1. Local-First Core Commitment
CodeBunker Labs ("CodeBunker", "we", "us", or "our") builds a unified developer command station, integrated software engineering utilities, and workspace management software engineered around a Local-First, Zero-Trust security architecture.
Unlike traditional cloud-dependent SaaS platforms that ingest your source code, project files, and environment configurations into remote cloud infrastructure, CodeBunker executes all local workflows, utilities, and project operations exclusively inside your local machine or workstation environment.
Your local project files, directory paths, source code, secrets, and configurations are never transmitted to CodeBunker servers, never shared with third parties, and never ingested into AI training sets without your explicit consent.
2. What We Collect
To maintain our service, issue software licenses, and facilitate authorized distribution, we collect only the minimum necessary administrative and technical information:
- Account Identifiers: Name, professional email address, and optional organizational affiliation provided during registration or support inquiries.
- Billing & Purchase Records: When purchasing licenses through authorized application stores or certified payment platforms, transactions are processed directly by those distributors. We do not collect, process, or store credit card numbers, bank account details, or payment card data. We retain only purchase confirmation records (such as license status, renewal dates, and transaction references) necessary to validate access.
- License Activation Signals: Machine fingerprint hashes (non-reversible cryptographic hashes generated from hardware identifiers), client version numbers, license key state, and activation timestamps required to enforce seat limits.
- Website Diagnostics: IP address, browser user-agent, operating system platform, and standard server log metrics collected when accessing
codebunker.devfor DDoS prevention and traffic routing.
3. What We Never Collect (Zero Code Leaks)
We maintain an uncompromising technical barrier between administrative metadata and your engineering artifacts. We strictly do not collect:
No local project files, source code lines, comments, or folder trees are uploaded.
API keys, passwords, certificates, and .env contents remain exclusively in your local vault.
Keystrokes, undo buffers, and active editor scratchpads are never logged or mirrored.
Code analyzed by CodeBunker is never used to train or fine-tune public or commercial LLMs.
4. Selective Local Vault & File System Architecture
CodeBunker does not store or replicate entire projects inside a vault. The Vault feature functions strictly as a local, user-initiated store for specific items you consciously choose to preserve:
- Selective & User-Initiated Storage: The vault only stores individual code snippets, specific text files (with a strict 2MB maximum size limit and no binary file support), AI plans/artifacts, or technical notes that you explicitly choose to save from the VS Code extension or create manually within the desktop app.
- Local-Only Storage on Your Machine (%AppData%): Vault entries and user preferences reside exclusively within CodeBunker's local database on your hard drive (standard Windows directories such as
%AppData%), remaining under your physical possession with zero cloud sync. - Your Project Folders Remain Untouched: CodeBunker does not clone your repositories or maintain background mirror copies of your whole projects. Your project directories remain solely in their existing locations on your file system.
5. Zero Telemetry, OS Permissions & Network Usage
CodeBunker is engineered from the ground up on an uncompromising privacy-by-design desktop architecture. We do not collect background usage analytics, monitor your workflows, or transmit unexpected outbound traffic:
- Windows Operating System Permissions: CodeBunker does not request, access, or utilize sensitive operating system sensors or device capabilities, including webcam, microphone, geographic location (GPS), contacts, calendar, or photo libraries. The application operates solely with standard operating system file system privileges over folders you explicitly choose to open.
- Zero Telemetry & Third-Party SDKs: Neither the CodeBunker Station nor our official extensions contain telemetry trackers (such as Google Analytics, Mixpanel, or Segment), remote crash diagnostic SDKs (such as Sentry or Crashlytics), or third-party advertising frameworks.
- Local-Only Diagnostic Logs: Any operational status messages, process logs, or error exceptions generated during execution are recorded exclusively in plain-text log files stored on your local disk for your own diagnostic inspection. They are never automatically transmitted to remote servers.
- Outbound Network Connections: The CodeBunker desktop application initiates external network connections strictly for the following transparent purposes:
- License Validation: Transmitting non-reversible cryptographic machine hashes and license tokens to verify entitlement status.
- Software Updates: Optionally checking our release distribution endpoints to inform you when a new software version is available.
- User-Directed Actions: Making direct outbound calls solely when you explicitly instruct the software to communicate with third-party endpoints (e.g., using your own user-provided API keys or connecting to external authorized developer services).
6. Accounts & Billing Processing
Software licenses and subscriptions are purchased and fulfilled through authorized application stores and certified payment distribution platforms. We do not collect, process, or store credit card numbers, bank accounts, or financial payment credentials on our infrastructure. When you purchase a license:
- Payment details are encrypted and handled directly by the respective authorized store or payment platform under their strict security certifications (such as PCI-DSS Level 1).
- We only receive and retain license entitlement status, renewal dates, and general transaction confirmation identifiers needed to grant access to the software.
- You may request update or deletion of your account contact information at any time by contacting our support team.
7. Third-Party Sub-processors
We partner with established infrastructure and distribution providers that adhere to GDPR, SOC 2 Type II, and ISO 27001 certifications:
| Sub-processor / Channel | Purpose | Location | Safeguard Mechanism |
|---|---|---|---|
| Authorized App Stores & Certified Gateways | License purchasing & transaction fulfillment | Global | PCI-DSS Level 1, Standard Contractual Clauses (SCC) |
| Cloudflare, Inc. | Edge CDN, DNS, and DDoS defense | USA / Global | SOC 2 Type II, ISO 27001, Data Processing Addendum |
| Managed Cloud Infrastructure | License verification & account authentication API | USA / EU | SOC 2 Type II, ISO 27001, EU Standard Contractual Clauses |
8. International Data Rights (GDPR & CCPA)
Depending on your location, you hold statutory rights under data protection laws such as the European Union General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA):
- Right to Access: You can request a copy of the personal account metadata we hold about you.
- Right to Rectification: You may update or correct inaccurate profile or contact information.
- Right to Erasure ("Right to be Forgotten"): You may request the permanent deletion of your account and licensing associations.
- Right to Restriction & Objection: You may restrict or object to the processing of diagnostics data at any moment.
- Non-Discrimination: We do not sell personal data, and exercising your statutory privacy rights will never result in degraded software performance or arbitrary price increases.
To exercise any of these rights, email us at privacy@codebunker.dev. We respond to all verified requests within thirty (30) business days.
9. Data Retention & Deletion
We retain account records only as long as necessary to fulfill active software entitlements, comply with statutory legal obligations, and protect against fraudulent chargebacks. When you close your CodeBunker account:
- Your account profile, active license seats, and personal contact info are purged from active production databases within 30 days.
- Encrypted database backups rotate out and are permanently expunged according to our standard retention lifecycle.
- Local cache files, settings, and workspace data on your workstation remain in your physical possession and can be deleted locally by removing the application data directory on your computer.
10. Security Incident Response
We take the security of our authentication and licensing systems with the highest gravity. In the unlikely event of a security compromise impacting user account credentials or licensing metadata:
- We will notify affected customers via email without undue delay and within seventy-two (72) hours of confirming a breach, in accordance with GDPR Article 33.
- We will publish an incident post-mortem with actionable remediation guidance.
- If you discover a potential vulnerability in CodeBunker software or infrastructure, we encourage responsible disclosure via security@codebunker.dev.
11. Revisions & Contact Information
We may revise this Privacy Policy periodically to reflect technological advancements, new product capabilities, or evolving legal frameworks. If changes are material, we will provide prominent notice through our website, application release notes, or direct email communication prior to the change taking effect.
Questions or Concerns?
For inquiries regarding this Privacy Policy, your personal data, or our local-first security architecture, please contact our data protection team: