What happens to your code
The short answer
CodeMesh reads the repositories you connect and stores their parsed structure and their source text in a graph scoped to your organisation. Your machine and your coding agent never hold a database credential: every query is scoped by the credential itself, executed read-only, and only the result crosses back. What follows is the whole list, including the parts that are awkward.
Read on your machine
- Source code and file structure
- Relationships between files
- Commit history, including author names and email addresses
- Commit messages
- Uncommitted work: working tree, staged changes, stashes
- Git config and remote URLs, credentials stripped
- The repository's path on the machine that synced it
Where it lands
The parsed structure and the source text, scoped to your organisation.
On Free, Basic and Team your graph shares an instance with other customers, and the separation between them is enforced by CodeMesh rather than by separate infrastructure. A dedicated instance is available on request.
Accounts, organisations, memberships, sessions, billing references, audit events and tool-call logs.
Also recorded about your use
- Your IP address and browser user-agent, against each sign-in, tool call and audit event
- A preview of what you asked our tools to do: search terms, questions, file paths, graph queries
- Audit events and tool-call logs are retained indefinitely today. A retention period is being defined.
Never happens
- No analytics, advertising, session recording or third-party tracker anywhere in the product
- Your code is never used to train machine-learning models
- Personal information is never sold
- Card details are entered with the payment provider and never reach CodeMesh
- No marketing email from this product
The four answers people actually want
Does my uncommitted work get indexed?
Are other people's names and emails in there?
Is my graph on its own database?
How long do you keep the logs of what I asked?
What you control from the panel
Which repositories are connected is the only decision that really matters, and it is made in the panel rather than buried in a settings page. A repository that is not connected is not read, not parsed and not stored.
Disconnecting an agent revokes its tokens immediately rather than at their next expiry, and the authorisation screen lists the scopes an app is asking for before you grant them. The read scope covers structural queries across your graph, which includes the git metadata described above, so it is worth reading rather than clicking through.
What never happens
No analytics, advertising, session-recording or tracking technology exists anywhere in the product. There is no Google Analytics, no advertising pixel and no third-party tracker. Fonts are served from our own servers rather than a font CDN, so loading a page tells no third party that you visited. Your code is never used to train machine-learning models, personal information is never sold, and card details are entered with the payment provider and never reach CodeMesh.
Two cookies exist and both are strictly necessary: codemesh_session, which keeps you signed in and is not readable by JavaScript, and codemesh_consent_csrf, a ten-minute security token protecting the OAuth authorisation screen.
The formal version of all of this, including who else processes your data and how to exercise your rights, is the privacy policy.
See how the syncing actually works
The mechanism behind every line on this page, in six beats.