Privacy

What happens to your documents

This audience reads the privacy policy and checks the claims with a proxy. So this page is specific rather than reassuring.

Checking, signed out

The file is uploaded over TLS, written to a temporary directory, analysed, and the directory is deleted when the request finishes. Nothing is stored. No copy is kept. The only record is an aggregate count that a check ran.

Checking, signed in

The same, unless you tick Save this check to my history. If you do, the file and its report are stored in your own private area and deleted after seven days. You can delete either sooner.

Remediation

The source and the remediated output are stored so you can download the result and reopen the report. Uploads expire after seven days; outputs are kept until you delete them.

Alt text generation

Three modes, chosen at setup and shown persistently in the interface:

  • Local — a bundled model. Image bytes never leave the process. This is enforced at the network layer, not by convention.
  • Your own key — images only, with explicit per-document consent, sent to the provider you configured.
  • Off — manual entry only.

Telemetry

Off by default and opt-in. If you turn it on it reports which checks ran and how long they took. It never includes document content, filenames, extracted text or findings.

Payments

Handled by Stripe. Card details are never sent to or stored by Taggart. We hold a customer identifier, a subscription status and a plan.

Where things are

Processing runs on European infrastructure. Storage and authentication are hosted in Frankfurt (Supabase, EU region).

Rights and contact

Access, correction, export and deletion on request: hello@codama.dev. Account deletion removes documents, jobs and reports.

Last updated 8 September 2026. Material changes will be noted in the changelog.