The text you type
Your text never reaches us. Whatever you paste, import or share into CodePass stays in the app's own storage on your phone and goes out over Bluetooth to your computer as keystrokes. It is not uploaded, logged, or backed up by us.
What our server stores
- Keys: only a one-way hash of each key, the plan bought, when it was created, when it was activated, and when it ends.
- A phone identifier: a one-way hash of an Android-generated app-specific id. It is not your phone number, IMEI, or account, and it cannot be matched against what other apps see.
- Payment reference: the order number and Razorpay payment id for your purchase, so a lost key can be found again.
- Rate limiting: a hash of the requesting IP address with a short expiry, to stop the payment and key endpoints being hammered. The address itself is not stored.
Payments
Payments are handled by Razorpay. Card and UPI details are entered in Razorpay's own checkout and never pass through our server or the app. Razorpay receives the contact details you give it there, under Razorpay's privacy policy.
Inside the app
- No ads, no analytics, no tracking. The app contains no advertising or analytics libraries.
- Photo to text is optional. If you add your own Google Gemini API key, the images you choose are sent to Google's API under your key and Google's terms. Without a key, text is read from images entirely on the phone and no image leaves it.
- Camera is used only while you are on the capture screen, for photographs you take yourself.
- Bluetooth is used to act as a keyboard. No location is derived from it.
- Your Gemini API key, if you add one, is stored only in the app's private storage on the phone.
Keeping and deleting
Licence records are kept while a pass is valid and afterwards as a record of the sale, as accounting rules require. Rate-limit rows expire within minutes. To have a licence record deleted, write to us — note that this also ends the pass it belongs to.
Your rights
You can ask what is held about you, ask for it to be corrected, or ask for it to be deleted, at codepasssupport@gmail.com.
Contact
codepasssupport@gmail.com — see the contact page.