Legal

Privacy Policy

Effective date: 2026-09-28. OpsForce is currently in beta; this policy explains in plain English what data we handle and why.

Overview

Who we are

OpsForce is a Salesforce DevOps and data-management service operated by Codality (“Codality”, “we”, “us”). This policy applies to the OpsForce website and application. When your organization uses OpsForce, your organization decides which Salesforce orgs and repositories to connect; we process that data on its behalf to provide the service.

Data

What we collect

  • Account information. Your name and email address, provided through our authentication provider (Clerk) when you sign up or sign in, plus the team you belong to and your role on it.
  • Salesforce org metadata. When you connect a Salesforce org, we retrieve and cache its metadata (for example Apex classes, objects, fields, flows, profiles, and permission sets) so we can compare and deploy it.
  • Salesforce org data records — only when you run a seeding or backup job. In that case we read the records that job needs from your org, and write them to the target you choose.
  • Git repository contents. When you connect a git repository, we read the files and branches needed to compare them with your orgs and, when you ask us to, write commits or branches back.
  • Usage logs. Technical logs such as request times, IP addresses, browser type, error reports, and the actions you take in the app (for example “comparison started”), used to operate, secure, and debug the service.
  • Messages you send us, such as feedback submitted in the app, early access requests, and support emails.

We do not collect or store your Salesforce username or password.

Purpose

How we use it

  • To provide the service: run comparisons, deployments, seeding, backups, and AI-assisted features you request.
  • To authenticate you, manage your team, and enforce plan limits.
  • To keep the service secure, detect abuse, and diagnose problems.
  • To communicate with you about your account, the beta, and changes to the service.
  • To improve OpsForce, using aggregated usage information.

We do not sell your data, we do not use it for advertising, and we do not use your Salesforce or repository content to train AI models.

Security

How we protect credentials

Salesforce and git connections use OAuth. The resulting access and refresh tokens are encrypted at rest with AES-256-GCM and scoped to your team. You can revoke OpsForce’s access at any time by disconnecting the org or repository in the app (which deletes the stored tokens), or by revoking the connected app from within Salesforce or your git provider.

Data is encrypted in transit with TLS. Access to production systems is limited to authorized Codality personnel who need it to operate the service. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you without undue delay.

Third parties

Subprocessors

We share data only with the service providers we need to run OpsForce:

ProviderPurpose
Google Cloud PlatformApplication hosting, database, and storage, located in the United States.
ClerkSign-up, sign-in, and session management.
StripePayment processing, when billing is enabled for your team. We never see or store full card numbers.
Codality AI gatewayRoutes requests for AI features (such as summaries and the research agent) to model providers. Only the content needed for the feature you invoke is sent.

We may also disclose information if required by law, or to a successor in the event of a merger or acquisition, in which case this policy will continue to apply.

Cookies

Cookies and local storage

We use only essential cookies: the session cookies that keep you signed in, set by our authentication provider. We also store small interface preferences (such as your theme and collapsed sidebar sections) in your browser. We do not use advertising or cross-site tracking cookies.

Retention

How long we keep data

  • Team data — connected orgs, repositories, comparisons, deployments, and cached metadata — is deleted when the team is deleted.
  • The source and target content of comparisons is purged automatically after the retention period for your plan; the comparison summary and your review decisions are kept until the team is deleted.
  • OAuth tokens are deleted when you disconnect the org or repository.
  • Usage logs are kept for a limited period for security and debugging, then deleted.
  • Account information is kept while your account is active and deleted when you ask us to delete it, except where we must keep limited records (for example billing records) to meet legal obligations.

Your rights

Access, export, and deletion

You can ask to access, export, correct, or delete your personal data. Team admins can manage members and delete team data from Settings → Team. For anything else, email support@codality.tech and we will respond within 30 days. Depending on where you live, you may also have the right to object to or restrict certain processing and to complain to your local data-protection authority.

Children

Children

OpsForce is a professional tool and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe we have, contact us and we will delete it.

Changes

Changes to this policy

We will update this policy as OpsForce moves out of beta. When we make material changes we will update the effective date above and notify account holders by email or in the app before the change takes effect.

Contact

Contact us

Questions about this policy or your data: support@codality.tech. OpsForce is operated by Codality.

Esc
Actions
Navigate
↑↓navigate↵open
16 results