Legal Document

PRIVACY POLICY

Version 3.0Effective from 9 August 2026Last updated 9 August 2026

This notice explains how the Codexe platform at codexe.eu processes personal data, under Regulation (EU) 2016/679 (GDPR). Codexe is a product of PENGUIN STUDIOS di MINURRI RAFFAELE. The Studio's custom-work business has its own notice: see Section 2.2.

1.Who we are and how to contact us

1.1Data Controller

The controller of the personal data described in this notice, within the meaning of Article 4(7) GDPR, is:

PENGUIN STUDIOS di MINURRI RAFFAELE
Sole proprietorship (impresa individuale)
Via Vito Dipierro n. 4 int. 5
70016 Noicattaro (BA), Italy
VAT No. IT09152590726
Tax Code: MNRRFL07S15H096Q

Privacy contact: [email protected]
Studio: penguinstudios.eu · [email protected]

Codexe is a product of PenguinStudios, not a separate company. The controller is the same legal entity for the platform and for the Studio's other activities, but they are separate services with separate notices.

1.2Data Protection Officer

We have not appointed one. Our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data, so the conditions in Article 37(1) GDPR are not met. Privacy enquiries are handled directly by the controller at the address above.

1.3Supervisory authority

Our lead supervisory authority is the Italian data protection authority, the Garante per la protezione dei dati personali. See Section 13.

2.Scope of this notice

2.1What this notice covers

Processing carried out in connection with the Codexe platform at codexe.eu: your account, your authentication, your subscription and payments, your projects and the AI generation you run, the public Gallery and community features, bots you host with us, API keys, the emails we send you, and the measures we take against abuse.

2.2What this notice does not cover

  • penguinstudios.eu and the Studio's custom-work business. Covered by the Studio's own notice at penguinstudios.eu/privacy. Same controller, different service, different processing. If you are both a Codexe user and a Studio client, both notices apply to you, each to its own service.
  • Discord, which processes your data as its own controller under its own policy, including on our community server.
  • GitHub, on the same basis, when you sign in or link an account.
  • A Discord bot you build and run. For the personal data your bot processes in the servers it joins, you are the controller and we are not. Section 6.11 explains what we process in order to host it for you.
  • Third-party sites we link to, and the servers or communities where you deploy code you generated here.

2.3A note on accuracy

This notice was written by going through the actual code, configuration and database schema of the platform, not from a template. Where the code can reach a third party but does not currently send it personal data, we say so rather than implying otherwise. Where something is done that a user might not expect, such as the engagement measurement in Section 6.8 or the usage scoring in Section 6.15, it is described in plain terms rather than hidden inside a general phrase.

3.At a glance

  • Our servers, database, files and outbound email run in the European Union (Germany).
  • We do not sell your data, and we do not use your prompts, projects or output to train AI models.
  • Your prompts are sent to the AI model provider you selected, which may be outside the EEA. Selecting a DeepSeek model sends them to China: see Section 9.2.
  • We run no advertising trackers and no third-party analytics. We do set one first-party attribution cookie and we do measure opens and clicks on the emails we send: Sections 6.8, 6.14 and 7.2.
  • We compute a usage score from your activity to decide which upgrade offers you are shown. It has no effect on your rights, your price or your service, and you can object to it: Section 6.15.
  • Card details never reach us. Payments run through Tebex as merchant of record.
  • You can delete your account yourself, at any time, from the account settings.

4.Categories of personal data

4.1Identity and account data

Email address, display name, avatar, account identifier, the date the account was created and the time you were last seen.

4.2Authentication and security credentials

Password stored only as an Argon2id hash where you set one; TOTP secret and recovery state where you enable an authenticator app; passkey public-key credentials and their metadata where you register a passkey; one-time email codes; session records; email verification and password-reset tokens.

4.3Linked identity data

Where you use Discord: Discord ID, username, avatar and the email address on that Discord account. Where you use GitHub: GitHub ID, username and avatar.

