Privacy Policy
Last updated 28 August 2026
CodeMesh turns a codebase into a queryable graph. To do that it reads your repositories, which means it necessarily processes information about people — including people who never signed up for CodeMesh. This policy says exactly what that is, where it goes, and who can reach it.
The same policy, as a diagram
Everything below in one picture: what is read, what crosses the boundary and where it lands, what else is recorded, and what never happens. The practical version of this page, written for developers deciding whether to install CodeMesh, is the data policy.
Read on your machine
- Source code and file structure
- Relationships between files
- Commit history, including author names and email addresses
- Commit messages
- Uncommitted work: working tree, staged changes, stashes
- Git config and remote URLs, credentials stripped
- The repository's path on the machine that synced it
Where it lands
The parsed structure and the source text, scoped to your organisation.
On Free, Basic and Team your graph shares an instance with other customers, and the separation between them is enforced by CodeMesh rather than by separate infrastructure. A dedicated instance is available on request.
Accounts, organisations, memberships, sessions, billing references, audit events and tool-call logs.
Also recorded about your use
- Your IP address and browser user-agent, against each sign-in, tool call and audit event
- A preview of what you asked our tools to do: search terms, questions, file paths, graph queries
- Audit events and tool-call logs are retained indefinitely today. A retention period is being defined.
Never happens
- No analytics, advertising, session recording or third-party tracker anywhere in the product
- Your code is never used to train machine-learning models
- Personal information is never sold
- Card details are entered with the payment provider and never reach CodeMesh
- No marketing email from this product
1. Information you give us
When you create an account we collect:
- Your name and email address.
- Your password, stored only as an argon2id hash. We never hold the password itself.
- Your organisation name, if you provide one.
- Your chosen plan, and — for a paid plan — a payment-provider preference. When you do not state one we infer it from the country in your request headers or the timezone your browser reports, so that we show the right provider and currency.
2. Information we collect automatically
- Your IP address and browser user-agent string, recorded against each sign-in session, each authenticated tool call, each audit event, and each OAuth client you register.
- What you asked our tools to do. Each tool call is logged with a preview of its arguments — the search terms, questions, file paths and graph queries you sent.
3. What we store when we index a repository
This is the section most people are looking for, so it is deliberately specific. When you connect a repository, CodeMesh reads and stores in your graph:
- Source code, file structure and the relationships between files.
- Commit history, including the name and email address of every commit author. Those people are frequently not CodeMesh users. They may be former colleagues, contractors, or open-source contributors who have no relationship with us and no opportunity to agree to this policy. If a name and email appear in your git history, they are stored in your graph and can be queried.
- Commit messages.
- Uncommitted work — the contents of your working tree and staged changes, and any stashes, when the editor daemon syncs them.
- Git configuration values and remote repository URLs, with credentials stripped.
- Repository identifiers, including the remote URL and the absolute filesystem path the repository occupies on the machine that synced it.
If your repositories contain personal data of third parties in any other form — customer records in a fixture, an email address in a comment, a name in a test file — CodeMesh will index it, because it indexes your code as written. You decide which repositories to connect and you remain responsible for what they contain.
4. Who can query that data
- Members of your organisation, subject to their role.
- Any third-party application you authorise. When you approve an OAuth client, or connect an agent over MCP, the scopes you grant determine what it can read. The read scope covers structural queries across your graph — which includes the commit author and git metadata described in section 3. Review what you are granting on the authorisation screen, and revoke grants you no longer use.
Every member of your organisation can also see an activity view covering the last 90 days. That view shows, for other members of your organisation, their email address, IP address, browser user-agent and a preview of the queries and questions they sent. If that is not appropriate for your team, do not connect repositories you are not willing to share at that level.
5. Where your data is held, and who else processes it
- Our own database holds accounts, organisations, memberships, sessions, billing references, audit events and tool-call logs.
- CognoDB holds your graph — the indexed code and git metadata from section 3. We provision an instance for your organisation through CognoDB's managed service.
- On the Free, Basic and Team plans your graph shares a database instance with other customers. Separation between customers is enforced by CodeMesh, not by separate infrastructure. A dedicated instance is available on request.
- A separate write service receives the code we index in order to write it into your graph.
- Payment providers. Card details are entered directly with Stripe or Razorpay and never reach CodeMesh; we store only a provider reference, the amount and the status. Your name and email address are shared with the provider so it can bill you. On the Razorpay path, Razorpay's checkout script loads in the page and receives your name and email to prefill the form.
- A currency-rate service is called to display prices in local currency. It receives no information about you.
6. Cookies and browser storage
CodeMesh runs no analytics, advertising, session-recording or tracking technology of any kind. There is no Google Analytics, no advertising pixel and no third-party tracker anywhere in the product. Fonts are served from our own servers rather than a font CDN, so loading a page tells no third party that you visited.
Two cookies exist, both strictly necessary and neither used to track you:
codemesh_session— keeps you signed in. Not readable by JavaScript.codemesh_consent_csrf— a ten-minute security token that protects the OAuth authorisation screen. Despite its name it is unrelated to cookie consent.
Nothing non-essential is set today, so there is nothing to opt out of yet. We still ask, on your first visit, and record your answer — so that the moment anything non-essential is added it is already gated behind a choice you made rather than switched on by default. You can change that answer at any time: .
7. What we do not do
- We do not sell personal information.
- We do not use your code to train machine-learning models.
- We do not send you marketing email from this product.
8. Retention
Expired sign-in sessions, expired authorisation codes and short-lived rate-limit counters are deleted automatically. Your graph persists for as long as your repository stays connected.
Audit events and tool-call logs — which contain IP addresses, user-agent strings and query previews — are currently retained indefinitely. We are defining a retention period for them and will state it here.
9. Your rights, and how to actually exercise them
Depending on where you live you may have rights to access, correct, delete, port, or object to our processing of your personal data, and to complain to a supervisory authority.
To exercise any of them, email hello@codemesh.com. We handle these requests manually today; there is no self-service deletion or export in the product, and we would rather say so than point you at a button that does not exist. That includes deleting an account, deleting an organisation, and removing an indexed repository and its graph.
If you are a commit author who has never used CodeMesh and your name or email appears in a customer's graph because of section 3, write to the same address. Note that the repository belongs to our customer, so in most cases we will need to act on their instruction.
10. Changes to this policy
We will update the date at the top when this changes. If a change is significant we will tell account holders directly.
11. Contact
The controlling legal entity, its registered address and the governing law for this policy are being confirmed and will be stated here.