This Privacy Policy is the single, umbrella privacy policy for Code Red and all of our products and services. It is in two parts: Part A sets out the shared terms that apply to everything we do, and Part B contains a short, self-contained schedule for each individual product describing the data flows that are unique to it. To understand how we handle your information for a particular product, read Part A together with that product's schedule in Part B.
Contents
- Part A — Shared
- 1. Who we are
- 2. Scope
- 3. What we collect
- 4. How we use it
- 5. Sharing & transfers
- 6. Security
- 7. Retention
- 8. Your rights
- 9. Children
- 10. Changes
- 11. Contact
- Part B — Per-product
- Schedule A — Lares (app)
- Schedule B — Code Red Shop
- Schedule C — Dailies (beta)
- Schedule D — Invoicing (beta)
- Schedule E — Future products
A1Who we are
This policy is issued by Code Red (ABN 99 163 851 573), based in Western Australia, Australia ("Code Red", "we", "us", "our"). For the purposes of applicable privacy laws, Code Red is the entity responsible for (and the data controller of) the personal information described in this policy.
Code Red is committed to handling personal information in accordance with the Australian Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), and, where applicable, with the GDPR (EU/UK) and the CCPA/CPRA (California).
Privacy questions, requests, and complaints: support@codered.lol.
A2Scope
This policy applies to all Code Red products and services, including Lares (our home-inventory app), Code Red Shop (our online store), Dailies (our daily reflection, habit and nutrition tracker), and Invoicing (our time-tracking and invoicing web app), and to any future products listed in the schedules below, except where a particular product publishes its own separate policy that expressly does not incorporate this one.
Part A applies across every product. Each product also has a schedule in Part B that lists the additional data, third parties, processing locations, and retention specific to that product. Where a schedule conflicts with Part A, the schedule prevails for that product.
A3What we collect across products
The exact information we collect depends on which Code Red product you use. Across our products the categories of personal information we may collect are:
| Category | What it can include | Used in |
|---|---|---|
| Identity & contact | Name, email address, and phone number where you provide it. | Lares (email), Code Red Shop (name, email, phone), Invoicing (name, email, phone) |
| Account & profile | User ID, plan tier, settings, preferences, goals, and usage counters. | Lares, Dailies, Invoicing |
| Address information | Shipping and billing addresses (street, city, state/province, postcode, country), or your business address. | Code Red Shop, Invoicing |
| Content you create or upload | Inventory entries, room names, photos and videos of your belongings, customisation details such as custom-logo text and image files, journal entries, checklists and todos, meal photos, time entries, and invoices. | Lares, Code Red Shop, Dailies, Invoicing |
| Location | Saved coordinates (latitude and longitude) of places you define, used only to recognise which of your places you are at. Never tracked in the background, and no history of your movements is kept. | Lares |
| Health & wellbeing information | Weight, body measurements, sex, age, height, sleep, mood, food intake and nutrients, and exercise. This is sensitive information and is collected only with your consent (see Schedule C). | Dailies |
| Business & financial details | Business name, ABN, bank account details (bank, BSB, account number and name), rates, hours, earnings, and invoice records. | Invoicing |
| Information about other people you provide | Your clients' contact names, company names, ABNs, and email addresses. | Invoicing |
| Order & transaction data | Items purchased, quantities, prices, order references, totals, currency, payment status and method label, fulfilment status, and carrier/tracking details. Subscription references and status. | Lares (subscription), Code Red Shop (orders), Invoicing (subscription, if paid plans are introduced) |
| Payment data | Card and payment details are collected and processed by our third-party payment providers. Code Red does not store full card numbers, PAN, or CVV — only a payment status and a payment-method label. | Lares, Code Red Shop |
| Device, network & usage data | IP address, browser/device identifiers, and cookies, primarily collected by the platforms that host checkout and by our sign-in provider, plus the request logs any web server keeps. Code Red-built surfaces run no analytics or tracking pixels of their own, except Google Analytics on the Code Red Shop storefront (see its schedule). | Lares (web app), Code Red Shop, Dailies, Invoicing |
| Correspondence | Messages you send us for support, returns, or enquiries. | All products |
We collect information directly from you (for example when you create an account, place an order, or contact us) and, for some categories, automatically (for example device and cookie data collected by a hosted checkout) or from our service providers (for example identity data returned by our authentication provider). Product-specific detail is in Part B.
A4How we use your information
Consistent with APP 6, we use personal information only for the purposes for which it was collected and related, reasonably expected purposes, including to:
- create, operate, authenticate, and secure your account;
- provide the product's core features (cataloguing belongings, AI recognition and valuation, processing and fulfilling orders, tracking your daily habits, nutrition and wellbeing, and building and emailing invoices to your clients);
- process payments and manage subscriptions through our payment providers;
- arrange delivery of physical goods and provide tracking;
- respond to your requests, provide support, and handle returns and complaints;
- measure how people use the Code Red Shop storefront and whether our ads lead to sales (Google Analytics and Google Ads conversion measurement, with ad personalisation turned off);
- maintain security, prevent fraud and abuse, debug, and keep our services running (we keep structured operational logs); and
- comply with our legal and tax record-keeping obligations.