4.4Technical and connection data

IP address at registration and on each login, user agent, and the country derived from the IP address. Server logs generated by our hosting and by the network layer in front of it.

4.5Subscription, purchase and billing data

Plan and tier, period start and end, renewal state, cancellation records and any reason you gave for declining a renewal, Tebex transaction and customer references, amount, currency, billing country, the email address used at checkout, token-pack purchases, custom plans, and offer or coupon claims. We never receive or store card numbers.

4.6Usage and generation content

Your projects: their names, descriptions, settings, prompts, generated files, conversation history, build results and exported artefacts. Your token ledger: every grant, spend, refund and bonus. Streak counters by UTC day, milestone rewards, achievements.

Your prompts are personal data if you put personal data in them

We do not ask you to, and the Acceptable Use clause in the Terms asks you not to submit other people's personal data or confidential material. Whatever you do put in a prompt is sent to the model provider you selected: see Sections 6.2 and 9.

4.7Public content and community data

Where you publish a project: its visibility setting, share identifier, name, description, files and history as published, view count, upvotes and downvotes, clone count and template flag, together with your display name and avatar shown beside it. Comments you write, bookmarks you make, votes you cast, and your position on the public leaderboard.

4.8Bot hosting data

Where you host a Discord bot with us: the bot token, encrypted at rest; the runtime state of the container; and the most recent log output the bot produced, which contains whatever your bot prints.

4.9Developer API data

Where an API key is issued to you: an irreversible hash of the key, a non-secret display prefix, the owner name, email and external reference we were given, the purchase reference, the key status, the time it was last used, and metered request counts and upstream cost.

4.10Communication and engagement data

The emails we send you and their delivery status; your email frequency setting and per-notification preferences; your unsubscribe token; your newsletter consent; in-app notifications; and, for the emails we send, whether the message was opened and which links were clicked, with the IP address and user agent of the device that did so. Section 6.8 explains this and how to avoid it.

4.11Acquisition and attribution data

How you arrived: the normalised channel, the medium, the campaign tag, the referring page, and any free-text answer you give to the "how did you find us" question. Section 6.14 explains this.

4.12Security, abuse and enforcement data

Login attempts and their outcome, IP records, rate-limit counters, the result of the VPN and proxy check at signup, bot-verification outcomes, referral records including rejected attempts and the IP addresses compared, ban status and reason, administrative notes on an account, and an audit log of administrative actions including support access to an account.

4.13Data we do not seek

We do not ask for and do not want special categories of data under Article 9 GDPR, data relating to criminal convictions, government identity documents, or payment card details. Do not put them in a prompt, a project, a comment or a support message.

5.Where your data comes from

  • Directly from you: registration, account settings, prompts and projects, comments, support messages, preferences, and the "how did you find us" answer.
  • Automatically from your device: IP address, user agent, cookies and local storage, and the referring page and campaign parameters on your first visit.
  • From Discord and GitHub, when you sign in or link an account, limited to the fields listed in Section 4.3.
  • From Tebex, when a payment completes, renews, fails or is refunded or disputed.
  • From proxycheck.io, the VPN, proxy and geolocation verdict on the IP address you register from.
  • From another user, where someone invites you through a referral link, or comments on or votes for a project you published.

6.Processing operations and legal bases

Each operation below states what is processed, why, and on what legal basis under Article 6(1) GDPR. Where the basis is legitimate interest we state the interest, and you can object under Article 21: see Section 11.6.

6.1Account creation, authentication and sessions

Identity, credential and session data, to create your account, sign you in, keep you signed in, verify your email address, reset a password and operate second factors. Contract, Article 6(1)(b), and legitimate interest, Article 6(1)(f) for the security of the authentication itself.

6.2Running a generation

Your prompt, the relevant project context and our system instructions are sent to the model provider that operates the model you selected, which returns the output. The provider processes it in order to produce that response. Contract, Article 6(1)(b). Providers are listed in Section 8 and transfers in Section 9. We do not permit providers to train on your content, and we do not train on it ourselves.

6.3Prompt enhancement, thumbnails and textures

Where you use the prompt-enhance helper, your draft prompt is sent to OpenAI. Project thumbnails are generated through OpenAI. Textures and images for 3D models and item packs are generated through Fal.ai from the description your project supplies. Contract, Article 6(1)(b).

6.4Storing projects, files and history

Your projects, files, conversation history and build artefacts are stored so you can come back to them, export them and continue working. Contract, Article 6(1)(b).

6.5Subscriptions, token packs and payments

Billing data and the token ledger, to activate a plan, grant and account for tokens, process renewals, cancellations and refunds, and mint and validate a coupon on an offer. Contract, Article 6(1)(b), and legal obligation, Article 6(1)(c) for accounting.

6.6Transactional email and in-app notifications

Email address and event data, to tell you a build finished or failed, that a subscription renewed or is expiring, that a referral paid, that a badge unlocked or that someone voted on your project, according to the frequency and per-notification preferences you set. Account and security emails are always sent. Contract, Article 6(1)(b).

6.7Newsletter, product updates and usage nudges

Marketing newsletters are sent only to users who opted in, on consent, Article 6(1)(a), withdrawable at any time. Product announcements and usage-related messages, such as a note that your token balance is running low, are sent to verified users who have not switched email off, on legitimate interest, Article 6(1)(f) in keeping users informed about a service they use. Every such email carries a one-click unsubscribe, and setting email frequency to off stops all of them.

6.8Measuring opens and clicks on our emails

Our emails contain a tracking pixel and links that pass through a redirect, so that we record whether a message was opened and which link was clicked, together with the IP address and user agent that did so. We use it to see whether announcements are landing and to stop sending mail nobody reads. Legitimate interest, Article 6(1)(f).

How to avoid it

Blocking remote images in your mail client stops the open pixel from firing. Copying a link rather than clicking it avoids the redirect. Setting email frequency to off, or unsubscribing, stops the mail and therefore the measurement. You may also object under Article 21, and we will exclude your address from measurement without switching off the emails you asked for.

6.9Public gallery, votes, comments and the leaderboard

Where you set a project to public or unlisted, its content and metadata, your display name and your avatar are shown to others, and public projects are ranked on a public leaderboard by net votes. Comments and votes are attributed to your display name. Contract, Article 6(1)(b), because publishing is a feature you chose to use. Keeping a project private keeps it out of all of this.

6.10Achievements and streaks

Daily activity counters and unlocked badges, to operate the streak and achievement features and to grant the associated bonuses. Contract, Article 6(1)(b).

6.11Hosting a Discord bot for you

Your bot token, held encrypted and decrypted only to start the container; the container state; and the recent log output, which contains whatever your bot prints. We process this to run the bot you asked us to run. Contract, Article 6(1)(b). For personal data your bot handles in Discord servers, you are the controller and we are not: see Section 2.2.

6.12Developer API keys

The key hash, owner details, status and metered usage, to authenticate calls, enforce the cost cap, bill the key and revoke it when required. Contract, Article 6(1)(b).

6.13Abuse prevention, fraud and enforcement

IP addresses and the VPN and proxy verdict at signup, the per-IP account cap, rate-limit counters, bot verification on sensitive forms, referral records including rejected attempts, ban status and reason, and the administrative audit log. Used to keep the free tier and the bonus programmes from being farmed, to protect the service against attack, and to evidence a decision if you challenge it. Legitimate interest, Article 6(1)(f) in the security and economic viability of the service. We have weighed this against your rights and consider it proportionate: the checks are narrow, the data is short-lived, and a human reviews any block on request.

6.14Acquisition attribution

On your first visit we record, in a first-party cookie, the campaign parameters in the URL and the site that referred you, normalised to a channel. If you sign up, that becomes the acquisition record on your account. If it is empty we may ask you once, in the interface, how you found us, and you can dismiss the question. We use it in aggregate to know which channels bring users. It is not shared, not used for advertising, and not used to track you across other sites. Legitimate interest, Article 6(1)(f). Section 7.2 covers the cookie itself and how to refuse it.

