Kontrua

Privacy Policy

Last updated: September 2026

1. Data controller

The controller responsible for your personal data under the EU General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés) is:

  • SEND RETURN (SASU, société par actions simplifiée unipersonnelle)
  • 47 rue Vivienne, 75002 Paris, France
  • SIREN 107 437 592 · SIRET 10743759200010 · RCS Paris
  • Contact: [email protected]
  • No data protection officer (DPO) is appointed; privacy requests go to the address above.

2. What we collect

When you use Kontrua we process:

  • Account data — your email, and GitHub/GitLab user ID and login (authentication)
  • Operational measurements — random demo identifier, audit outcome, workspace activation, correction acceptance and verification, paid invoice and renewal identifiers, and model usage counts. These records contain no repository source or prompt text.
  • Repository metadata — repository names, installation/webhook configuration, run history
  • Audit and run data — supported claims, findings, proposed changes, and generated document outputs
  • Billing data — plan, subscription status, and billing identifiers (card data is handled solely by Stripe; we never see raw card numbers)
  • Technical data — IP address, request logs, and error diagnostics for security and reliability
  • Optional website analytics — public-page visits through Umami and PostHog, only after you allow analytics

3. Repository content and analytics

Kontrua fetches repository files to audit supported references and prepare proposed changes. Correction runs can send selected repository context to Anthropic for generation. During hosted generation, Cloudflare Workers AI checks narrative sentences through Jev by default unless disabled for the repository. It receives those sentences and candidate repository paths, script and dependency names. If Jev correction selection is enabled, it also receives the broken reference, surrounding lines and the first 30 lines of candidate files. We do not persist a complete copy of your repository, but we do store audit findings, correction summaries, and full generated document outputs with run records. Those outputs can contain repository content. Optional analytics is separate from repository audits. Umami and PostHog load only after consent on supported public pages. We exclude private dashboard and authentication pages, URL parameters, fragments, referrers and repository content. Session recording, automatic click capture and identified user profiles are disabled. PostHog uses a temporary identifier held in page memory rather than a persistent analytics cookie.

You can decline without losing any service features, or change your choice using Analytics preferences at the bottom of the page. Your choice is saved in this browser for 180 days. Essential sign-in and evaluation-handoff cookies remain separate.

4. Legal basis for processing

  • Contract (Art. 6(1)(b)) — providing the service: authentication, running generations, opening pull requests, notifications.
  • Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, and limited operational measurements of service delivery.
  • Legal obligation (Art. 6(1)(c)) — retaining billing/tax records.
  • Consent (Art. 6(1)(a)) — optional website analytics and optional emails, where applicable; withdrawable at any time.

5. How we use your data

Data is used to provide, secure, and improve Kontrua: triggering runs, proposing repository changes, sending run notifications if enabled, billing, support, and measuring website and product use. We do not sell your data or share it for third-party marketing.

6. Sub-processors

The application is configured to use these services for the listed purposes:

  • DigitalOcean — application hosting (Frankfurt, EU)
  • Supabase — application database (EU region)
  • Cloudflare R2 — encrypted database backups (EU jurisdiction)
  • Stripe — payment processing
  • GitHub / GitLab — source access & pull requests (per your connection)
  • Anthropic — LLM generation (US)
  • Cloudflare Workers AI — narrative checks during hosted generation and optional correction selection through Jev
  • Resend — transactional email
  • Inngest — background job processing
  • Upstash — rate-limiting cache
  • Sentry — error monitoring
  • Umami — cookieless analytics
  • PostHog — product analytics (EU ingestion endpoint)
  • Notion — document publishing, if you connect a workspace
  • Slack / Discord or your configured webhook destination — run notifications, if enabled

7. International transfers

Some processors (e.g. Anthropic) process data in the United States. Such transfers rely on the European Commission’s Standard Contractual Clauses and/or the EU–US Data Privacy Framework, together with additional safeguards where required.

8. Data retention

A functional handoff cookie remembers your evaluated repository and PR for seven days so sign-in can continue the evaluation. Operational measurements linked to a workspace follow its retention and deletion; anonymous demo measurements are removed after 90 days.

Removing GitHub App access pauses repository work but retains its saved history and configuration in your workspace. Use Remove repository in the repository page's Danger zone to delete that repository data.

Generated output content is cleared 90 days after a run completes; run summaries remain while the workspace exists. Webhook delivery logs are pruned after 90 days and security audit logs after 365 days. Repository removal also deletes its run records, outputs, API tokens, findings, proposals, webhook logs and linked operational measurements.

Deleting your account removes your user record, password-reset tokens and linked account logs. Workspaces where you are the only member are deleted with their repository data, after subscription cancellation succeeds. Shared workspaces and their history remain with other members; you must transfer ownership of any shared workspace you own before deleting your account.

Deletion stops Kontrua processing the removed repositories. It does not uninstall the GitHub App, remove provider-side webhooks or erase existing pull requests, comments or documents on GitHub, GitLab or Notion. You can remove those connections and outputs in the relevant service.

The database is backed up every night. Each backup is encrypted before it leaves our systems and is deleted after 35 days.

Deletion from the active application database does not immediately erase those backups or records held by processors. Billing records required by law are retained separately (French accounting records generally for 10 years). Contact us for questions about processor-held data.

9. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing. To exercise them, email [email protected]. We respond within one month.

You may also lodge a complaint with your supervisory authority. In France, this is the CNIL (www.cnil.fr).

10. Contact

Questions about this policy? Email [email protected].