Your data is yours. We take only as much as the service cannot run without, exactly that much. We do not sell your data to anyone, and we keep no third-party advertising on the site.
What We Collect
What you give
Name and email (to open an account)
Password (stored as an encrypted hash, we cannot see the original password)
The prompts you write and the files of the apps you create
Your own API Key, given optionally (stored with AES-256-GCM encryption)
Profile photo, public name (@handle), your bio and links (if you add them)
Site settings (Analytics ID, Pixel ID, custom head code) and your own domain (if you add one)
What is stored automatically
Token usage records (which Model took how many Tokens), kept as long as the account exists
Login session, when you last visited, and which way you signed in (email or Google)
Your referral code, and whose link you came through, if any
Email sending logs (which mail went out when)
We do not collect your NID, bank details or card details. When a payment is made, it is completed on the payment gateway's own secure page. When the manual bKash option is on, the money goes from your own bKash app; we then keep only the transaction TrxID and (if you give it) the sender number, nothing more.
Site Inbox Submissions (Business Hosting)
Whatever a visitor types into a form on a site with the Business or Commerce hosting plan (name, phone, address, message) is stored in that site owner's inbox. The site's owner sees it. We can look too when support needs it, but every such look is logged and the owner can see the log in the dashboard; we never sell it, use it for advertising, or train AI on it. The owner can delete any submission or export them as CSV. The visitor's IP address is not stored with a submission, only a salted hash used to stop abuse. The visitor-count chart follows the same rule: a hash, never the IP.
On Commerce hosting, if the owner has set up their own SMS gateway, the buyer's phone number and the order text go to that gateway; which gateway is the owner's choice, not ours.
The auto-reply a visitor receives goes through our email provider, and the visitor's email address stays in our send log for 90 days, then clears itself.
Why We Use It
To run the service (building, saving and previewing your apps)
To keep Token records and to prevent fraud
To send essential emails (verification, password reset, order updates)
To send account and product emails: getting-started tips, Token pack offers, a warning before a free app is moved away, a weekly count of how many people opened what you built, and the occasional word about new features. If you no longer want these, the toggle in Settings or the link under every such mail stops them with one click; one line to support@banglacodes.com works too. The essential emails (verification, password reset, order) keep coming as long as the account exists, because the account cannot run without them.
To understand and improve the quality of the service
Third Parties
Those we use to run the service:
AI Model providers: Google Gemini, OpenRouter, Groq, Cloudflare Workers AI and Z.ai (GLM). Your prompt (and any image you attach with it) goes to them to generate the response. OpenRouter alone gathers many companies' Models in one place (including Anthropic's Claude, OpenAI's GPT, DeepSeek and Moonshot's Kimi), so a prompt that goes through OpenRouter also reaches the company behind that Model. If you add your own API Key, your prompt goes directly to that company, not through our Key. Each one's own privacy policy applies.
Acumbamail (Resend or Cloudflare Email as fallback): to send emails (your name, email address and the text of the mail go to them)
Cloudflare: hosting and security, and the prompts for AI-generated images also go to Cloudflare Workers AI
Amazon Web Services: the once-a-day backup copy, details in the "Backups" section below
Google (Login): if you use "Login with Google", your name and email come from Google, and Google learns that you signed in to BanglaCodes
GitHub: only if you connect GitHub yourself do your app's files go to your repo; the GitHub token you give is stored encrypted
Pexels: when you search for images in the builder, your search words go to Pexels
Google Fonts and fonts.maateen.me: the site's fonts load from there, so those two servers see your browser's IP address
Google Analytics: statistics on how many times a page was viewed (not the content you write)
Stripe: to complete card payments (card details go directly to Stripe, we do not see them)
SSLCommerz: to complete bKash, Nagad, Rocket, local card and bank payments (the payment details go directly to SSLCommerz, we do not see them)
Beyond this, your data is not shared with anyone. There is no third-party advertising network on our site.
Cookie
We do not track you. We only use Google Analytics to see what people do on the site, such as how many times a page was viewed. That is all, just this much.
Essential cookie: keeps your login session (httpOnly, 30 days).
Sign-in cookie: when you press "Login with Google", a cookie named bdcode_oauth_state is set for 10 minutes, so the link coming back from Google can be matched to the browser that started it. It clears itself once that is done.
Analytics cookie: Google Analytics keeps two cookies whose names start with _ga (for at most 2 years), so that a return visit from the same browser is not counted as a new person. They hold no name or email, only a random number. If cookies are off in your browser or an ad blocker is on, they are not set, and the site still works.
No advertising cookie. The apps, prompts or chat text you create never go to Analytics.
Share links or the secret code of a password reset are not sent to Analytics, those are removed beforehand.
IP Address
To prevent abuse (such as repeatedly entering a wrong password from the same place or opening countless accounts), your IP address is stored temporarily, for at most 8 days. After that it is deleted automatically. When counting how many people visited a shared app, the IP is not stored directly, instead a hash is kept, which cannot be reversed without our server key.
Your Rights
You can download your own app or move it to GitHub at any time
If you delete an app yourself, you can bring it back from the "deleted apps" list for 30 days, after which it goes for good
Apps on a free account are moved to "deleted apps" automatically 60 days after the last edit and kept there for a year, after which they are deleted for good; apps on a Pro account remain as long as the account exists
A deleted app keeps its newest 5 versions with it; the older versions are not kept
If you want to delete your account and all data, email support@banglacodes.com or let us know at BanglaCodes Facebook group, it will be deleted within 7 working days
If there is incorrect information, you can request a correction
Security
Passwords are stored with scrypt hashing, API Keys with AES-256-GCM encryption. The entire site runs on HTTPS. Still, remember that no one can guarantee one hundred percent security on the internet.
Backups and where your data is kept
So that one company closing an account cannot wipe out a thousand people's work at once, copies of the data are kept in two places. You should know this, because it means a copy of your data leaves the country.
The running site, the images and the published pages live on Cloudflare. A backup is taken there every 6 hours.
Beyond that, once a day a copy goes to the Mumbai region of Amazon Web Services, which is in India. The newest 10 copies are kept and older ones are removed automatically.
A copy of the images and the published site files goes there too. That copy is never removed automatically, because the job of a disaster copy is to remember what was lost.
None of the copies is open for anyone to browse, all of them sit encrypted, and they are used only for bringing the site back.
If you delete your account, everything goes from the running servers. The copies left in backups clear themselves within 10 days, and the file copy held outside is removed by hand along with your request.
Use by Children
This service is not for those under 13 years of age. It is best used under the supervision of a guardian.
Contact
Any question about privacy: support@banglacodes.com · BanglaCodes Facebook group NShamimPRO, 183/3, Tejkunipara, Tejgaon, Dhaka 1215, Bangladesh