6.15Usage scoring and commercial offers

We compute a score from your own activity over the last thirty days: how many generations you ran, what share of them used premium models, how many projects you have, your build success rate and your streak length. The score places the account in one of three bands, and the band decides which upgrade prompts and which time-limited offers you are shown. Legitimate interest, Article 6(1)(f) in offering the plan that fits how the service is actually being used.

What this is and is not

It is profiling within the meaning of Article 4(4) GDPR, and we call it that. It is computed only from your own activity in Codexe, never from data bought or inferred elsewhere. It has no effect on your price, your token allowance, your service quality or any right you have: the only thing it changes is which offer banner you see. It is not a decision based solely on automated processing within the meaning of Article 22, because it produces no legal or similarly significant effect. You may object under Article 21, and on objection we stop scoring the account and show you nothing but the standard pricing page.

6.16Support, and administrative access to an account

Support messages and, where necessary to reproduce a fault or investigate a specific abuse signal, administrative access to an account, together with internal notes on the account. Every such access is written to an audit log with the administrator, the time and the action. Contract, Article 6(1)(b) for support you asked for, and legitimate interest, Article 6(1)(f) for investigation and for the auditability of our own staff.

6.17Quality review of generations

An administrator may read a conversation in order to understand why a generation went wrong, annotate it internally as good, bad or noteworthy, and write a general instruction that is added to the system prompt for future generations of that project type.

Those instructions are written by a person and are general rules, for example about how a given API should be called. They are not your text, they are not model training, and no part of your project is copied into them. Legitimate interest, Article 6(1)(f) in improving the accuracy of the service. We use it on failures and on conversations you report; we do not read private projects out of curiosity.

6.18Invoicing, accounting and tax

Transaction records and the payouts we receive, kept and reported as Italian tax and accounting law requires. Legal obligation, Article 6(1)(c).

6.19Legal claims

Where a claim, a dispute or an investigation arises, the records needed to establish, exercise or defend it, kept for as long as that requires. Legitimate interest, Article 6(1)(f), and legal obligation, Article 6(1)(c) where we are required to retain or produce them.

6.20What we do not do

We do not sell or rent personal data. We do not run third-party analytics or advertising trackers on the site. We do not build marketing profiles from data obtained outside Codexe. We do not use your prompts, projects or output to train AI models. We do not use the Google Places integration on user data: it is called only by an internal tool restricted to the Studio owner and processes business listings, not Codexe accounts.

7.Cookies and local storage

7.1Strictly necessary items

These are exempt from consent under Article 5(3) of the ePrivacy Directive because the service you asked for cannot work without them.

  • codexe_session: authentication token, 30 days.
  • codexe_pending_2fa: carries the second-factor step, about 5 minutes.
  • discord_oauth_state, github_oauth_state: cross-site request forgery protection during the sign-in handshake, deleted on completion.
  • discord_link_mode, github_link_mode: marks that an existing user started the link-account flow, deleted on completion.
  • codexe_ref: referral code from an invite link, 30 days, read once at signup.
  • codexe_banned_info, codexe_ip_blocked_info: single-shot 5-minute cookies carrying the reason to the page that explains a block, cleared on read.
  • codexe_impersonation_stash: set only while an administrator is accessing an account under Section 6.16, and expires with that access.

7.2Attribution: not strictly necessary

codexe_acq, 90 days

On your first visit we write a first-party cookie holding the campaign parameters in the URL, the referring host, a normalised channel and a timestamp. It is first-touch, so it is never overwritten, and it is read once if you sign up. It is not used for advertising, it is not shared with anyone, and it cannot follow you to another site.

We do not claim this one is strictly necessary. It exists so we know which channels bring people to Codexe. You can refuse or remove it at any time by blocking or deleting cookies for codexe.eu, and nothing in the service stops working if you do. There is no consent banner on the site today: this notice is where we tell you the cookie is there, and deleting it is how you refuse it. If we ever set a cookie that does more than this one does, it will be put behind a consent step and this notice will be reissued before it is set.

