Legal Privacy Policy
Privacy Policy
This policy explains what personal data we collect when you use Codasc and the apps published under it, why we collect it, who we share it with, and the rights you have over it.
1. Who we are
Codasc is operated by CODASC SOFTWARE PUBLISHING, a sole proprietorship (“Codasc”, “we”, “us”). We are the data controller responsible for the personal data described here. For any privacy question or to exercise your rights, contact us at [email protected].
This policy covers the Codasc website (codasc.dev) and the apps we publish under one account — Workout, Bike Fit, Outage Watch and BIR DAT — together with Codasc Assistant, the AI helper available inside them. Some apps collect additional data specific to what they do, described in Section 3.
2. Data we collect for every account
- Account details — your name, email address and a securely hashed password. We never store your password in readable form.
- Sign-in with Google (optional) — if you choose Google sign-in, we receive your name, email address and profile picture from Google. We do not receive your Google password.
- Authentication & security records — a session token (stored in a cookie) that keeps you signed in, plus security event logs (sign-ups, log-ins, password resets) used to protect your account and prevent abuse.
- Last-access dates — the date (never the time) you were last active on Codasc, and the date you last opened each app. We keep only the most recent date for each, not a history, and we use it to understand which accounts and apps are still in use. It is deleted with your account.
- Usage analytics — we use Google Analytics across the Codasc website and the signed-in app suite, which receives your IP address, browser user-agent, the pages you visit and the milestones you reach (such as creating an account or opening an app). It is not given your name, email address or account identifier (see our Cookie Policy).
- Advertising measurement — on the Studio Services pages only (
app.codasc.dev/studio), where our Facebook and Instagram ads link, we measure which ads lead to an enquiry using the Meta pixel and Meta’s Conversions API. If you send the enquiry form, Meta is given your email address and mobile number hashed (scrambled with SHA-256, so it cannot be read back), plus the page address, your IP address and user-agent — never your name or what you wrote. This does not run anywhere else on Codasc (see our Cookie Policy). - Support and contact messages — if you email us or use the contact form, we keep your message, your email address, any phone number you supply, and our reply.
Our own servers do not log your IP address against your account. Server request logs record the internal address of our proxy rather than yours.
3. Data collected by specific apps
Workout
Exercises, routines and the workout log entries you create (sets, reps, weight, duration, notes and similar fields). This is fitness data you choose to record; it stays in your account.
Bike Fit
Body measurements you enter (such as height, inseam, torso, arm and shoulder lengths), your stated flexibility, and the bike-fit results generated from them. These are estimates for your own use — see our Disclaimers.
Outage Watch
- Subscriptions — the areas, sources and keywords you choose to follow. Because these are usually places that matter to you (your barangay, feeder or street), treat them as an indication of where you live or work.
- Telegram link — when you connect Telegram, we store your Telegram chat ID (and public handle/name, if any) so we can deliver alerts to you.
- Phone number (SMS) — if you opt into SMS alerts, your phone number is stored encrypted at rest and decrypted only at the moment a message is sent. We also store a short-lived verification code while you confirm the number.
- Delivery history — a record of the alerts we sent you, on which channel, whether they succeeded, and the SMS credits they used. This is how we can show you what you received and account for credits correctly.
- Credits and passes — your SMS credit balance and the ledger of credits added or spent, plus the status of any trial or pass.
- Outage advisories shown in the app are gathered from publicly-posted sources and are not personal data about you.
BIR DAT
BIR DAT prepares Philippine BIR alphalist and DAT submissions. It is deliberately built so that your tax data stays on your own device.
- Held in your browser, not on our servers — the taxpayer profile you enter (TIN, RDO and branch codes, registered name and address) and the employee rows you work on (names, TINs, employment dates and status, and compensation, contribution and withholding figures) are stored locally in your browser. Importing a CSV, generating a DAT file and printing a Form 2316 all happen on your device. None of this is transmitted to us.
