Privacy Policy
Effective September 7, 2026
The short version
- CodeHound reads the Promotions category of your Gmail with read-only access, on your iPhone.
- Emails are parsed in memory on your phone and discarded. Only the deals it finds (store, code, offer, deadline, subject line, a short snippet) are saved, on your phone.
- There is no CodeHound server. Nothing about you or your email is sent to us or to anyone else. No analytics.
- The app shows a small banner ad from Google AdMob, requested as non-personalized. The ad service never receives your email, your deals or your Gmail address.
- Signing out revokes CodeHound's access and deletes the saved deals. Deleting the app deletes everything.
1. Who this policy covers
This policy describes how the CodeHound app for iPhone ("CodeHound", "the app", "we") handles information, including information received from Google APIs. CodeHound is developed and published by Rick Conner, an individual developer. You can reach us at support@codehound.app.
This policy also covers the website codehound.app, which is a static site that sets no cookies and runs no analytics or tracking scripts.
2. What information CodeHound accesses
CodeHound works only with data you explicitly authorise through Google's sign-in and consent screen.
Google account and Gmail data
| Data | How it is obtained | Why |
|---|---|---|
| Your Gmail address | From the Gmail API profile endpoint after you sign in | Shown in Settings so you can see which account is connected |
| OAuth access and refresh tokens | Issued by Google when you grant access | To call the Gmail API as you, without asking you to sign in every time |
| Email messages in the Promotions category | Gmail API, read-only scope (https://www.googleapis.com/auth/gmail.readonly), using the search category:promotions limited to your chosen look-back window (7 to 90 days) |
To find promo codes, offers and deadlines |
CodeHound requests a single Google permission: read-only access to Gmail. It never asks for permission to send, modify, delete or label mail, or to access any other Google service. Although the read-only permission technically covers your whole mailbox, the app only ever requests messages that Gmail has filed in the Promotions category; it does not fetch your other mail.
Information CodeHound does not collect
CodeHound has no user accounts of its own, no server, and no analytics. It does not collect your name, contacts, location, usage statistics or crash reports, and it does not use cookies. The only third-party code in the app is Google's advertising SDK, described in section 5, which never has access to your Gmail data.
3. How CodeHound uses this information
Every use of your Google user data happens on your iPhone and serves one user-facing feature: the deals list you see in the app.
- The app asks Gmail for the list of messages in the Promotions category within your look-back window, then downloads each message over an encrypted connection directly from Google to your phone.
- Each message is converted to plain text and scanned for a store name, promo codes, offers (such as "20% off" or "free shipping") and end dates.
- The full email is then discarded from memory. CodeHound keeps only the extracted deal: store name and domain, the code, the offer, the deadline, the email's subject line and date, Gmail's message identifier (so the app can open the original email in Gmail for you), and a one-line snippet of the text around the code so you can judge whether it was read correctly.
- Deals from the same store with the same code are merged, and expired deals are hidden unless you choose to show them.
CodeHound does not use your Google user data for advertising (the banner ads described in section 5 are selected without it), does not sell it, does not use it to build profiles, and does not use it to develop, improve or train any machine-learning or artificial-intelligence models. No human at CodeHound can read your data, because it never leaves your device.
4. Where the information is stored
- OAuth tokens are stored in the iOS Keychain on your device, marked as accessible only on that device and never migrated to another device. They are not included in backups.
- Extracted deals and your settings are stored in a single file in the app's private storage on your device. Like most app data, this file may be included in your iPhone backups (iCloud or a computer backup), which are controlled by you and protected by Apple, not by CodeHound.
- Email contents are held only in memory while a scan runs and are never written to disk.
CodeHound operates no servers and stores no Google user data anywhere other than on your device.
5. Advertising
CodeHound is free and is supported by a small banner advertisement in the deals list, served by Google AdMob (Google LLC). The advertising SDK runs in a separate part of the app and has no access to your email, your deals, your Gmail address or your OAuth tokens. Google user data is never used to select, target or measure ads.
- Non-personalized only. Every ad request is flagged as non-personalized, on every device and in every region. Ads are chosen by context (the app and the ad slot), not by a profile of you. CodeHound never asks for permission to track you across apps and does not use the advertising identifier.
- What the ad service receives. To serve an ad and detect fraud, Google's SDK sends your IP address (from which a rough location may be inferred), basic device and app information (device model, iOS version, language, app bundle id, the ad unit), and whether the ad was shown or tapped. Attribution for taps uses Apple's privacy-preserving SKAdNetwork. Google's handling of this data is described in the Google Privacy Policy and how Google uses information from apps that use its services.
- Consent. In the European Economic Area, the United Kingdom and Switzerland, a consent form from Google is shown before any ad is requested, and ads are only requested once you have answered or the law does not require a form. You can change your choice at any time in Settings → Privacy options.
- Your controls. You can adjust Google's ad settings at adssettings.google.com.
6. Sharing and disclosure
CodeHound does not share, transfer, sell or disclose your Google user data or any other personal data to anyone. The app makes network requests only to Google: to sign in, to read Gmail, to revoke access when you sign out, and to request ads as described in section 5. The Gmail requests and the ad requests are separate, and the ad requests carry none of your Gmail data.
Because no data is ever transmitted to us, we hold nothing that could be disclosed in response to a legal request, transferred in a sale of the business, or exposed in a breach of our systems.
7. Google API Services User Data Policy and Limited Use
CodeHound's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, CodeHound:
- only uses Gmail data to provide and improve the user-facing deals list that is prominent in the app;
- does not transfer Gmail data to anyone, except as necessary to comply with applicable law;
- does not use Gmail data for serving advertisements;
- does not allow humans to read Gmail data;
- does not use Gmail data to develop, improve or train generalised or non-personalised AI or machine-learning models.
8. Retention and deletion
- Sign out (Settings → Sign out) asks Google to revoke CodeHound's token, deletes the token from the Keychain and deletes every saved deal from the device.
- Deleting the app removes the deals file and the Keychain entry.
- Revoking access from Google at myaccount.google.com/permissions stops the app from reading your mail immediately; the next scan will fail and sign you out.
- Each scan replaces the previous results, so deals older than your look-back window disappear on the next refresh.
Since we never receive your data, there is nothing for us to delete on our side. If you have any concern, email support@codehound.app and we will help.
9. Security
All connections to Google use HTTPS. Sign-in uses OAuth 2.0 with PKCE in the system's secure web session, so your Google password is entered only on Google's own pages and never seen by the app. Tokens are protected by the iOS Keychain and by your device passcode. The advertising SDK is confined to the ad slots and is never handed email content, deals or tokens.
10. Children
CodeHound is not directed at children under 13 (or the equivalent minimum age in your jurisdiction) and does not knowingly collect information from them. Google accounts for children are managed through Family Link, and the app has no special handling for them.
11. Your rights
Depending on where you live you may have rights to access, correct, delete or export personal data about you. Because all of your data lives on your device under your control, you can exercise these rights directly: view the deals in the app, delete them by signing out or removing the app, and revoke access through your Google account. If you believe we hold any data about you, contact us and we will respond promptly.
12. Changes to this policy
If CodeHound's handling of data ever changes, this page will be updated and the effective date at the top revised. Material changes that affect Google user data will also be reflected on Google's consent screen when you next grant access.
13. Contact
Rick Conner
Email: support@codehound.app
Web: codehound.app