7.3Advertising items: none

We set no advertising cookies, no cross-site identifiers, no conversion pixels and no third-party analytics tags. If that ever changes it will be behind a consent banner and this notice will be reissued first.

7.4Third-party items

Cloudflare Turnstile sets its own short-lived challenge token on the forms where it runs, for bot verification only, and is strictly necessary to the security of those forms. Loading the code-editor assets from a content delivery network and the two-factor QR image from an external renderer exposes your IP address to those services at the moment of the request: see Section 8.

7.5Local storage

The interface keeps preferences such as editor layout and dismissed notices in your browser's local storage. They stay on your device, are not sent to us as a profile, and clearing site data removes them.

8.Recipients and processors

8.1We do not sell your data

Nobody receives your personal data for their own marketing. The recipients below receive only what they need for the function described.

8.2AI model providers

When you run a generation, the prompt, the relevant project context and the system instructions are sent to the provider of the model you selected. Providers act on our instructions for that purpose and are not permitted to train on your content.

  • Anthropic, Claude models, United States.
  • OpenAI, GPT models, United States. Also used for the prompt-enhance helper and project thumbnails.
  • xAI, Grok models, United States.
  • DeepSeek, DeepSeek models, People's Republic of China. Read Section 9.2 before selecting one.
  • Fal.ai, United States. Image generation for 3D model and item-pack textures.

8.3Platform and infrastructure

  • Hetzner Online GmbH, Germany. Hosting of our servers, database, stored files and bot containers.
  • Tebex (Analyse BV), Netherlands. Payment processing and subscription billing, as merchant of record.
  • Resend, United States. Transactional and campaign email delivery.
  • Cloudflare, United States and edge locations. Turnstile bot verification on sensitive forms; your IP address and a challenge token are processed to decide whether you are a bot.
  • proxycheck.io, United Kingdom. IP geolocation and VPN or proxy detection at signup.
  • jsDelivr, content delivery network. Serves the code-editor assets in the project workspace; your IP address is visible to the network when those assets load.
  • goQR.me (api.qrserver.com), renders the QR code shown when you set up an authenticator app. Your browser requests the image, so the enrolment URI, which contains the shared secret, is visible to that service. If you would rather not involve a third party in your two-factor setup, type the secret into your authenticator app by hand instead of scanning the code.

8.4Independent controllers

These decide their own purposes and are not our processors: Discord and GitHub, for sign-in and optional account linking, and Discord again in respect of a bot you host, for everything that happens inside the servers your bot joins.

8.5Others

We disclose personal data to a public authority only where we are legally required to, and to a professional adviser or a court only where necessary to establish, exercise or defend a legal claim. If the business is transferred, the acquirer receives the data subject to this notice, and you will be told.

9.International transfers

9.1Where processing happens by default

Our servers, database, stored files, bot containers and outbound email infrastructure run in the European Union (Germany), so the great majority of processing takes place inside the EEA.

Personal data is transferred outside the EEA only in the cases listed in Section 8. Those transfers rely on the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR and, where the recipient is certified, on the EU-US Data Privacy Framework adequacy decision under Article 45 GDPR. You can request a copy of the safeguards at the contact address in Section 1.

9.2Transfers to China: DeepSeek

No adequacy decision covers this transfer

The DeepSeek models are operated from the People's Republic of China, for which the European Commission has issued no adequacy decision. If you select a DeepSeek model, the content of your prompt and the relevant project context are transferred there. We rely on Standard Contractual Clauses, but you should be aware that the practical enforceability of EU data protection rights in that jurisdiction is more limited than within the EEA.

You are never required to use a DeepSeek model. Every plan includes alternatives hosted by EU or US providers, and you can change the model on a project at any time from the project settings. If you do not want any transfer to China, do not select a DeepSeek model.