- Optional encrypted cloud backup — if you turn on backup, your workspace is encrypted in your browser with a passphrase only you know, and we store only the resulting unreadable blob. We cannot decrypt it, read it, or help you recover it if you lose the passphrase. You can delete it at any time from within the app.
- What we do see — your account identity, and non-content facts such as your plan tier and how many rows a generation contained.
Data about other people. The employee records you handle in BIR DAT are personal data about your employees or clients, not about you. For that data you are the controller and we are not — it never reaches us in readable form. You are responsible for having a lawful basis to process it and for meeting your own obligations under the Data Privacy Act toward those individuals.
Codasc Assistant
Codasc Assistant is an AI helper you can use inside our apps. If you use it:
- Your conversations — the messages you send, the replies, a running summary of the conversation, and any facts you explicitly ask it to remember. These are stored encrypted at rest. Conversation titles are stored unencrypted.
- Your app data, when relevant — when you ask about one of your apps, the Assistant reads the data it needs to answer. For Workout that includes your exercises, routines and training statistics; for Bike Fit it includes your body measurements and flexibility.
- Sent to OpenAI — to generate a reply, your messages, remembered facts and any app data retrieved as above are transmitted to OpenAI, which processes them on our behalf. We do not send your name or email address. If you would rather this data not leave our servers, do not use the Assistant — every app is fully usable without it.
- Credits — a ledger of Assistant credits you have bought and used.
4. Why we use your data (and our legal bases)
- To create and operate your account and provide the app features you use (performance of our contract with you).
- To keep accounts secure and prevent fraud and abuse (our legitimate interests).
- To send you the alerts, verification and service emails you ask for (consent / contract).
- To answer your questions in Codasc Assistant, which involves sending your messages and the relevant app data to our AI provider (consent — you choose to use it; see Section 3).
- To process payments for paid features (contract — see Section 6).
- To understand and improve how our products are used, in aggregate (legitimate interests / consent for analytics cookies).
- To comply with our legal obligations.
5. When we share data
We do notsell your personal data. We share it only with the service providers (“sub-processors”) we rely on to run the service, and only as needed for them to perform their function on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| PayMongo | Processing payments for paid features. You enter card or e-wallet details on PayMongo’s own hosted checkout — we never see or store them. We send only an internal account reference, the item and the amount. | Philippines |
| Semaphore | Delivering Outage Watch SMS (verification codes, outage alerts, credit and expiry notices). Receives your mobile number and the message text. | Philippines |
| Telegram (Bot API) | Delivering Outage Watch alerts to the chat you link. Receives your Telegram chat ID and the message text. | Global |
| OpenAI | Two separate uses: (a) powering Codasc Assistant — receives your messages and, when you ask about an app, the relevant data from it; (b) reading text from public outage-advisory images for Outage Watch — no account data. | United States |
| Google (Sign-in / OAuth) | Optional social sign-in; receives your name, email and avatar only when you choose Google. | United States / global |
| Google (Analytics 4) | Aggregate usage analytics for the codasc.dev website. Receives your IP address, browser user-agent and the pages you visit. | United States / global |
| Meta (Facebook) — ads measurement | Measuring which of our Facebook and Instagram ads lead to an enquiry, on the Studio Services pages only (app.codasc.dev/studio). Receives the page address, your IP address and user-agent, and — only if you send the intake form, after ticking the consent box — your email and mobile number hashed with SHA-256. Never your name or what you wrote, and nothing at all elsewhere on Codasc. | United States / global |
| Google Fonts | Serving the typefaces used inside the apps. Your browser requests these directly, which discloses your IP address and user-agent to Google. | United States / global |
| Mailtrap | Sending transactional email (verification, password reset, notifications) and delivering contact-form messages. Receives the recipient address and the message content. | European Union / global |
| Apify | Collecting publicly-posted outage advisories that power Outage Watch (no personal data sent). | United States / EU |
| Contabo | Hosting the servers and database that run Codasc and its apps. | European Union (France) |
We may also disclose data where required by law, to enforce our terms, or to protect the rights, safety and property of our users or others. If the business is ever transferred, your data may transfer with it under this policy.