We do not sell your personal information, and we do not use it for cross-context behavioural advertising. Where a product relies on your consent for a particular processing activity (such as cloud AI processing of images in Lares and Dailies, or health information in Dailies), that is identified in the relevant schedule.
A5Sharing & international transfers
We share personal information only with the categories of recipients below, each acting to deliver the part of the product that depends on them, or where required by law. We do not sell your data, and we do not share it for targeted or personalised advertising.
- E-commerce platform & hosted checkout (Shopify) — for Code Red Shop orders and payment.
- Payment providers (Shopify Payments and its payment processor; Stripe; the Apple App Store and Google Play, through RevenueCat, for subscriptions bought in the Lares apps; and our self-hosted crypto-payment server, BTCPay) — to process payments. Card data is handled by these providers, not by Code Red.
- AI / recognition & valuation providers (OpenRouter routing to Google Gemini; plus marketplace and barcode lookups) — for Lares item recognition and valuation, and Dailies meal-photo estimates.
- Food data provider (Open Food Facts) — barcode and food-search lookups for Dailies. No personal information is sent.
- Authentication provider (Clerk) — for sign-in and identity across Lares, Dailies, and Invoicing, which share one Code Red account.
- Email delivery (Brevo) — to deliver the invoice emails you send to your clients from Invoicing.
- Hosting, storage & address tools (Vultr cloud servers; Neon managed Postgres; Cloudflare R2 / S3-compatible object storage; Vercel and Vercel Blob; jsDelivr content delivery; Google Maps/Places autocomplete) — to host our services and store files.
- Analytics & ad measurement (Google Analytics and Google Ads) — for Code Red Shop, to count visits and measure which ads lead to items being added to cart, checkouts, and purchases. Ad personalisation (remarketing) is off.
- Shipping carriers (e.g. Australia Post or couriers) — to deliver physical goods and provide tracking.
- Our own self-hosted systems (InvenTree inventory, Paperless-ngx document archive, ntfy notifications, Kimai time tracking, and the servers and databases behind Dailies) — these run on infrastructure we operate ourselves. They are not external third parties, but they do hold customer personal information and are disclosed for transparency.
- Legal & safety — courts, regulators, or other parties where required by law or to protect rights, safety, or property.
APP 8 Overseas / cross-border disclosure
Several of our providers are located outside Australia, so your personal information is likely to be transferred to, processed, and stored overseas. The likely recipient countries are the United States, Canada, Ireland/EU, and Singapore:
- Shopify (Code Red Shop's e-commerce platform and hosted checkout) is based in Canada/US and uses subprocessors in the US, Canada, the EU/Ireland, and Singapore. Shopify acts as a data processor under its Data Processing Addendum and uses standard contractual clauses with its subprocessors.
- Stripe, RevenueCat, Apple, Clerk, OpenRouter, UPCitemdb, Expo, Vercel, jsDelivr, and Google are principally US-based or operate on global cloud infrastructure.
- Brevo (Invoicing email delivery) and Open Food Facts (Dailies food lookups) are based in France/the EU.
The Dailies database, and the Invoicing database, app server, and time-tracking system, are hosted in Australia.
Code Red remains the data controller and takes reasonable steps (as required by APP 8) to ensure overseas recipients handle your personal information consistently with the APPs, including by relying on those providers' data-processing terms. Privacy laws in those countries may differ from Australian law. Where a product feature depends on overseas processing, using that feature involves this overseas disclosure.
A6Security
All data sent between you, our servers, and our providers is transmitted over encrypted connections (HTTPS/TLS). Personal information is held in access-controlled systems; uploaded files are stored in account- or order-scoped storage; and sign-in session tokens are kept only in your device's OS secure store (mobile apps) or in secure browser cookies (web apps). No method of transmission or storage is completely secure, but we take reasonable steps to protect your information. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme.
A7Retention
- We keep personal information only for as long as needed for the purposes described in this policy, or as required by law (for example, order and tax records).
- Account and content data is generally kept until you delete it or your account is deleted (see the Lares, Dailies, and Invoicing schedules).
- Order records, receipts, and related documents are retained for the period required for tax and accounting purposes (see the Code Red Shop schedule).
- Product-specific retention details are set out in the relevant schedule in Part B.
A8Your rights (access, correction, deletion)
Subject to applicable law, you have the right to access the personal information we hold about you, to request correction of inaccurate information, and to request deletion of your information. You can also opt out of any marketing communications at any time.
- Access & correction (APP 12/13): you can view and edit much of your data directly in-product (for example, your inventory and settings in Lares), or email support@codered.lol and we will provide or correct it.
