← Back to home

Privacy Policy

Last updated: June 29, 2026

Kavaca ("we", "us") helps developers find security and production-readiness issues in apps built with AI coding tools. This policy explains what we collect, how we use it, and the choices you have. Our guiding principle is simple: your source code is read to run the checks and then discarded — we keep the report, not your code, and we use no third-party trackers.

Data controller. Kavaca is operated by JOHO DIGITAL FZE, a free zone establishment registered in the United Arab Emirates, which is the data controller responsible for the personal information described in this policy. For any privacy question or request, contact privacy@kavaca.io.

1. Information we collect

2. Cookies

We do not use third-party advertising or analytics cookies.

3. How we use information

4. Legal bases for processing

Where data-protection law (such as the EU/UK GDPR) applies, we rely on the following legal bases:

5. How we share information

We do not sell your personal information. We share data only with service providers and parties that help us operate:

We may also disclose information where required by law, to protect the service, or in connection with a merger, acquisition, or sale of assets.

6. International transfers

We are based outside the EU/UK, and our service providers (including GitHub and Stripe) may process your information in the United States and other countries. Where we transfer personal information across borders, we rely on appropriate safeguards — such as the Standard Contractual Clauses or equivalent mechanisms offered by those providers — to protect it.

7. Data retention & deletion

8. Security

We request the least GitHub access needed, mask detected secrets, encrypt access tokens at rest, and serve the application over TLS. No method of transmission or storage is 100% secure, but we work to protect your information.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Withdrawing consent does not affect processing already carried out on that basis. You can disconnect your GitHub account at any time from the app, or contact us to exercise these rights. If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection authority.

10. Children

Kavaca is not directed to children under 16, and we do not knowingly collect their information.

11. Changes to this policy

We may update this policy from time to time. We will revise the "last updated" date above and, for material changes, provide additional notice.

12. Contact

Questions about privacy? Email privacy@kavaca.io.