6. Payments
Paid features are sold through PayMongo, our payment provider. You enter your card or e-wallet details on PayMongo’s own hosted checkout pages — those details never pass through our servers, and we never receive or store your card number, expiry or cardholder name. When we create a checkout we send PayMongo only an internal account reference, the item being bought and the amount; we do not send your name or email.
We keep a record of the transaction (amount, currency, status and payment references) for accounting, support and dispute resolution, together with the raw notification PayMongo sends us confirming the payment.
7. How long we keep data
We keep your account data for as long as your account is active. We are a small operation and we will be straightforward with you about what this means today:
- Deleting your account is currently a manual process. There is no self-service delete button yet. Email [email protected] and we will delete your account and the data in your apps by hand, within the time the law allows.
- Some records are kept deliberately, even after an account goes away: payment and credit-ledger entries (financial history we must be able to account for), security and audit events, notices we have already sent you, and the record binding a Telegram chat to the account that first claimed it — that last one exists to stop the same free trial being claimed repeatedly, and it must outlive the link itself to work at all.
- Operational records expire automatically. A daily job prunes them: delivered emails are removed after 7 days (so password-reset links do not linger), security-log entries have your email address stripped out after 30 days and the entries themselves are deleted after a year, expired sessions and used one-time links go after 7–30 days, and stored payment notifications are emptied of their contents after 180 days.
- Outage Watch delivery history has your phone number and chat ID removed after 90 days — leaving only what was sent, when, and whether it worked — and the record is deleted entirely after a year.
- Backups. We take a nightly backup of the database and keep only 7 days of them. This means that after we delete something at your request, a copy can persist in backups for up to 7 days before ageing out. We do not restore backups in order to recover data you asked us to erase.
8. Your rights
Under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) — and, where they apply to you, equivalent laws such as the EU/UK GDPR — you have the right to:
- access the personal data we hold about you and ask for a copy;
- correct data that is inaccurate or out of date;
- erase your data (“right to be forgotten”), subject to the retention exceptions above;
- object to or restrict certain processing, and withdraw consent at any time;
- receive your data in a portable, machine-readable form; and
- lodge a complaint with a data-protection authority — in the Philippines, the National Privacy Commission (privacy.gov.ph).
To exercise any of these, email [email protected]. We may need to verify your identity first, and we respond within the time required by law. We currently handle access, export and erasure requests manually rather than through a button in the app — the outcome is the same, it just goes through us. Note the retention exceptions in Section 7: a small set of financial and anti-abuse records survives erasure.
9. Security
We protect your data with measures appropriate to its sensitivity:
- All traffic runs over encrypted connections (HTTPS).
- Passwords are stored using a slow one-way hash, never in readable form.
- Session, verification and password-reset tokens are stored hashed rather than in readable form. Verification and reset tokens are short-lived and single-use.
- Sensitive fields are encrypted at rest with AES-256-GCM — Outage Watch phone numbers, and Codasc Assistant conversations and remembered facts.
- BIR DAT cloud backups are encrypted in your browser before upload with a passphrase we never receive.
- Each app’s data is isolated in its own database schema, with per-app credentials.
No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security, but we work to protect your information and to notify you and the National Privacy Commission of a breach where the law requires.
10. Where your data is stored, and international transfers
Our servers and database are hosted in the European Union (France), with Contabo. If you are in the Philippines, this means your data is stored outside the country.
Several of our sub-processors also operate outside your country (see Section 5) — notably OpenAI and Google in the United States. Where data is transferred internationally, we rely on appropriate safeguards and on the providers’ own compliance frameworks to protect it.
11. Children
Codasc is not directed to children. You must be at least 18 years old (or the age of majority where you live) to create an account. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as our products and the law evolve. We will change the “last updated” date above and, for material changes, take reasonable steps to notify you. Continuing to use Codasc after a change means you accept the updated policy.
Questions about this document? Email [email protected].