- Deletion: you can delete content in-product where available, or email support@codered.lol from your account/order email and we will delete your information without undue delay, except where we must retain it by law (such as completed-order tax records). Product-specific deletion mechanics are in Part B.
- EU/UK (GDPR): you additionally have rights to rectification, erasure, restriction, data portability, and objection, and may lodge a complaint with your local supervisory authority. We process data to provide the service you requested (contract), for our legitimate interests in operating and securing our products and measuring our shop and its ads, to meet legal obligations, and — for cloud AI processing of images and for health information — on the basis of your consent.
- California (CCPA/CPRA): you have the right to know, to delete, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information and do not use it for cross-context behavioural advertising.
- Complaints (Australia): please contact us first at support@codered.lol. If you are not satisfied, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
A9Children
Code Red products are not directed to children and are not intended for anyone under 16 years of age. Lares in particular captures camera images and processes them with AI, so we ask that minors not use it. If you believe a child has provided us with personal information, contact us and we will delete it.
A10Changes to this policy
We may update this Privacy Policy from time to time, including by adding a new product schedule. When we make a change we will revise the "Last updated" date at the top, and material changes will be communicated in-product or by other reasonable means. Continued use of a Code Red product after an update means you accept the revised policy.
A11Contact
Code Red
ABN 99 163 851 573
Western Australia, Australia
Email: support@codered.lol
Schedule A — Lares (app)
This schedule adds to Part A the data flows specific to Lares, our home-inventory and valuation app for iOS, Android, and the web (lares.codered.lol). Read it together with Part A.
What Lares collects (in addition to Part A)
For Lares we collect only what we need to run the app. We do not collect your name, phone number, postal address, health data, biometric data, or government identifiers, and we collect location only in the limited way described under "Place locations" below.
| Category | What it includes | How it is collected |
|---|---|---|
| Account identifiers | Your unique user ID and email address. (We do not store your name or password — those are held by our authentication provider, Clerk.) | Provided to us by Clerk when you sign up or sign in, and synced via a signed webhook when your Clerk account is created, updated, or deleted. |
| Account settings & usage counters | Your plan tier (free / pro / household), default currency (e.g. AUD), a counter of cloud-AI scans you have used, and created/updated timestamps. | Set on sign-up and when you change settings; the cloud-AI counter increments each time a cloud scan succeeds. |
| Inventory item data | Item name, category, description, brand, model number, barcode/UPC, quantity, condition, purchase date, estimated value and currency, and AI detection/valuation source and confidence. | Manual entry, single-photo AI scan, or video room-scan review. |
| Room / location names | The room or area names you define (e.g. "Living Room", "Garage"), which can be nested. | Entered by you in the app. |
| Place locations | One latitude/longitude pair for each top-level place you define (for example "Home"), so Lares can recognise which of your places you are at when you start a room scan. We keep no history of where you have been and never track your location in the background. | Only if you allow location access, and only on the room-scan screen. The first time you record a scan at a place with no saved location, the app saves your current position to that place and tells you so. On later scans your device compares its current position with your saved places on the device itself — your live position is not sent to us except when it is saved to a place. You can remove a place's saved location at any time. |
| Photos of your belongings | JPEG/PNG/WebP/HEIC photos (up to 25 MB each) you capture with the in-app camera. These can incidentally show the inside of your home and your possessions. | Captured with the in-app camera and uploaded to our cloud storage. The app uses only the live camera — it does not read your device photo library. |
| Walkthrough scan videos | MP4/MOV room-walkthrough videos (up to 200 MB) recorded with your camera. Audio is captured as part of the recording. | Recorded with the in-app camera and microphone and uploaded to our cloud storage; we extract still frames from them on our server. |
| AI detection & valuation results | Detected item names, brands, models and confidence scores, and valuation history (estimated value, source, confidence, and the raw response from the AI / marketplace lookup). | Generated on our server when you scan or value an item. |
| Billing / subscription references | Payment provider name, subscription reference, subscription status, and current period end — the store transaction reference for subscriptions bought in the iOS or Android app, or the Stripe customer and subscription IDs for subscriptions started through Stripe. We never store your card number, PAN, or CVV. | In the iOS and Android apps, subscriptions are bought through the Apple App Store or Google Play and managed through RevenueCat, which receives your Lares user ID so a purchase can be linked to your account; payment is handled entirely by Apple or Google. Subscriptions previously started through Stripe continue to be managed via Stripe webhooks; for those, card details were entered on Stripe's own pages and never reached our servers. |
| Session tokens | Clerk session / login tokens. | Issued by Clerk. In the iOS and Android apps they are stored only on your device in the OS secure store (iOS Keychain / Android Keystore); in the web app, Clerk keeps them in secure browser cookies. Our backend verifies them but does not store them. |
Camera, microphone, and location access
Lares requests access to your device camera to photograph and catalog your belongings, scan barcodes, and record room-walkthrough videos. Because room-scan videos are recorded with sound, Lares also requests microphone access — the microphone is used only as part of video recording. Lares does not request access to your photo/media library. Lares asks for location access only on the room-scan screen and only while you are using it — never in the background. Location is optional: if you decline, you choose the place and room yourself. Media used by Lares comes only from the live camera while you are using a capture feature.
