ccodexgram Legal home
Codexgram · Privacy

Privacy Policy

Effective date: October 10, 2026 · Last updated: October 10, 2026

Draft for review. Complete every bracketed field and confirm the actual vendor and retention settings before publication.

This Privacy Policy explains how [LEGAL ENTITY NAME] (“Codexgram,” “we,” “us,” or “our”) handles personal information when you use the Codexgram app and related services (“Service”). Our contact details are in Contact us.

1. Information we handle

Account information. When you register or sign in, you provide your name, email address, and password or choose an authentication method offered through Clerk. The app sends sign-up and sign-in credentials to Clerk; the application’s Convex database does not store your password. Clerk may receive identity information returned by the authentication method you choose.

Profile information. The app handles your username, display name, profile photo, and bio. Profile editing also saves website and location text in Clerk profile metadata. Location is information you type yourself; the code does not request GPS or derive your location from device sensors. The app’s public profile response includes username, display name, profile photo URL, bio, and follower/following/post counts. Website and location are not included in that Convex public-profile response.

Posts and activity. If you use the social features, we handle the photos or videos you select or capture, their media type and content type, any video duration, post captions, comments, follows, likes, and associated timestamps and counts. Videos may include audio. Photos and videos are uploaded to Convex storage; profile photos are sent to Clerk. The app code does not implement media analysis or end-to-end encryption. It does not demonstrate that metadata embedded in selected media, such as EXIF, is removed.

Device permissions and content selection. You can choose media through the device’s photo picker and use the camera to capture photos or videos. The app requests camera access when you choose the camera feature and declares photo, camera, and microphone permission purposes in its app configuration. You can manage device permissions through your operating system. We found no code that reads contacts, precise device location, motion data, or other sensor data.

Messages demo. The Messages screen currently shows sample conversations held in app memory for a session. This demo conversation content is not sent to Codexgram’s Convex backend by the messaging feature.

Service and diagnostic information. Clerk and Convex receive requests needed to authenticate you and provide the Service. They may process technical, security, or diagnostic information under their service configurations and agreements. The application source does not specify all provider-collected fields or their retention periods. We do not add an app-level analytics, advertising, or crash-reporting SDK in the dependencies/source reviewed.

2. How we use information

We use the information above to create and manage accounts; create and display profiles; store and show posts, stories, comments, likes, and follows to signed-in users; authenticate sessions; support account deletion; and operate and maintain the Service. Stories are returned in the active-story view for 24 hours. After that period the app stops returning them in that view; their records and files are not automatically deleted by the story-view code.

Where applicable law requires a legal basis for processing, our legal bases are: [CONFIRM AND DESCRIBE THE LEGAL BASIS FOR EACH PURPOSE IN EACH RELEVANT JURISDICTION].

3. Who receives information

The repository contains an internal demo-seed action that downloads fixed sample images from Unsplash into Convex storage. Those requests use sample image URLs rather than user-submitted data. Whether that action is enabled in production must be confirmed.

4. Analytics, advertising, cookies, and telemetry

No separate analytics, advertising, or crash-reporting SDK was found in the app’s checked-in dependencies and source. The app code does not request precise location or advertising identifiers. Clerk’s SDK can have its own telemetry behavior; Clerk’s current documentation describes SDK usage telemetry for development instances and says it does not include end-user information. This app’s provider does not explicitly configure telemetry off, so confirm behavior for the installed SDK and production instance. See Clerk’s telemetry documentation.

The project also has a web build. Whether web authentication uses cookies or other browser storage depends on the deployed Clerk and web configuration: [CONFIRM AND DESCRIBE THE WEB SESSION/COOKIE BEHAVIOR BEFORE PUBLICATION].

Sale, sharing for cross-context behavioral advertising, and any marketing use outside the code-reviewed app: [CONFIRM THE OPERATOR’S PRACTICES AND STATE THEM HERE; DO NOT LEAVE THIS PLACEHOLDER IN A PUBLISHED POLICY].

5. Retention and deletion

You can request account deletion in Settings. The app asks Clerk to delete your account and then starts background cleanup of the linked Convex profile, posts and media, stories and media, comments, likes, and follows. Cleanup runs asynchronously in batches. The code does not state how long completion takes or how long provider backups, security logs, or other provider-held records remain.

Stories stop appearing in the active-story query after 24 hours, but that query does not delete the story record or media file. Individual post and story deletion controls were not found. Confirm the actual retention schedule, deletion deadline, backup/log handling, and any legally required retention here: [RETENTION PERIODS BY DATA CATEGORY, INCLUDING BACKUPS/LOGS].

6. Security

Application backend functions require an authenticated Clerk identity for the profile, post, and story operations reviewed. Clerk’s Expo token-cache integration is configured in the app. Convex reports encryption at rest for data on its platform; the Codexgram source does not configure client-side content encryption or end-to-end encryption. Confirm the production deployment, access controls, provider contracts, and security measures before making any broader security claim. No method of storage or transmission can be represented as completely secure.

7. Your controls and privacy rights

You can edit profile fields and delete your account in the app, and you can control camera/photo access through your device settings. The app currently has no self-service data export, privacy-request, consent-management, or advertising opt-out screen. Its “Privacy” and “Privacy Policy” settings entries are placeholders rather than working controls.

Depending on where you live, privacy law may give you rights to access, correct, delete, export, restrict, or object to certain processing. To make a request, contact [PRIVACY REQUEST EMAIL]. We will handle requests as required by applicable law after confirming identity. Confirm that this contact is monitored and that the operator has a process to respond before publication.

8. Children and age

The Service’s intended audience and minimum age have not been established in the code. The app does not ask for or verify a user’s age. The intended minimum age is [MINIMUM AGE]; users below the age of majority are [NOT ELIGIBLE / ELIGIBLE ONLY WITH THE REQUIRED PARENT OR GUARDIAN CONSENT IF PERMITTED]. Confirm the target audience, age gate, and any child-specific notice/consent requirements in each market before launch. Do not publish this section with unresolved alternatives.

9. International processing

Authentication and application data are processed by the providers identified above. The repository does not identify the live data regions, provider subprocessors, or transfer arrangements. Confirm where the production Clerk and Convex deployments and their subprocessors process data, then describe the applicable international transfer safeguards here: [DATA REGIONS AND TRANSFER SAFEGUARDS, IF APPLICABLE].

10. Changes to this policy

We may update this policy when the Service or our practices change. We will update the effective date and provide notice through [CONFIRM NOTICE METHOD] for material changes. The code currently does not record privacy-policy acknowledgement or consent.

11. Contact us

[LEGAL ENTITY NAME]
Privacy email: [PRIVACY REQUEST EMAIL]
Postal address: [POSTAL ADDRESS]
Data protection officer or representative, if required: [NAME AND CONTACT OR “NOT APPOINTED / NOT REQUIRED”]