Privacy Policy
Draft. Fields in brackets are placeholders; a lawyer reviews this before the first paying customer.
The controller of the personal data described here is [company legal name], [CNPJ], [address]. Questions and requests: privacy@kuuhaku.dev. Data protection officer (encarregado): [name and email].
Contents
1. What we collect
| Data | Examples | Source |
|---|---|---|
| Account | Name, email, password hash, organisation, role, sign-in times | You |
| Billing | Plan, subscription status, invoices; card details stay with Stripe | You, Stripe |
| Workspace configuration | Repository URLs, the optional architecture YAML, schedule, the public half of the scan key | You |
| The graph | Route paths, service and model names, queue names, hostnames and ports, environment variable names, dependency names and versions, file paths and line numbers of definitions and calls, commit counts, hotspots, author names from git history | Your repositories, read by the scanner |
| Decisions and text | Confirmations, rejections, owners, descriptions, edited summaries, feedback you send, with who and when | You and your team |
| Technical | IP address, browser, pages visited inside the product, errors, request logs | Your browser, our servers |
Author names from git history are personal data of your contributors. You are the controller for that data and we process it on your instructions; you can ask us to drop author names from a workspace.
2. What we do not collect
- Your source code, apart from up to three lines around each item left for review, which the graph keeps so a reviewer can see the call. A clone exists on our runner only while a scan runs and is deleted when it ends. With the command-line tool, only the graph reaches us.
- Values of environment variables, secrets, tokens or credentials found in code or in
.envfiles. The scanner records key names only, and strips credentials from database connection strings. - Card numbers. Payment data goes directly to Stripe.
- Advertising identifiers or tracking across other sites. We run no advertising and no third-party trackers.
3. Why, and on what legal basis
| Purpose | Legal basis (LGPD art. 7 / GDPR art. 6) |
|---|---|
| Providing the service: accounts, scans, the map, the review inbox, emails about scans and invites | Performance of the contract |
| Billing and invoicing | Contract; legal obligation for tax records |
| Security: sign-in protection, abuse prevention, audit of staff access | Legitimate interest |
| Fixing errors: error reports with request context | Legitimate interest |
| Product analytics inside the product (which screens are used), aggregated | Legitimate interest; you can opt out in settings |
| Suggestions in the review inbox computed by a decision model | Contract. Names, paths, hostnames and the three-line excerpts of review items are sent, never whole files |
| Marketing emails | Consent, withdrawable in every email |
4. Who else processes it
We use these processors under contracts that bind them to this policy:
| Processor | What for | What they see | Where |
|---|---|---|---|
| Contabo | Servers, database, storage | Everything we store, encrypted at rest | USA |
| Stripe | Payments | Email, organisation name, plan, card data they collect themselves | USA, EU |
| Resend | Transactional email | Email address, name, the content of the message | USA |
| TypeSafe AI (Jev) | Suggested answers for review items and repository judgments | Route and call paths, service and queue names, file paths and line numbers, hostnames, environment key names, and up to three lines of code around each review item. No whole files; no personal data beyond author names and commit counts in owner suggestions | USA |
| Sentry | Error monitoring | Error traces, request paths, organisation and workspace ids | USA or EU |
| GitHub, Bitbucket | Where your repositories live | We read with the key you add; they see our runner's requests | Theirs |
We do not sell personal data and do not share it with anyone else, except when the law requires or to protect our rights, in which case we tell you unless forbidden.
5. Where it is stored
Data is stored in the United States. Some processors above are in the United States; transfers rely on standard contractual clauses (GDPR) and the adequacy mechanisms of LGPD art. 33. Customers on the Company plan may run the scanner on their own machines, in which case only the graph crosses borders.
6. How long we keep it
- Imports: the number your plan keeps (3 on Free, 50 on paid plans); older ones are deleted automatically, graph files included.
- Account and workspace data: while the organisation exists, then deleted within 30 days of its deletion.
- Billing records: 5 years, as Brazilian tax law requires.
- Logs and error reports: 90 days.
- Backups: 14 days, then overwritten.
7. Your rights
Under the LGPD (art. 18) and the GDPR (arts. 15 to 22) you may ask us to confirm what we process, access it, correct it, delete it, port it, restrict or object to its processing, and withdraw consent. Most of this is available in the product: export, edit and delete are in the settings. For the rest, write to privacy@kuuhaku.dev; we answer within 15 days. You may also complain to the ANPD (Brazil) or your local supervisory authority.
8. Cookies and local storage
The web application keeps your session token and interface preferences in your browser's local storage, and your language in one cookie (codemap_locale). These are strictly necessary, and none of them tracks you. The landing site uses no cookies. If we add privacy-friendly analytics, this section will say which and how to opt out.
9. Security
Transport encryption everywhere, passwords hashed with bcrypt, scan keys encrypted at rest with a key kept outside the database, access limited by role, staff access logged and shown to you. The full description is on the security page. If a breach affects you, we notify you and the authority within the legal deadlines.
10. Children
The service is for businesses and is not directed at people under 18. We do not knowingly collect their data.
11. Changes
We will announce material changes by email and in the product before they apply. The current version, with its date, is always at this address.