Important AI processing of your images
Some Lares features send your images off your device and to a third-party AI provider for automated item recognition and valuation. Please read this carefully:
- Single-photo scans: when you tap "High accuracy (cloud)" — or when cloud is the configured default, which is currently the case in our production service — the photo is uploaded to us and then sent (base64-encoded) to our cloud AI provider.
- Video room-scans: these always use the cloud AI provider. We extract still keyframes from your video on our server and send each keyframe to the cloud provider.
- Valuation: in addition to images, we send a text query built from the item's name, brand, model, barcode, and attributes (plus any web-search snippets) to help estimate value.
- The cloud provider receives only the image(s) and the text needed for recognition/valuation. We do not send your email address, account ID, or any device identifier in these AI requests.
- Our production cloud AI path is OpenRouter, which routes the request to Google Gemini (model google/gemini-2.5-flash-preview-04-17).
- A non-cloud single-photo option uses a self-hosted AI model running on our own infrastructure; in that path your image is not transmitted to any third party.
By using the cloud scan features you consent to this processing. If you do not want an image processed by the third-party AI, do not use the cloud single-photo option or the video room-scan feature.
Lares third parties & processing locations
In addition to the categories in Part A, Lares relies on:
| Provider | Role | What it receives |
|---|---|---|
| Clerk (US) | Authentication and identity. Holds your login credentials, email, and any profile information you give it. | Clerk collects your credentials and email directly at sign-up/sign-in. We receive your user ID and email back from Clerk. |
| OpenRouter → Google Gemini (US / Google cloud) | Cloud AI vision for item recognition and valuation. Our primary production vision provider. | Your item photos and extracted video keyframes (as base64 images), plus item text for valuation. No account email, ID, or device identifier. |
| Stripe (US / global) | Payment processing for subscriptions started through Stripe Checkout (Checkout, Billing Portal, webhooks). | Card details are entered directly on Stripe's pages and never touch our servers. We pass Stripe your user ID and plan tier as metadata; Stripe returns customer/subscription IDs and status. |
| RevenueCat (US) | Manages subscriptions bought in the iOS and Android apps, and tells us when one starts, renews, or ends. | Your Lares user ID and your purchase and entitlement status. No card details, photos, inventory, or location. |
| Apple App Store / Google Play (US / global) | Payment for subscriptions bought in the iOS and Android apps. | Your payment details, handled entirely by Apple or Google under your App Store or Google Play account. |
| eBay (Browse API) (global) | Marketplace price estimation (median of active listings). | A search query built from the item's brand/name/model only. No account info and no photos. |
| UPCitemdb (US) | Barcode → product identity lookup, to improve valuation accuracy. | The scanned barcode/UPC number only. No personal information and no photos. |
| Cloud object storage (operator-hosted; e.g. Cloudflare R2 / S3-compatible) | Stores your uploaded photos and videos. | Your photos, videos, and the keyframe thumbnails we extract, stored under a path scoped to your account. |
| Self-hosted services (operator infrastructure — not third parties) | A self-hosted AI model (non-cloud photo path) and a self-hosted web-search service used to ground valuations. The web-search service may query upstream search engines using an item text query (no personal information). | Item images (local AI path only) and item text queries. |
| Expo / EAS (US) | Build and distribution tooling for the mobile app. Not a runtime data processor. | No user runtime data. Lares includes no Expo analytics, push notifications, or update-tracking in the reviewed code. |
Each provider operates under its own privacy policy. Lares contains no analytics, telemetry, crash-reporting, advertising, or attribution SDKs (no Sentry, Crashlytics/Firebase, Amplitude, Mixpanel, PostHog, Segment, the Facebook SDK, AdMob, or App Tracking Transparency), sends no push notifications, and does not collect advertising identifiers. Place locations are stored only on our own servers and are not shared with any of these providers. Our server keeps structured operational logs only.
Lares retention & deletion
- Inventory items, locations, photos, videos, scans, and valuations are kept until you delete them in the app, or until your account is deleted.
- A place's saved location is removed when you remove it in the app, delete the place, or delete your account.
- When your account is deleted, your account record and all related database rows (items, locations, photo/video references, scans, detections, valuations, and subscription references) are permanently deleted. We do not run a fixed retention timer; data persists while your account is active.
- You can access and correct your inventory data directly in the app, delete individual items, locations, and scan sessions at any time, and export your data (CSV/ZIP and PDF) from settings.
- To delete your whole account, use the in-app account-deletion option where available, or email support@codered.lol from your account email. When your Clerk account is deleted, a signed webhook triggers permanent deletion of your Lares records.
