Last updated: August 12, 2026
This policy explains how Codelit.io collects and uses information when you use the website, AI architecture tools, integrations, saved sessions, sharing features, and Stripe-powered billing.
Codelit for Mac can be used locally without an account. Sensitive workspace records are encrypted in the app's local database. User-selected folder permissions and local model files stay on the Mac. The app does not send local prompts, files, run events, or receipts to Codelit when you use only the built-in on-device model.
If you choose to connect an existing Codelit account, pairing sends a challenge, app version, and build channel. Codelit collects the linked user ID for account functionality. If you separately approve a cloud handoff, Codelit also collects the selected artifact and run settings as Other User Content so it can provide the requested hosted workflow. The App Store build does not track users or include advertising.
When you use free or Pro AI models without your own API key, prompts, chat history, and related architecture context may be routed through Codelit servers and sent to AI providers or model-routing providers so they can generate a response. These currently include OpenRouter and, as a fallback for free generation when the primary provider is unavailable, Kilo Gateway (api.kilo.ai). When you use your own API key from the BYOK menu, the key is stored in your browser and requests are intended to go directly from your browser to the selected AI provider.
Codelit does not use your prompts, architectures, saved sessions, or shared diagrams to train Codelit-owned AI models. Third-party AI providers may process submitted content under their own terms and privacy policies.
Keys used only for in-tab or Local Lite runs can remain in browser storage and can be cleared from Settings. When you explicitly save a key for hosted automation, Codelit stores it in the encrypted server vault so the selected provider can be called while your tab is closed. OAuth and connected-app tokens are also encrypted server-side when the integration requires hosted refresh or execution. Raw secrets are not returned to the interface after saving.
LocalStorage is controlled by your browser and device. Avoid entering API keys or connecting private workspaces on shared or untrusted devices.
Pro, Team, and Execution Pack billing is handled by Stripe. Stripe receives the information needed to create checkout sessions, manage subscriptions, process payments, issue invoices, and provide the customer portal. Codelit stores subscription status, entitlement version, Stripe identifiers, idempotent pack purchase records, prepaid balances, reservations, and aggregate model and browser usage so the app can enforce limits without storing payment card numbers.
Architectures and boards you explicitly share are stored with a unique public link. Anyone with that link may view the shared content. Do not share content that contains secrets, credentials, private business information, or data you are not authorized to disclose.
We use service providers to operate Codelit, including Firebase/Google for authentication, database, hosting, and analytics storage; Stripe for billing; Vercel for hosting, deployment, and anonymous public-page Web Analytics; AI providers for generation; and connected third-party platforms when you authorize an integration. Vercel Web Analytics uses an anonymous daily request hash rather than an advertising cookie. These providers process data only as needed to provide their services to us or to you.
Codelit uses browser storage for app settings, model choices, API keys, integration tokens, usage counters, and session behavior. A per-tab sampling choice may be kept in session storage to limit anonymous performance reporting. Vercel Web Analytics is cookieless. We do not currently use third-party advertising cookies. Authentication and payment providers may use cookies or similar technologies under their own policies.
We keep account, usage, billing, and saved content for as long as needed to provide the service, comply with legal obligations, resolve disputes, prevent abuse, and maintain business records. You can delete saved sessions and shared content where the product provides controls. You can request deletion of your account and associated Codelit data from Settings or by emailing us.
Delete account & data removes account-linked Codelit analytics. Identifier-free performance samples and anonymous aggregate Web Analytics cannot be resolved back to an account. Some information may remain in backups, security logs, billing records, or records we must keep for legal, tax, fraud-prevention, or dispute-resolution purposes.
We use reasonable technical and organizational safeguards, including provider-managed authentication and payment processing. No internet service is perfectly secure. You are responsible for protecting your account, browser, devices, API keys, and connected workspaces.
Codelit is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Codelit is operated from the United States. If you use the service from another country, your information may be processed in the United States or other locations where our providers operate.
We may update this Privacy Policy as the service changes. The updated version will be posted here with a new "Last updated" date.
Questions or privacy requests? Email mo@codelit.io.