Kontrua

Privacy Policy

Last updated: July 2026

1. Data controller

The controller responsible for your personal data under the EU General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés) is:

  • SEND RETURN (SASU, société par actions simplifiée unipersonnelle)
  • 47 rue Vivienne, 75002 Paris, France
  • SIREN 107 437 592 · SIRET 10743759200010 · RCS Paris
  • Contact: [email protected]
  • No data protection officer (DPO) is appointed; privacy requests go to the address above.

2. What we collect

When you use Kontrua we process:

  • Account data — your email, and GitHub/GitLab user ID and login (authentication)
  • Repository metadata — repository names, installation/webhook configuration, run history
  • Billing data — plan, subscription status, and billing identifiers (card data is handled solely by Stripe; we never see raw card numbers)
  • Technical data — IP address, request logs, and error diagnostics for security and reliability

3. What we do not collect

Kontrua does not store your source code. Files are fetched at run time to generate context and documentation, then discarded — they are not persisted after a run completes. We use no advertising cookies and set no persistent tracking identifier. Our product analytics (Umami) are cookieless and aggregated.

4. Legal basis for processing

  • Contract (Art. 6(1)(b)) — providing the service: authentication, running generations, opening pull requests, notifications.
  • Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, and aggregated product analytics.
  • Legal obligation (Art. 6(1)(c)) — retaining billing/tax records.
  • Consent (Art. 6(1)(a)) — optional emails, where applicable; withdrawable at any time.

5. How we use your data

Data is used exclusively to provide and secure Kontrua: triggering runs, committing generated context to your branch via pull requests, sending run notifications if enabled, billing, and support. We do not sell your data or share it for third-party marketing.

6. Sub-processors

We rely on the following processors, each bound by a data processing agreement:

  • DigitalOcean — hosting & managed database (Frankfurt, EU)
  • Stripe — payment processing
  • GitHub / GitLab — source access & pull requests (per your connection)
  • Anthropic — LLM generation (US)
  • Resend — transactional email
  • Inngest — background job processing
  • Upstash — rate-limiting cache
  • Sentry — error monitoring
  • Umami — cookieless analytics

7. International transfers

Some processors (e.g. Anthropic) process data in the United States. Such transfers rely on the European Commission’s Standard Contractual Clauses and/or the EU–US Data Privacy Framework, together with additional safeguards where required.

8. Data retention

We keep account and repository data for as long as your account is active. You can delete your account at any time from the dashboard; on deletion we remove your user record and revoke active webhooks within 30 days, except data we must retain by law (e.g. Stripe billing records, kept for 10 years under French commercial law).

9. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing. To exercise them, email [email protected]. We respond within one month.

You may also lodge a complaint with your supervisory authority. In France, this is the CNIL (www.cnil.fr).

10. Contact

Questions about this policy? Email [email protected].