Honest disclosure Stored media after deletion
When data is deleted, our deletion process currently removes the database records only. The underlying photo, video, and thumbnail files in object storage may not be automatically deleted at the same time, and could remain in storage until purged separately by us. We are working to make blob deletion automatic. If you want assurance that your stored images and videos have been purged, contact support@codered.lol and we will action it.
Schedule B — Code Red Shop (online store)
This schedule adds to Part A the data flows specific to Code Red Shop, our online store selling keyboards, related hardware, and merchandise. Read it together with Part A.
How the store works
The Code Red Shop storefront is a headless website, but checkout and payment are hosted by Shopify. When you check out on the standard card path, you are taken to Shopify's own hosted checkout, where Shopify (as the merchant of record for the order) collects your name, email, optional phone number, shipping and billing addresses, and your card/payment details. Code Red's storefront never sees your raw card data. After payment, the order details flow back to Code Red through authenticated webhooks so we can fulfil and record the order.
An optional "Pay with crypto" path is operated directly by Code Red: you enter your name, email, and shipping address into a Code Red form, and we send the payment to our self-hosted BTCPay Server for Bitcoin, Lightning, or Monero. This path is not Shopify-hosted and does not involve card data.
What Code Red Shop collects, and who it goes to
When you buy hardware we collect your name, email address, shipping and billing address, optional phone number, and order/transaction history. Card payment is handled on Shopify's hosted checkout (card details are not stored by Code Red). The table below sets out each data flow.
| Data | Collected via | Stored where | Shared with |
|---|---|---|---|
| Full name | Shopify-hosted checkout (standard card path); Code Red crypto form (crypto path). | Shopify (merchant of record). Also pushed to our self-hosted InvenTree (customer record) and rendered into a PDF stored in our self-hosted Paperless-ngx on every paid order. | Shopify (US/global); InvenTree; Paperless-ngx; ntfy order alert. Crypto path: also in the BTCPay invoice metadata. |
| Email address | Shopify-hosted checkout (standard); Code Red crypto form (crypto). | Shopify; InvenTree (used as the customer-lookup key); Paperless PDF receipt; BTCPay invoice metadata (crypto path). | Shopify (US/global); InvenTree; Paperless-ngx; ntfy (email appears in the "New Order" and "Order Fulfilled" notifications); BTCPay (crypto path). |
| Shipping address | Shopify-hosted checkout (standard); Code Red crypto form, with Google Places autocomplete assisting entry (crypto). | Shopify; InvenTree (address record + sales-order shipping address); Paperless PDF receipt. | Shopify (US/global); InvenTree; Paperless-ngx; ntfy (city/postcode/country summarised); shipping carrier (via Shopify). Crypto path: full address to BTCPay metadata, and the address you type is sent to Google (US) for autocomplete suggestions. |
| Billing address | Shopify-hosted checkout only (standard card path). The crypto form collects a single shipping address and no separate billing address. | Shopify; rendered into the Paperless PDF receipt. InvenTree uses billing address only as a fallback if no shipping address is present. | Shopify (US/global); Paperless-ngx; InvenTree (fallback only). |
| Phone number | Optional at Shopify-hosted checkout. The Code Red/crypto form does not collect a phone number. | Shopify only. | Shopify (US/global). Not forwarded to InvenTree, Paperless, or ntfy by Code Red. |
| Payment / card data | Shopify-hosted checkout exclusively — the storefront redirects to Shopify's hosted checkout. On the crypto path BTCPay collects the on-chain payment; no card data at all. | Shopify and its payment processor. Code Red/InvenTree/Paperless store only the payment status and a method label ("Shopify Payments" or "BTCPay (BTC / XMR / LN)") — never card numbers. | Shopify Payments / Shopify's payment processor (US/global). Crypto path: self-hosted BTCPay Server; no card data. |
| Order / transaction history | Generated by purchasing (Shopify order; InvenTree sales order; Paperless archived receipt). | Shopify; InvenTree (orders, line items, and any uploaded custom-logo attachments); Paperless-ngx (PDF receipts, kept for tax records); Vercel Blob (temporary custom-logo image storage, deleted after upload to InvenTree). | Shopify (US/global); InvenTree; Paperless-ngx; ntfy (order/fulfilment summaries); Vercel Blob (transient, US/global). |
| Device / network / cookies | Shopify checkout and Shopify-managed cookies during the hosted checkout. The Code Red storefront sets a first-party functional cartId cookie (the Shopify cart token) and, outside the EEA, UK and Switzerland, Google Analytics cookies. The Google tag records pages viewed, device/browser details, and shopping events (add to cart, checkout started, purchase, with item and order value). | Shopify (per its privacy policy). The cartId cookie is functional/first-party. Analytics events: Google (US). | Shopify (US/global) and any of Shopify's analytics/advertising partners per Shopify's policy. Google (US), for Google Analytics and Google Ads conversion measurement, with ad personalisation off. In the EEA, UK and Switzerland, Google's analytics and advertising cookies are not set (Google Consent Mode). Code Red adds no other analytics (no Meta Pixel, PostHog, Plausible, or Sentry). |
| Carrier tracking info | Shopify fulfilment webhook when the order is marked shipped (carrier, tracking number, tracking URL). | Shopify; written back to the InvenTree sales order; sent in the ntfy "Order Fulfilled & Shipped" notification. | The shipping carrier (Australia Post / courier); InvenTree; ntfy. |
Code Red Shop third parties
- Shopify (Canada/US; global infrastructure) — e-commerce platform and merchant-of-record hosted checkout. Collects and processes name, email, phone, shipping and billing addresses, payment/card data, order history, and device/IP/cookies. International transfer to US/global Shopify infrastructure. See Part A, Section A5 (APP 8).
