Privacy Policy

Last updated: July 18, 2026

This Privacy Policy describes how CodeShift AI, LLC, a Colorado limited liability company (“CodeShift AI,” “we,” “us,” “our”), collects, uses, and shares information when you use Trellis Communities at trelliscommunities.com (the “Service”).

The short version: we collect what’s needed to run your communities, we share it with the other members of your communities (that’s the product) and with the vendors that host and deliver the Service, and we don’t sell it, don’t run ads, and don’t use tracking cookies.

1. Communities and who sees what

Trellis Communities hosts member-driven communities. Each community is operated by its own administrators (“Organizers”), who decide who may join, what information the community asks for at signup, and how content is moderated. CodeShift AI operates the underlying platform.

This matters for privacy in two ways:

  • Your community sees you. Your profile, name, and email address are visible to the other active members of the communities you belong to (not to the public internet) — including in the member roster, whether or not you ever post. When you post to a community email list, your message — including your name and email address as its sender — is delivered to that community’s subscribers.
  • Organizers see your application. When you apply to join a community, its Organizers and moderators see the information you submit, including any community-specific signup fields, so they can decide on your application.

2. Information we collect

Account information. Your name, email address, and password. Passwords are stored only as salted hashes (bcrypt) — we cannot read them.

Profile information. What you choose to add to your member profile. Depending on your community, profile fields can include: display name, photo, professional credentials, license type/state/number, education, practice name and address, phone, contact email, website, languages, areas of focus, topic/specialty tags, session-fee and insurance details, and optional self-reported demographic information (for example, gender identity, or identifying as BIPOC or LGBTQ+). Beyond your display name these fields are optional; you provide them specifically so they can be shown to the members of your community (see Section 1), and adding one is your consent to display it there. Profiles exist per community.

Community signup information. Communities may ask applicants for additional fields, which vary by community — for example, a professional community may ask for a license number, university, program, or graduation year; a neighborhood community may ask for a street address. This information is defined and used by that community’s Organizers.

Content. Messages you post to community lists, their subjects and attachments, replies, and other material you contribute (events, shared resources).

Community requests. If you request a new community via our public form, we collect the community name, web address, category, timezone, and your founder account details.

Email delivery data. Delivery events for mail we send — sends, bounces, and spam complaints — so we can stop sending to addresses that bounce or complain.

Technical data. IP addresses and request metadata, used transiently for security, rate limiting, and abuse prevention; and server logs, which are configured to redact personal information (email addresses, IPs, tokens) at the point of logging.

We collect all of the above directly from you or from your use of the Service. We do not buy data about you or collect it from data brokers.

3. How we use information

  • To operate the Service — deliver listserv mail to subscribers, maintain community archives and digests, show member directories, process membership applications, and let Organizers run their communities.
  • To send transactional email — verification, password resets, membership and moderation notices.
  • For security and abuse prevention — rate limiting, blocking abusive signups, investigating violations of our Terms.
  • To fix problems — error monitoring and debugging (see Sentry in Section 4).
  • To comply with law.

We do not use your information for advertising, we do not sell or rent it, and we do not use it to train AI models.

4. How information is shared

Within your communities, as described in Section 1.

With service providers that host and deliver the Service on our behalf:

ProviderRoleNotes
VercelApplication hostingRuns the web application.
NeonDatabase hostingStores the Service’s data.
Amazon Web ServicesInbound email receipt, file storageReceives mail sent to community lists; stores attachments and profile photos. Raw inbound mail is deleted after 30 days.
ResendOutbound email deliveryDelivers listserv and transactional mail.
UpstashRate limitingSees only short-lived rate-limit counter keys derived from your email address or IP — no message content.
SentryError monitoringConfigured to exclude personal information: reports are scrubbed of emails, IPs, and tokens, and session replays are masked.
CloudflareDNS and network securitySees request metadata (IP, URL) in transit; does not store message content.

These providers process data only to provide their service to us.

For legal reasons — if required by law, legal process, or to protect the rights, safety, or security of the Service, our users, or others.

In a business transfer — if CodeShift AI is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction; this Policy would continue to apply to it.

We do not share information with advertisers or data brokers, and we do not sell personal information as “sale” is defined under US state privacy laws.

5. Health-related information

Some communities serve licensed professionals, including mental-health professionals, and community discussions may touch on professional casework. The Service is a professional networking platform, not a clinical system: it is not intended for protected health information, members are instructed not to post information identifying a client or patient, and we are not a “covered entity” or “business associate” under HIPAA and do not offer Business Associate Agreements. Please do not submit health information about yourself or others through the Service.

6. Cookies

We use only essential cookies: session cookies that keep you signed in and protect against request forgery, plus short-lived functional cookies (for example, a ten-minute token used during the unsubscribe flow). We do not use advertising, analytics, or cross-site tracking cookies, and we do not respond differently to “Do Not Track” signals because we do not track.

7. Data retention

  • Account and profile data — kept while your account is active.
  • Community content (messages, attachments) — kept as part of the community’s archive while the community exists.
  • Raw inbound email — deleted from storage 30 days after receipt (the processed message remains in the community archive).
  • Delivery events — kept to maintain bounce/complaint suppression and audit delivery problems.
  • Declined or deleted communities — a community that is declined or deleted during setup is removed along with its community data. The founder’s user account persists (it may belong to other communities) and can be deleted on request.
  • Technical data — rate-limit counters expire automatically within hours; server logs are redacted at the point of logging and retained short-term by our hosting provider.

8. Access, correction, and deletion

Email privacy@trelliscommunities.com to request access to, correction of, or deletion of your information. We honor these requests regardless of where you live and will respond within 45 days. Three honest caveats:

  • Email cannot be recalled. Posts already delivered to other members’ inboxes exist in those inboxes; deletion applies to what we store.
  • Community archives. Messages you posted to a community list remain part of that community’s archive — they are part of conversations other members rely on.
  • We may retain limited information where we have a legal obligation or a legitimate security need (for example, bounce-suppression entries so a deleted address doesn’t start receiving mail again, or records of abuse).

You can control ordinary email delivery yourself: per-list delivery settings and unsubscribe links are in every community message, and profile settings control your directory listing content.

9. Security

Data is encrypted in transit (TLS). Passwords are bcrypt-hashed. Application logs redact personal information at the point of logging, and error reports are scrubbed at multiple layers before leaving our systems. Access to production data is limited to the platform operator. No system is perfectly secure — if we learn of a breach affecting your personal information, we will notify you as required by law (including Colorado’s breach-notification statute).

10. Children

The Service is for adults 18 and over. We do not knowingly collect information from anyone under 18; if we learn we have, we will delete it.

11. Where data is processed

The Service is operated from the United States and data is stored and processed there. If you use the Service from outside the US, you understand your information will be processed in the US, where privacy laws may differ from your jurisdiction’s.

12. Changes to this Policy

We may update this Policy. For material changes we will give notice (by email or in-product) at least 14 days before the change takes effect, and we will update the date at the top. Continued use after the effective date constitutes acceptance.

13. Contact

CodeShift AI, LLC
privacy@trelliscommunities.com
850 Oleander St, Castle Rock, CO 80109