Privacy Policy

Last updated 5 October 2026 · Version 0.1 · Written for the LGPD (Brazil) and the GDPR

Draft. Fields in brackets are placeholders; a lawyer reviews this before the first paying customer.

The controller of the personal data described here is [company legal name], [CNPJ], [address]. Questions and requests: privacy@kuuhaku.dev. Data protection officer (encarregado): [name and email].

Contents

  1. What we collect
  2. What we do not collect
  3. Why, and on what legal basis
  4. Who else processes it
  5. Where it is stored
  6. How long we keep it
  7. Your rights
  8. Cookies and local storage
  9. Security
  10. Children
  11. Changes

1. What we collect

DataExamplesSource
AccountName, email, password hash, organisation, role, sign-in timesYou
BillingPlan, subscription status, invoices; card details stay with StripeYou, Stripe
Workspace configurationRepository URLs, the optional architecture YAML, schedule, the public half of the scan keyYou
The graphRoute paths, service and model names, queue names, hostnames and ports, environment variable names, dependency names and versions, file paths and line numbers of definitions and calls, commit counts, hotspots, author names from git historyYour repositories, read by the scanner
Decisions and textConfirmations, rejections, owners, descriptions, edited summaries, feedback you send, with who and whenYou and your team
TechnicalIP address, browser, pages visited inside the product, errors, request logsYour browser, our servers

Author names from git history are personal data of your contributors. You are the controller for that data and we process it on your instructions; you can ask us to drop author names from a workspace.

2. What we do not collect

3. Why, and on what legal basis

PurposeLegal basis (LGPD art. 7 / GDPR art. 6)
Providing the service: accounts, scans, the map, the review inbox, emails about scans and invitesPerformance of the contract
Billing and invoicingContract; legal obligation for tax records
Security: sign-in protection, abuse prevention, audit of staff accessLegitimate interest
Fixing errors: error reports with request contextLegitimate interest
Product analytics inside the product (which screens are used), aggregatedLegitimate interest; you can opt out in settings
Suggestions in the review inbox computed by a decision modelContract. Names, paths, hostnames and the three-line excerpts of review items are sent, never whole files
Marketing emailsConsent, withdrawable in every email

4. Who else processes it

We use these processors under contracts that bind them to this policy:

ProcessorWhat forWhat they seeWhere
ContaboServers, database, storageEverything we store, encrypted at restUSA
StripePaymentsEmail, organisation name, plan, card data they collect themselvesUSA, EU
ResendTransactional emailEmail address, name, the content of the messageUSA
TypeSafe AI (Jev)Suggested answers for review items and repository judgmentsRoute and call paths, service and queue names, file paths and line numbers, hostnames, environment key names, and up to three lines of code around each review item. No whole files; no personal data beyond author names and commit counts in owner suggestionsUSA
SentryError monitoringError traces, request paths, organisation and workspace idsUSA or EU
GitHub, BitbucketWhere your repositories liveWe read with the key you add; they see our runner's requestsTheirs

We do not sell personal data and do not share it with anyone else, except when the law requires or to protect our rights, in which case we tell you unless forbidden.

5. Where it is stored

Data is stored in the United States. Some processors above are in the United States; transfers rely on standard contractual clauses (GDPR) and the adequacy mechanisms of LGPD art. 33. Customers on the Company plan may run the scanner on their own machines, in which case only the graph crosses borders.

6. How long we keep it

7. Your rights

Under the LGPD (art. 18) and the GDPR (arts. 15 to 22) you may ask us to confirm what we process, access it, correct it, delete it, port it, restrict or object to its processing, and withdraw consent. Most of this is available in the product: export, edit and delete are in the settings. For the rest, write to privacy@kuuhaku.dev; we answer within 15 days. You may also complain to the ANPD (Brazil) or your local supervisory authority.

8. Cookies and local storage

The web application keeps your session token and interface preferences in your browser's local storage, and your language in one cookie (codemap_locale). These are strictly necessary, and none of them tracks you. The landing site uses no cookies. If we add privacy-friendly analytics, this section will say which and how to opt out.

9. Security

Transport encryption everywhere, passwords hashed with bcrypt, scan keys encrypted at rest with a key kept outside the database, access limited by role, staff access logged and shown to you. The full description is on the security page. If a breach affects you, we notify you and the authority within the legal deadlines.

10. Children

The service is for businesses and is not directed at people under 18. We do not knowingly collect their data.

11. Changes

We will announce material changes by email and in the product before they apply. The current version, with its date, is always at this address.