- Shopify Payments — Shopify's integrated payment processor; processes card payments inside the hosted checkout. Card data never touches Code Red servers.
- Shipping carrier(s) (e.g. Australia Post / courier) — receive your name and shipping address to deliver your order and return tracking details.
- Google (Maps / Places API) — address autocomplete only on the crypto checkout form; as you type a shipping address, keystrokes are sent to Google (US) for Australia-scoped suggestions. Not used on the standard Shopify checkout path.
- Google (Analytics / Ads) — the Google tag on the storefront sends page views, device/browser details, and shopping events (add to cart, checkout started, purchase) to Google (US) so we can measure the shop and which Google Ads lead to sales. A Google Analytics pixel in Shopify's checkout also reports completed purchases (order ID, value, items; no name, email or address), and follows Shopify's customer privacy settings. Our product catalogue (no customer data) is sent to Google Merchant Center. The storefront tag has ad personalisation and remarketing turned off, and in the EEA, UK and Switzerland it sets no cookies.
- Vercel (hosting + Vercel Blob) — hosts the storefront (US/global) and temporarily stores customer-uploaded custom-logo image files until they are copied into InvenTree, after which the blob is deleted; may incidentally process request IP/logs.
- Self-hosted InvenTree (operator infrastructure, not an external third party) — receives customer name, email, and address and stores them as a customer record plus a sales order with line-item customisations.
- Self-hosted Paperless-ngx (operator infrastructure, not an external third party) — every paid order is rendered to a PDF receipt containing name, email, full shipping and billing address, line items, and total, then archived for tax records.
- Self-hosted ntfy (operator infrastructure, not an external third party) — receives push notifications on new and fulfilled orders containing your email, an item summary, and the destination city/postcode/country (and destination name on fulfilment).
- Self-hosted BTCPay Server (operator infrastructure; crypto checkout path only) — on the "Pay with crypto" path your name, email, and full shipping address are included in the invoice metadata, and BTCPay hosts the BTC / Lightning / Monero payment page. Not used on the standard card path.
Payment data & processors
Card and payment details for standard orders are collected and processed by Shopify Payments inside Shopify's PCI-compliant hosted checkout; Code Red does not store full card numbers. Crypto payments are processed by our self-hosted BTCPay Server. Please review Shopify's privacy policy for how it handles checkout, payment, and cookie data, including any Shopify-side fraud-analysis, network-intelligence, or Shop Pay features that may be enabled.
Code Red Shop retention
Order records, receipts, and related correspondence are retained for as long as needed to fulfil and support your order and to meet our tax and accounting obligations (typically several years, as required by Australian law). Data held by Shopify is retained under Shopify's policy. You can request access to or correction of your order details, or deletion of personal information that we are not required to keep, by emailing support@codered.lol.
Schedule C — Dailies (beta)
This schedule adds to Part A the data flows specific to Dailies, our daily reflection, habit, and nutrition tracker at log.codered.lol. Dailies is currently in beta. Read it together with Part A.
What Dailies collects (in addition to Part A)
Dailies stores only your account ID from our authentication provider — not your name, email address, or password. Everything else is what you choose to record.
| Category | What it includes | How it is collected |
|---|---|---|
| Account identifier | Your unique Clerk user ID. Your name, email, and password are held by Clerk, not by Dailies. | Provided by Clerk when you sign in. |
| Journal & planning | Daily reflections and intentions, recurring checklist items and which ones you tick each day, and todos. | Entered by you. |
| Health & wellbeing entries | Daily weight, mood rating, sleep duration and bed/wake times; food and drink entries with calorie, macronutrient, and micronutrient amounts; recipes; and exercise entries (activity, duration, calories, and details such as sets and weights). | Entered by you. Nutrient values come from our food database or an AI photo estimate. Sleep can also be sent by a health automation you set up (e.g. iOS Shortcuts or Health Auto Export) using your personal API token — only sleep records are kept; any other health metrics in that data are discarded. |
| Body profile & goals | Sex, age, height, activity level, starting and goal weight, body-fat percentage, neck/waist/hip measurements, calorie and macronutrient targets, sleep goal, and dashboard layout. | Entered by you in Goals & settings. Used only to calculate your targets inside Dailies. |
| Integration credentials | Your personal API token for sleep automations and, if you link Invoicing, the API key for your Invoicing account. | Generated by Dailies, or retrieved from Invoicing when you choose to link it. |
| Linked Invoicing summaries (optional) | If you link Invoicing, earned amounts, hours, invoice numbers, client company names, totals, and paid dates, shown alongside your day. | Fetched from Invoicing when you view Dailies. Not saved to the Dailies database; cached on our server for up to 5 minutes. |
Sensitive information Your health information
Much of what you record in Dailies — weight, body measurements, sleep, mood, diet, and exercise — is health information, which is sensitive information under the Privacy Act. We collect it only with your consent: by entering it into Dailies (or connecting a health automation) you consent to us collecting and storing it for the sole purpose of providing Dailies to you. Recording any of it is optional.