10.How long we keep data

10.1Retention

DataKept for
Account, profile and linked identitiesUntil you delete the account
Projects, prompts, files and historyUntil you delete the project, or the account
Sessions30 days
Login attempts90 days
IP records90 days
Token ledgerLife of the account
Streak countersLife of the account; the visible calendar shows the last 60 days
Referral records, including rejected attemptsLife of both accounts, so the one-bonus-per-signup rule stays auditable
Subscription, purchase and coupon recordsUntil you delete the account; see 10.2
Email delivery log, opens and clicksLife of the account
Bot token and container stateUntil you remove the bot or delete the project
Bot log outputMost recent output only, overwritten as the bot runs
API key records and metered usageLife of the key, then 12 months
Ban records and administrative audit logAs long as needed to enforce and to evidence the decision, then deleted
Accounting records of payouts received10 years, as Italian tax law requires

10.2What deleting your account actually removes

Deleting the account removes, in a single transaction, your account record, your projects and their files and history, your token ledger, your sessions, your credentials and second factors, your IP records and login attempts, your subscription record, your custom plans and our own copy of your purchase records, including the Tebex references stored against them.

Two things survive, and neither is under our control in the way the rest is. Tebex holds the payment records as merchant of record, under its own obligations and its own notice. Our accounting records of the payouts we receive are kept for the ten years Italian tax law requires; they are organised by payout and not by Codexe account, and deleting your account does not and cannot remove them.

Public content is removed with the account, but anything another user already read, copied or cloned while it was public is beyond our reach: see Section 14.6 of the Terms.

10.3Backups

Backups are kept on a rolling basis and overwritten in the ordinary cycle. Data deleted from the live system disappears from backups as that cycle completes. We do not restore a backup in order to recover data a user asked us to erase.

11.Your rights

11.1Access, Article 15

You can ask for confirmation of whether we process your data, a copy of it, and the information in this notice as it applies to you.

11.2Rectification, Article 16

You can correct inaccurate data and complete incomplete data. Most of it you can edit yourself in the account settings.

11.3Erasure, Article 17

You can delete your account yourself at any time, or ask us to. Section 10.2 explains exactly what that removes and what survives.

11.4Restriction, Article 18

You can ask us to freeze processing while an accuracy dispute or an objection is resolved.

11.5Portability, Article 20

You can receive the data you gave us, and your projects, in a structured, commonly used, machine-readable format. Projects can be exported from the interface at any time without asking us.

11.6Objection, Article 21

You can object to any processing based on legitimate interest, namely Sections 6.7, 6.8, 6.13, 6.14, 6.15, 6.16, 6.17 and 6.19. We stop unless we can demonstrate compelling legitimate grounds that override your interests, which in practice means we will keep only what is needed to prevent abuse or to defend a legal claim. An objection to Section 6.15 is always honoured without argument.

11.7Withdrawal of consent, Article 7(3)

Where processing rests on consent, in practice the newsletter, you can withdraw it at any time, from your preferences or through the unsubscribe link in any email. Withdrawal does not affect processing already carried out.

11.8Automated decisions, Article 22

You are not subject to a decision based solely on automated processing with legal or similarly significant effects. Section 14 sets out the automated checks that do run and how to get a person to look at one.

11.9Complaint, Article 77

You can complain to a supervisory authority. See Section 13.

12.How to exercise your rights

12.1Where to write

Email [email protected], or reach us through Discord. Say what you want; you do not need to cite an article or use any particular form of words.

12.2Verifying who you are

We will normally verify you by asking you to write from the email address on the account, or to act from inside a signed-in session. We ask for an identity document only where we have real doubt, and we do not keep a copy longer than the check requires.

12.3Timescales

We respond within one month, extendable by two further months for complex requests, in which case we tell you why within the first month.

12.4Cost

Exercising your rights is free. We may charge a reasonable fee, or refuse, only for a manifestly unfounded or excessive request, and we will explain why.

12.5If you are unhappy with our response

Tell us and we will look again. You can also complain to a supervisory authority at any point, without going through us first.

