Trust & transparency

Legal and product review draft

Clear promises for the stories that matter.

A single place to understand how CODA handles private memories, account data, recipient delivery, subscriptions, and regional privacy rights.

Prepared 22 September 2026 · 17 pages · Proposed effective date pending

One framework, built around private delivery.

CODA lets people preserve text, photos, video, audio, and documents, choose recipients, and set scheduled or check-in-based delivery. The policy pack explains the data and responsibilities behind that experience.

This document is not yet an effective public policy.

Company identity, contact details, hosting locations, retention commitments, and country-specific legal decisions remain open. Complete every bracketed item and obtain local legal review before production publication.

Part I

Privacy Policy

Covers account and profile information, private memory content, recipient details, check-ins, subscriptions, notification tokens, operational logs, support records, and administrative activity.

How data is usedTo secure accounts, store and deliver memories, operate reminders, manage billing, and support the service.
How content is protectedContent is encrypted at rest and protected in transit. The current architecture is not end-to-end encrypted.
Who receives dataChosen recipients and providers required for hosting, storage, notifications, payments, and lawful operations.
Your choicesAccess, correction, deletion, restriction, objection, portability, consent withdrawal, and complaints where applicable.
Read the full Privacy Policy

Part II

Terms of Service

Defines eligibility, account security, ownership of uploaded content, delivery rules, subscriptions, refunds, account deletion, availability, liability, and dispute handling.

  • CODA is a private memory storage and user-directed delivery service.
  • CODA is not a will, emergency service, death-verification tool, or guaranteed permanent archive.
  • Delivery timing depends on accurate recipient details, network and provider availability, and the selected rules.
  • Users retain ownership of their content and grant only the limited rights needed to operate the service.
Read the full Terms of Service

Part III

Acceptable Use Policy

CODA may restrict unlawful, abusive, dangerous, fraudulent, or technically harmful activity. This includes content shared without authority, harassment, exploitation, malware, impersonation, unsolicited marketing, and attempts to bypass service security.

Read the Acceptable Use Policy

Part IV

Regional Privacy Addendum

Privacy law is country-specific. The draft sets a regional framework while requiring separate review before any market is enabled.

European Union & EEA

GDPR rights, lawful bases, DPIA planning, representatives, and international transfers.

Asia

Country-specific coverage for Singapore, Japan, India, mainland China, and future markets.

MENA

Privacy, transfer, telecom, and consumer requirements across Saudi Arabia, the UAE, and the region.

Africa

Frameworks including South Africa POPIA, Nigeria NDPA, Kenya DPA, and local-market reviews.

Read the Regional Addendum

CODA App Policies

View the exact 17-page review draft or download a copy for offline review.

Your browser cannot display the embedded PDF.

Open the policy document