We do not use your health information for any other purpose, do not disclose it to anyone except as described in this schedule, and never use it for advertising.
Important AI estimates from meal photos
- When you use Photo to log a meal, your browser shrinks the image and re-encodes it as a JPEG (which normally removes location metadata), then sends it to our server with any optional hint you type. Our server forwards the image and hint to OpenRouter, which routes it to Google Gemini, to estimate the foods and nutrients.
- Meal photos are not stored. They are processed in memory and discarded — never written to our database or file storage. Only the estimated items you choose to add are saved.
- We do not send your email address, account ID, device identifier, body profile, goals, or any other entries in these requests.
- By using Photo you consent to this processing. If you do not want a photo sent to the AI provider, add foods by search, barcode, or manual entry instead.
Camera access
Dailies uses your camera only while the barcode scanner or photo capture is open, and stops it when you close it. Barcodes are decoded in your browser; only the barcode number is sent to our server.
Dailies third parties & processing locations
| Provider | Role | What it receives |
|---|---|---|
| Clerk (US) | Authentication — the same Code Red sign-in used by Lares and Invoicing. | Clerk collects your credentials and email directly. Dailies receives only your user ID. |
| OpenRouter → Google Gemini (US / Google cloud) | AI estimates of foods and nutrients from meal photos. | The meal photo and your optional hint. No account, device, or other personal identifiers. |
| Open Food Facts (France / global) | Barcode product lookup and optional online food search. | The barcode number or search term, sent from our server (not your device). No personal information. Products found are cached in a shared food catalogue that contains no user data. |
| jsDelivr / Fastly (global CDN) | On browsers without built-in barcode detection (e.g. Safari and Firefox), your browser downloads the barcode-decoding library from this CDN. | Your IP address and browser details, as with any web request. No Dailies data. |
| Food Standards Australia New Zealand (AFCD data) | Generic Australian food composition data, loaded into our database in advance. | Nothing — no data about you is sent. |
| Code Red Invoicing (our own product; optional) | Shows your earnings in Dailies if you link the two. | When you link, Dailies sends your sign-in session token to Invoicing to retrieve your API key; afterwards it uses that key to read your income summaries. Dailies sends no journal, health, or other entries to Invoicing. |
| Self-hosted infrastructure (operator infrastructure — not third parties) | The Dailies app and its database run on servers we operate ourselves in Australia. Traffic reaches them through our cloud edge server (Vultr, Sydney), which handles HTTPS and forwards requests over an encrypted private tunnel. | All Dailies data. |
Dailies contains no analytics, advertising, or tracking scripts, sets no cookies of its own (Clerk sets its sign-in session cookies), and sends no emails or push notifications.
Dailies retention & deletion
- Your entries are kept until you delete them or ask us to delete your account. We do not run a fixed retention timer.
- In the app you can delete individual food entries, exercise entries, todos, and recipes; untick habits; clear reflections, weight, mood, and sleep for a day; unlink Invoicing; and regenerate your API token.
- To delete your whole Dailies account or get a copy of your data, email support@codered.lol from your account email. We will action it within 30 days.
Honest disclosure Current beta limitations
Dailies does not yet offer in-app account deletion or data export, so please use the email method above. Removing a checklist item archives it (it is hidden, but its tick history is kept). Deleting your Code Red sign-in (Clerk) account does not automatically delete your Dailies data — email us and we will remove it.
Schedule D — Invoicing (beta)
This schedule adds to Part A the data flows specific to Invoicing, our time-tracking and invoicing web app at invoicing.codered.lol. Invoicing is currently in beta. Read it together with Part A.
Information about you, and about your clients
Invoicing holds information about you and information you enter about your clients. For information about you, Code Red is responsible as described in this policy. For your clients' information, you decide what to enter and are responsible for having the right to use it and for meeting any privacy obligations you have to your clients; we handle it only to provide Invoicing to you.
