privacy policy

Privacy Policy

codecash pays developers to show one sponsored line in their AI coding agent’s wait states. This policy explains what we collect and what we deliberately don’t. The short version: we never read, store, or transmit your source code — see our transparency page for the exact wire payloads.

Last updated: June 16, 2026

01Who we are

This policy applies to the codecash website (codecash.dev), the codecash web app, and the codecash editor extension (collectively, the “Service”). In this policy, “codecash,” “we,” and “us” mean Skim AI Limited, the company that operates the Service. For any privacy question, reach us at vittorio@justskim.ai.

02The short version

  • We never access your source code, files, prompts, or the model’s output.
  • We collect the minimum needed to run an honest ad marketplace: your account email, a device record, ad view/earning events, and (for advertisers) billing details.
  • We don’t sell your personal data, and we don’t use your data to target ads.
  • You can disable the extension, delete your account, and request erasure at any time.

03Information we collect

Account information. Authentication is handled by Clerk. When you sign in we receive your email address and a Clerk user identifier, and we store a profile row keyed to it. If you set an optional display name or public handle, we store those too.

Device & technical information. When you connect the extension we create a device record containing the adapter (e.g. claude-cli), your operating system name (e.g. darwin), and your Claude Code version — used to check compatibility. We issue a signed device token that authenticates the extension’s requests. For fraud prevention only, our servers compute a salted, one-way hash of the IP address your requests already arrive with (as every web service receives) and store only that hash, never the raw IP — it lets us spot abuse such as one machine farming many accounts. We do not store your raw IP, derive your location, profile you, or use any of this to target ads, and we never collect your username, machine name, or any editor/project contents.

Ad & earning events. To run and pay out the marketplace we record ad serves, impressions (the server-signed token, a random idempotency key, how many milliseconds the ad was visible, and a timestamp), clicks where applicable, and the resulting ledger entries (your earnings, in micro-dollars).

Product telemetry. We record anonymized funnel events (rendered → viewable → threshold) via PostHog to measure fill rate and detect abuse. Your identity is resolved server-side from your token; the client never attaches it to telemetry.

Advertiser & payment information. If you buy ads, we collect the campaign details you submit (ad text, destination URL, brand name, icon) and process payment through Stripe. We never see or store your full card number — Stripe handles card data directly; we retain only a Stripe identifier and the resulting block/budget records.

Public profile (opt-in only). If you choose to make your earnings profile public, your handle and ledger-derived stats (lifetime earnings, ads shown, days active, community rank) become visible at /u/<handle>. Nothing is public until you opt in, and you can turn it off at any time.

04What we never collect

We never collect, transmit, or store:

  • Your source code, file names, paths, or file contents
  • Your prompts to the agent, or the model's output
  • Your repository or project structure
  • Keystrokes or editor activity
  • Your dependency list, lockfiles, or package versions

Relevant ads (opt-in, off by default). If you turn on relevant ads, the extension reads your dependency manifests locally, on your device and maps them against a small, fixed allowlist to coarse stack tags — for example fw:next, lang:python, db:postgres. Only those tags are sent, and only to rank which ad you see; never the manifests, their contents, or your dependency list. The tags rank a single ad and are then discarded — they are not stored against your device or your account, and we build no profile of your stack. You can view the tags codecash would send (e.g. codecash consent show) and switch the feature off in one click, after which requests carry no stack information at all.

05How we use information

  • Operate the money loop — serve ads, credit your earnings, and bill advertisers accurately.
  • Authenticate you and keep your account and device secure.
  • Detect and prevent fraud and abuse (e.g. automated or fake impressions, or one machine farming many accounts — correlated via a salted, hash-only signal, never your raw IP).
  • Measure and improve the product (aggregate funnel and fill-rate analytics).
  • Communicate with you about your account, payouts, and material changes to the Service.
  • Comply with legal, tax, and accounting obligations.

We do not do behavioral or cross-site ad targeting, we do not build a profile of you, and we do not sell your information. The optional relevant-ads feature uses only the coarse, on-device stack tags described in §4 — to rank a single ad, never linked to you.

06Files the extension writes on your device

The extension stores a small local ad cache and configuration under a folder in your home directory, and — when you enable it — edits ~/.claude/settings.json to render the sponsored line. Your original settings are backed up first and restored exactly when you disable or sign out. These files live on your machine; the render script makes no network calls of its own.

07How we share information

We share personal data only with the service providers that make the Service work, each under their own terms:

  • Clerk — authentication and account management.
  • Stripe — advertiser payments and (when available) developer payouts.
  • PostHog — product and funnel analytics, and abuse detection.
  • Amazon Web Services — application hosting and the database.

Advertisers receive only aggregate performance data (e.g. impression and click counts) — never information that identifies an individual developer. We may also disclose information if required by law, to enforce our Terms, or in connection with a merger or acquisition. We do not sell personal data.

08Cookies & similar technologies

The website uses a session cookie set by Clerk to keep you signed in, and analytics identifiers from PostHog to understand product usage. The editor extension uses a token stored in your editor’s secret storage rather than browser cookies. We do not use third-party advertising cookies.

09Data retention

We keep account and ledger data for as long as your account is active and as long as needed for legal, tax, and accounting purposes. Ad-serve records are short-lived operational data. When you delete your account we remove or anonymize your personal data, except records we must retain to meet legal obligations or resolve disputes.

10Your rights

Depending on where you live (including under the GDPR and CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email vittorio@justskim.ai and we’ll respond within the timeframe the applicable law requires. We will not discriminate against you for exercising these rights.

11Security

Billable events are authorized by server-signed tokens and verified server-side, so a modified client can’t fabricate earnings. Device tokens are short-lived and rotate automatically. We use reputable infrastructure and encryption in transit, but no method of transmission or storage is perfectly secure, and we can’t guarantee absolute security.

12International data transfers

We host the Service on infrastructure located in the European Union and rely on providers (such as Clerk, Stripe, and PostHog) that may process data in other countries. Where required, such transfers are made under appropriate safeguards (e.g. Standard Contractual Clauses).

13Children

The Service is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact vittorio@justskim.ai and we will delete it.

14Changes to this policy

We may update this policy as the Service evolves. We’ll revise the “Last updated” date above and, for material changes, provide a more prominent notice. Your continued use after an update means you accept the revised policy.

15Contact us

Questions about this policy or your data? Email vittorio@justskim.ai. See also our Terms of Service.