which is what covers your work, your credentials and your billing records.
  • Legitimate interests — keeping the service available and secure, preventing abuse, and understanding which parts of it people use.
  • Legal obligation — tax, accounting and lawful requests from authorities.

9. Your rights

Depending on where you live — the GDPR and the CCPA/CPRA both apply here — you can ask us to show you the personal data we hold about you, correct it, delete it, or send you a copy in a portable format. You can object to analytics and other non-essential processing. Email info@codecobra.ai and we will respond within the time the law allows. If you are unhappy with our answer, you can complain to your local data protection authority.

We do not sell your data. We never have, and there is no version of this business where we would.

10. Payments

Card payments are handled by Stripe. We never see or store your full card number — Stripe holds it and gives us a token plus the last four digits so you can tell your cards apart.

11. Where your data lives

Our infrastructure runs in the United States. If you are in the EEA or the UK, using CodeCobra means your data is transferred to and processed in the US. Where a transfer needs a legal mechanism, we rely on the European Commission's Standard Contractual Clauses. We can execute a Data Processing Agreement with you on request.

12. Cookies and local storage

We use browser storage to keep you signed in and to remember interface preferences such as your theme. Our public website uses Google Analytics; you can block it with any standard browser setting or extension without losing access to anything.

13. Changes to this policy

If we change something that matters, we will update the date at the top of this page and tell account holders by email. We will not quietly broaden what we do with your data.

14. Contact us

For privacy questions, to exercise any of the rights above, to request a Data Processing Agreement, or to report a security issue, email info@codecobra.ai, or write to the address in section 1.

CodeCobra
PricingPrivacyTermsDocumentationAPIBlogSupport
© 2026 CodeCobra. All rights reserved.