What Invoicing collects (in addition to Part A)
| Category | What it includes | How it is collected |
|---|---|---|
| Account identifiers | Your Clerk user ID, username, email address, and first and last name, plus the IDs of your linked time-tracking account. | Retrieved from Clerk the first time you sign in. |
| Business profile | Business name, ABN, sender name and email, job title, website, GitHub profile, profile photo, phone number, address, bank account details (bank, BSB, account number, account name), payment terms, and brand colours. | Entered by you during onboarding or in settings. These details are printed on your invoices and invoice emails. |
| Your clients (third-party information) | Contact name, company name, ABN, billing email address, invoice code, and the rates you charge them. | Entered by you. |
| Time entries | Date, start and end times, service, work description, billable status, and rates. | Logged by you in Invoicing or through the API (for example, from an iOS Shortcut). Stored in our self-hosted time-tracking system (Kimai). |
| Invoices | Invoice number, period, line items (dates, work descriptions, hours, rates, amounts), totals, status, sent and paid dates, and the rendered PDF — including draft invoices created in preview mode. | Generated from your time entries. PDFs are stored in our database. |
| Templates & presets | Your email and invoice templates, default rates, and saved service/description presets. | Entered by you. |
| Mail server settings (optional) | SMTP host, port, username, and password (the password is encrypted at rest). Invoice emails are currently sent through Code Red's mail service, so these settings are stored but not used. | Entered by you during onboarding. |
| API key | A personal key that lets integrations (such as iOS Shortcuts or Dailies) log time and read your income summaries. | Generated by Invoicing. |
| Subscription references (if paid plans are introduced) | Stripe customer ID, subscription ID, status, and any promo code used. We never store card numbers. Invoicing is currently free during beta and no payments are taken. | Via Stripe Checkout and Stripe webhooks. |
Important Invoice emails and automatic sending
- When you send an invoice — or if you turn on scheduled invoicing and switch off preview mode — Invoicing emails the invoice, with the PDF attached, to your client's billing email address. Scheduled invoicing builds and sends invoices automatically on the weekday you choose, without a further review step. It is off by default, and starts in preview mode.
- Invoice emails and PDFs include the business profile details listed above (including your bank details) and your client's name, company, ABN, and email.
- Emails are delivered through our own mail server and the Brevo email relay (France/EU).
- Recipient email addresses appear in our server logs so we can troubleshoot delivery.
Invoicing third parties & processing locations
| Provider | Role | What it receives |
|---|---|---|
| Clerk (US) | Authentication — the same Code Red sign-in used by Lares and Dailies. | Clerk collects your credentials directly. Invoicing receives your user ID, email, username, and name. |
| Neon (AWS Sydney, Australia) | Managed Postgres database hosting. | All Invoicing data, including invoice PDFs. |
| Vultr (Sydney, Australia) | Cloud server hosting the Invoicing app, our mail server, and our time-tracking system. | Data passing through and stored by those services. |
| Brevo (France / EU) | Outbound email delivery. | Recipient address and the full invoice email, including the PDF attachment. |
| Kimai (self-hosted on our Vultr server — not a third party) | Time-tracking backend. | Your time entries; your username and email for a time-tracking account; and each client's company name, billing email, and ABN. |
| Stripe (US / global) | Payment processing, only if paid plans are introduced. | Your email and account ID at checkout. Card details are entered on Stripe's pages and never reach our servers. |
| Code Red Dailies (our own product; optional) | Shows your earnings in Dailies if you link the two. | Your API key and income summaries (earned amounts, hours, invoice numbers, client company names, totals, paid dates). |
Crypto payment links (BTCPay) and document archiving (Paperless-ngx) are enabled only for Code Red's own account and are not used for other users' invoices. Invoicing contains no analytics, advertising, or tracking scripts, and uses only essential cookies (Clerk sign-in session cookies and security/session cookies). Invoice emails use embedded images, not remote tracking pixels.
Invoicing retention & deletion
- Your data is kept until you delete it or your account is deleted. We do not run a fixed retention timer.
- In the app you can delete time entries, presets, and draft invoices, and download each invoice PDF. Clients can be deleted while no invoices reference them; deleting a client hides (rather than erases) its record in our time-tracking system.
- Sent invoices cannot be deleted in the app, because they form your business records. Emails already delivered to your clients cannot be recalled.
- To delete your whole Invoicing account (including sent invoices and time-tracking records) or get a copy of your data, email support@codered.lol from your account email. We will action it within 30 days. Keeping copies of your invoices for tax purposes is your responsibility, so download them before you ask us to delete your account.
Honest disclosure Current beta limitations
Invoicing does not yet offer in-app account deletion or bulk data export, so please use the email method above. Deleting your Code Red sign-in (Clerk) account does not automatically delete your Invoicing or time-tracking data — email us and we will remove it.
Schedule E — Future products
As Code Red launches new products and services, each will be added here as its own self-contained schedule describing the additional data, third parties, processing locations, and retention specific to it. The shared terms in Part A apply to every future product unless that product publishes its own separate policy that expressly does not incorporate this one.
For questions about this policy or to exercise your rights, contact support@codered.lol.