13.Complaint to the supervisory authority

You have the right to lodge a complaint under Article 77 GDPR with the Italian data protection authority, the Garante per la protezione dei dati personali, at www.garanteprivacy.it, or with the supervisory authority of the EU Member State where you live, where you work, or where the alleged infringement took place. We would appreciate the chance to address your concern first, but that is a preference, not a condition.

14.Automated decision-making and profiling

14.1No decisions with legal or similarly significant effects

We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 GDPR.

14.2Automated processing that does take place

  • The VPN and proxy check and the per-IP account cap at signup, which can block a registration.
  • Rate limiting and the concurrency limit, which can delay a request.
  • Bot verification on sensitive forms, which can block a submission.
  • Abuse signals that can flag an account for review. A ban is applied by a person, not by the system.
  • The usage score in Section 6.15, which selects which upgrade offers you see.

Where an automated check blocks you, the page that explains the block also tells you how to reach us, and a person reviews the case on request.

14.3Profiling: what we do and do not do

The only profiling we carry out is the usage score described in Section 6.15, computed from your own activity in Codexe and used only to select a commercial offer. We do not profile you from data obtained elsewhere, we do not build advertising audiences, and we do not share any score with a third party.

14.4Artificial intelligence transparency

Section 20 of the Terms sets out our position under Regulation (EU) 2024/1689, including our role, the classification of the systems we operate, the marking of machine-generated content and the human route that is always available.

15.Children and minors

The Service is not intended for anyone under 16, and you must be at least 16 to create an account. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, write to us and we will remove it and close the account.

16.Security

We implement measures appropriate to the risk under Article 32 GDPR: passwords stored only as Argon2id hashes, HTTPS with strict transport security, signed session tokens, optional second factors including passkeys and authenticator codes, encryption at rest for hosted bot tokens, a strict content security policy, rate limiting, bot verification on sensitive forms, VPN and proxy detection at signup, least-privilege administrative access, and an audit log of administrative actions.

No system is perfectly secure. If you find a vulnerability, write to [email protected]. We will not pursue anyone who reports a genuine issue in good faith, without accessing other people's data and without degrading the service.

17.Personal data breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Garante without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33 GDPR). Where the breach is likely to result in a high risk to you, we will also inform you directly and without undue delay, in plain language, telling you what happened, what data was involved and what to do (Article 34 GDPR).

18.Changes to this notice and versioning

18.1Versioning

Every release of this notice carries a version number, an effective date and a last-updated date. This release is version 3.0, effective 9 August 2026. A published version is not edited in place: any change of wording is issued as a new version number.

18.2Archive

We keep every superseded version and will supply on request the text in force on any given date. The public archive at penguinstudios.eu/legal covers the Studio's general Terms and Conditions and Privacy Policy; the Codexe documents are held by the Studio and issued on request until a public Codexe archive is published.

18.3How we notify changes

The list of model providers in Section 8 changes when we add or withdraw models, and this notice is updated when it does. Material changes are communicated by email or by a notice in the Service before they take effect.

18.4Version history

  • 3.0, effective 9 August 2026. Restructured onto the numbering and drafting conventions of the Studio's Privacy Policy. Adds the processing that version 2.0 did not describe: email open and click measurement, the acquisition cookie, the usage score used to select commercial offers, hosted bot tokens and logs, developer API keys, public content and the leaderboard, passkeys, in-app notifications and digests, administrative access to an account, and internal quality review of generations. Withdraws the claim that only strictly necessary cookies are set, which the attribution cookie in Section 7.2 contradicted, and the claim that no profiling for commercial purposes takes place. Corrects the account-deletion and retention description, which previously stated that transaction records survive deletion when the platform in fact deletes its own copy of them. No new processing was introduced by this version: it describes what the platform already does.
  • 2.0, effective 4 August 2026, superseded 9 August 2026.

19.Contact

For anything in this notice, or to exercise a right, write to [email protected] or reach us on Discord. The controller's full details are in Section 1.1.

Privacy | Codexe