Privacy Policy

This policy explains what personal data CODEJ TECH (47.131.652/0001-29), Brazil processes when you use Thaydom, why we process it, who we share it with, and the rights you can exercise.

Last updated: 31 August 2026

1. Who we are

Thaydom is an AI execution platform operated by CODEJ TECH (47.131.652/0001-29), Brazil. For data protection purposes we act as the controller of account and billing data, and as a processor of the project content you submit to the platform.

Privacy and data requests: team@thaydom.com.

2. Data we collect

  • Account data: name, email address and authentication identifiers (including Google sign-in identifiers when you use it).
  • Billing data: subscription plan, credit balance, purchase and invoice history. Card details are entered directly with our payment processor and never reach our servers.
  • Project content: Business Context, Run Briefs, workflow runs, generated outputs, uploaded and generated assets.
  • Usage data: pages viewed, actions taken, credit consumption, error and audit logs.
  • Technical data: IP address, browser and device information, and cookies strictly necessary to keep you signed in.
  • Landing lead capture: email address and UTM parameters submitted through the updates form on the homepage. This is used only to contact you about product and pricing updates. It is not sold or shared with third parties.

3. Why we process it and on what legal basis

  • To provide the service and run the workflows you request — performance of a contract.
  • To take payments, prevent fraud and meet tax and accounting duties — contract and legal obligation.
  • To keep the platform secure, debug failures and improve reliability — legitimate interests.
  • To send service and transactional emails such as receipts, access and activation notices — contract.
  • To send optional product and pricing updates about Thaydom to addresses collected through the landing-page form — consent, withdrawable at any time by emailing the contact address below.

4. Who we share data with

We share only what each provider needs to perform its function, under a data processing agreement:

  • Payment processing: Stripe (payments, invoices, tax documentation, fraud checks).
  • Infrastructure, database, authentication and file storage: Supabase and our hosting provider.
  • AI model providers: prompts and project content required to generate the requested output are transmitted to the model provider used for that run.
  • Transactional email delivery.

We do not sell personal data and we do not share it for cross-context behavioural advertising.

5. AI processing

Content you submit is sent to AI model providers solely to produce the output you asked for. We do not use your project content to train our own models. Provider-side retention follows the provider's own policy; where the provider offers a no-training configuration for API traffic, we rely on it.

6. International transfers

Our providers operate in the United States and the European Union, so your data may be transferred outside your country. Transfers out of the EEA, the UK or Brazil rely on Standard Contractual Clauses or an equivalent safeguard offered by the provider.

7. Retention

  • Account and project data: kept while your account is active, then deleted or anonymised within 90 days of account deletion.
  • Billing and tax records: retained for the period required by law (typically 5–10 years).
  • Security and audit logs: up to 12 months.

8. Your rights

Depending on where you live you may request access, correction, deletion, a portable copy, restriction of or objection to processing, and withdrawal of consent. Under the CCPA/CPRA you may also request disclosure of the categories of data collected and opt out of sale or sharing — we do neither. You may complain to your local supervisory authority (in Brazil, the ANPD).

To exercise a right, or to ask us to remove your landing-lead record, contact team@thaydom.com. We answer within 30 days and will not discriminate against you for exercising a right. Removal requests are handled manually until an automated unsubscribe flow ships.

9. Security

Data is encrypted in transit and at rest, access is scoped per account through row-level database policies, and administrative access is restricted. No system is perfectly secure; we notify affected users and regulators of a qualifying breach without undue delay.

10. Children

Thaydom is not directed to anyone under 18 and we do not knowingly collect their data.

11. Changes

We will post any update on this page and, for material changes, notify account holders by email before the change takes effect.