Privacy Policy
Last updated: 3 August 2026
CodeOBF ("we", "us") operates a JavaScript code-protection service at codeobf.com. This policy explains what we collect, why, and your choices. The short version: we do not store or log the source code you submit — it is compiled in memory and the result is returned in the same request. We store only the minimum account data needed to sign you in and bill you.
1. Your code is not stored
When you obfuscate code — in the playground or via the API — your source and the protected output are processed in memory and returned in the same HTTP response. They are never written to disk, persisted to a database, or logged. We never execute your code; we only parse and compile it.
2. What we do collect
- Account: your email address, sign-in sessions, and your subscription plan and API key. This is stored so you can sign in and access paid features.
- Payments: handled by Stripe. We do not receive or store your card number. We store a Stripe customer identifier to link your subscription to your account. See Stripe's privacy policy.
- Operational logs: standard request metadata (IP address, timestamp) used transiently for rate-limiting and abuse prevention. These do not contain your source code.
3. Why we collect it
To authenticate you, provide the service you paid for, process payments, prevent abuse, and meet legal obligations. We do not sell your data or use it for advertising.
4. Cookies
We set one first-party, HTTP-only session cookie after you sign in. It is used solely to keep you logged in. We do not use third-party tracking or advertising cookies.
5. Sharing
We share data only with service providers that make the product work — currently Stripe (payments) and our email provider (sign-in links). We may disclose information if required by law.
6. Retention
We keep account data while your account is active. You may request deletion at any time (see contact below); we will delete your account data except where we must retain records for legal or accounting reasons.
7. Your rights
Depending on your jurisdiction (e.g. GDPR/UK GDPR, CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Contact us to exercise them.
8. Security
Passwords are not used — sign-in is via one-time email links. Sessions are signed and HTTP-only. Secrets are held server-side only. No system is perfectly secure, but we apply reasonable safeguards.
9. Changes
We will update this page and the "last updated" date when this policy changes.
10. Contact
Questions or requests: privacy@codeobf.com.
This is a good-faith draft, not legal advice. Have it reviewed by qualified counsel and adapted to your jurisdiction and actual data practices before you rely on it.