Privacy Policy

Effective Date: August 29, 2025
Last Updated: August 29, 2025

1. Data Controller

CPWE AI, the operator of KOJIE AI Software Engineering Platform, is the data controller responsible for your personal data.

Contact Information:
CPWE AI
Email: james@cpwe.biz
Data Protection Officer: james@cpwe.biz

2. Information We Collect

2.1 Authentication Data (via Replit OAuth)

  • User ID (stable identifier)
  • Email address
  • First and last name (if provided)
  • Profile image URL

2.2 Platform Usage Data

  • Projects created and managed
  • AI chat conversations and code generation requests
  • Performance analytics and usage patterns
  • Navigation and interaction data for UX improvement

2.3 Technical Data

  • Session tokens and authentication state
  • Browser and device information
  • Performance metrics and Core Web Vitals

3. Legal Basis for Processing (GDPR)

Contractual Necessity

Authentication, project management, and core platform features

Legitimate Interest

Performance optimization, security monitoring, and platform improvement

4. How We Use Your Information

  • Provide authentication and secure access
  • Manage projects and AI-assisted development
  • Process AI chat interactions and code generation
  • Maintain session state and user preferences

  • Monitor performance and optimize user experience
  • Analyze usage patterns for feature development
  • Conduct A/B testing for platform improvements
  • Generate anonymized analytics reports

5. AI Provider Integration

When you use AI features:

  • Your prompts and code are processed by selected AI providers
  • Each provider has their own privacy policies which apply to their processing
  • We do not store AI provider responses beyond session management
  • You can choose your preferred AI provider for each interaction

6. Google Drive & Sheets Integration

6.1 Data We Access

When you connect your Google account, we request access to:

  • Google Drive (drive.file scope): Access only to files that you explicitly select or that our application creates. We cannot access your entire Drive.
  • Google Sheets (spreadsheets.readonly scope): Read-only access to spreadsheets you select for import purposes.
  • Basic Profile Info: Your Google email address and name for account linking.

6.2 How We Use This Data

  • Import inspection data from your Google Sheets into the platform
  • Store photos from your Google Drive for visual inspection reports
  • Link your Google account to your CPWE AI profile for seamless access

6.3 Data Storage & Security

  • Google OAuth tokens are encrypted using industry-standard Fernet encryption
  • Tokens are stored per-tenant with strict isolation between customers
  • You can disconnect your Google account at any time, which revokes our access
  • We never share your Google data with third parties

6.4 Revoking Access

You can revoke CPWE AI's access to your Google account at any time by:

  1. Going to Google Account Permissions
  2. Finding "CPWE AI" in the list of connected apps
  3. Clicking "Remove Access"

7. Your GDPR Rights

Access & Portability

Request a copy of your personal data in a structured format

Rectification

Correct inaccurate or incomplete personal data

Erasure

Request deletion of your personal data (right to be forgotten)

Object & Restrict

Object to processing or request restriction of processing

To exercise your rights, contact us at james@cpwe.biz

8. Data Security

Enterprise Security Measures

  • End-to-end encryption for data transmission
  • Secure OAuth authentication via Replit
  • Regular security audits and penetration testing
  • SOC 2 Type II compliance framework
  • Role-based access controls and session management

9. Data Retention

Data Type Retention Period Purpose
Authentication Data Until account deletion Account management
Project Data Until user deletion Platform functionality
Chat Sessions 12 months Service improvement
Analytics Data 24 months (anonymized) Platform optimization

10. International Transfers

Your data may be processed in:

  • United States: Our primary hosting infrastructure
  • European Union: For EU users under GDPR adequacy decisions
  • AI Provider Locations: Based on your selected AI provider

All transfers are protected by appropriate safeguards including Standard Contractual Clauses (SCCs).

11. Contact & Complaints

Contact Us

Email: james@cpwe.biz
DPO: james@cpwe.biz

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority.

12. Changes to This Policy

We will notify you of significant changes to this privacy policy via email or platform notification. Continued use after changes constitutes acceptance of the updated policy.