Quick Answers
This summary is here for readability. The full notice below is authoritative.
Do you store my source code?
No. Your source code is not written to a database, disk, or other permanent storage on RemObjects servers.
Is my source code used to train AI models?
No. RemObjects does not train AI models on your code, and OpenAI’s business terms do not allow OpenAI to use customer content to develop or improve its services unless the customer explicitly agrees to that use.
Who can see my data?
Access to the production database is limited to authorzied and trusted RemObjects Software personal. The CodeBot database contains only login names, user ids and usage records, no personal information. It does not contain your source code or conversations.
Where does my code go?
CodeBot sends the code and prompts needed to answer your request to OpenAI for model processing. OpenAI may temporarily process or cache data as described below. RemObjects does not store your code or converdsations anywhere else.
What do you store about me?
We store your login name, RemObjects user id, and usage records such as request counts, token usage, and costs.
Can I delete my data?
Yes. Email support@remobjects.com and we will handle the request.
Who We Are
RemObjects Software. About.
Privacy contact: marc hoffman de garcía: Contact.
This notice covers the CodeBot Server service, as used by Codebot for Delphi, only.
For RemObjects’ general privacy practices, see the RemObjects Privacy Policy.
Your Source Code
CodeBot is an AI-assisted developer tool. In order to answer a request, CodeBot sends the relevant prompt, source code, and session context to OpenAI for processing. That transfer is necessary for the service to work.
RemObjects does not use your source code to train AI models. OpenAI’s business terms state that OpenAI will not use customer content to develop or improve its services unless the customer explicitly agrees to that use.
- Your source code is sent to OpenAI over HTTPS.
- It is held in RemObjects server memory only while your request is being processed.
- It is not written to RemObjects databases, disk, or other permanent server storage.
- It may be temporarily cached by OpenAI for performance. OpenAI’s prompt caching documentation describes in-memory caching as typically active for 5 to 10 minutes of inactivity, up to a maximum of one hour, and extended caching as up to 24 hours when enabled.
- It may be retained by OpenAI longer when required for safety, abuse monitoring, legal compliance, or similar obligations under OpenAI’s terms and policies.
OpenAI
We use OpenAI as our AI provider. When you use CodeBot:
- Your prompts, relevant source code, and session context are sent to OpenAI to process your request.
- We send OpenAI a one-way hash of your email address rather than the email address itself. OpenAI cannot reverse this hash. RemObjects can use it to identify the account associated with a request if OpenAI flags a policy or abuse issue.
- We may send a session-scoped cache key to improve performance and reduce cost through OpenAI’s prompt caching system. This cache key does not identify you beyond the hashed identifier described above.
- Data may be processed by OpenAI in the United States. OpenAI’s Data Processing Addendum includes standard contractual clauses and other terms for international data transfers where applicable.
OpenAI policy references: OpenAI Services Agreement, OpenAI Data Processing Addendum, and OpenAI Prompt Caching documentation.
What We Collect
| Data | Why |
|---|---|
| Email address | Account identity |
| Billing records | Amount and type of CodeBot products purcased only, for usage accounting |
| Usage records, including request type, timing, token counts, and cost | Billing, service operation, capacity planning, and abuse prevention |
| Session IDs, such as random identifiers or GUIDs | Correlating requests within a session |
| Skills | Server-side skills you create are stored in S3 |
We do not store conversation content, chat history, or source code in our production database.
Server-Side Diagnostic Logs
Our servers log operational activity for debugging and service operation. Logs may include your email address, session ID, request metadata, request size, request type, timing, and similar operational information. The content of your prompts and source code is not logged by RemObjects server-side diagnostics.
Logs are currently stored in AWS RDS.
Local Logs On Your Machine
The CodeBot IDE plugin writes diagnostic logs to your machine at:
%LOCALAPPDATA%\Temp\RemObjects CodeBot for Delphi\Logs\
Each session has logs in its own subfolder. These local logs may contain the full session, including source code and chat content, as raw JSON, HTML, images that are part of the interactive chat, and text.
These logs stay on your machine. RemObjects cannot access them unless you choose to share them with us, for example when contacting support.
Hosting And Sub-Processors
| Provider | Role | Location | Notes |
|---|---|---|---|
| OpenAI | United States and other locations used by OpenAI | Governed by OpenAI business terms and Data Processing Addendum | |
| AWS | CodeBot Server | US East | Used services: EC2, RDS, S3 |
We will update this table as our infrastructure changes.
License validation uses RemObjects’ standard licensing system, described in the RemObjects Privacy Policy.
Enterprise Dedicated Servers
Some companies purchase a dedicated CodeBot deployment, such as a VM or container used only by that company. In that case, interactions and source code pass through that dedicated server and then to OpenAI. They do not pass through RemObjects infrastructure shared with other CodeBot customers.
Authentication and billing remain centralized. User email addresses and usage records remain in the shared RemObjects database.
Data Retention
| Data | Retained for |
|---|---|
| Email and billing records | Lifetime of your account, and as required by law |
| Usage records | As needed for billing, service operation, accounting, and legal compliance |
| Session data | Server memory only while processing the request; not persisted by RemObjects |
| Source code | Not retained by RemObjects |
| Server diagnostic logs | As needed |
| Local diagnostic logs | On your own machine until you delete them |
Who Has Access
Two people at RemObjects have access to the production database: marc hoffman de garcía (Chief Architect) and David Millington (CodeBot for Del;phi Team Lead). That database contains accunt names (often the email address), user ids, and purchase and usage records. It does not contain code or conversations. Access is for operations and support.
Security
- All network connections use HTTPS.
- The production database is encrypted at rest by the hosting provider.
- Production database access is limited to the people named above.
- If a data breach affects your personal data, we will notify affected users and relevant authorities within the time required by applicable law, including 72 hours where GDPR requires it.
Your Rights
GDPR gives EU users the right to access, correct, export, or delete their personal data, and to restrict or object to processing.
Wherever you are, you can ask us to delete your account and associated personal data, subject to legal and accounting obligations that may require limited retention.
Email support@remobjects.com to exercise these rights.
Children
CodeBot is a developer tool for professional use. It is not intended for anyone under 13, or under 16 in the EU.
Changes To This Notice
We will update this notice as our practices change, including when we add hosting regions, move infrastructure, or add or change sub-processors. The page will always show the date it was last updated.
Contact
RemObjects Software. About.
Privacy contact: marc hoffman de garcía: Contact.
Legal Basis For Processing Under GDPR
| Data | Legal basis |
|---|---|
| Email address | Contract performance, because it is needed to provide the CodeBot service |
| Billing records | Legal obligation and contract performance |
| Usage records | Contract performance and legitimate interest in operating, securing, and billing for the service |
| Session data, processed transiently | Contract performance |
| Source code sent to OpenAI for processing | Contract performance |
| Email address and metadata in diagnostic logs | Legitimate interest in service operation, debugging, diagnosis, and abuse prevention |
