Privacy Policy
Last updated: June 29, 2026
Kavaca ("we", "us") helps developers find security and production-readiness issues in apps built with AI coding tools. This policy explains what we collect, how we use it, and the choices you have. Our guiding principle is simple: your source code is read to run the checks and then discarded — we keep the report, not your code, and we use no third-party trackers.
Data controller. Kavaca is operated by JOHO DIGITAL FZE, a free zone establishment registered in the United Arab Emirates, which is the data controller responsible for the personal information described in this policy. For any privacy question or request, contact privacy@kavaca.io.
1. Information we collect
- Account information. When you sign in with GitHub we receive your GitHub username, name, email address, avatar URL, and GitHub user ID.
- Repository access & scanning. With your authorization we use read-only access to fetch a copy of the repository you choose into a temporary workspace, analyze it in memory to run the checks, and delete that copy as soon as the scan finishes. We do not store your source code.
- Scan results. We store the report we generate — the findings, severity, scores, and remediation guidance. Any credentials detected in your code are masked/redacted; we never store or display a raw secret.
- Payment information. Payments are processed by Stripe. We store a record of your purchase (status, amount, timestamps) but never your full card details.
- Acquisition metadata. We record how you arrived (e.g. campaign/UTM parameters) in a first-party cookie and on your account to understand which channels work. This is campaign metadata and a random visitor identifier — it contains no directly identifying information and no cross-site tracking, and we use no third-party advertising or tracking cookies.
- Technical & log data. Standard server logs (such as a request ID) for operating and securing the service. We take care not to log secrets or sensitive query parameters.
2. Cookies
- Session cookie — essential, keeps you signed in.
- kavaca_attribution — a first-party, signed cookie (about 90 days) holding campaign metadata and a random visitor ID so we can attribute sign-ups to the right source. No cross-site tracking. Because this cookie persists a unique identifier, we treat it as personal information once it is associated with your account, and we set it on the basis described in "Legal bases" below.
We do not use third-party advertising or analytics cookies.
3. How we use information
- To provide the service: run scans, generate reports, and show your results.
- To process payments and unlock the full report.
- To understand which acquisition channels convert, in aggregate.
- To operate, secure, debug, and improve the service.
- In addition to the scan results described above (which we retain in identifiable form, associated with your account, as your scan history), we create and retain aggregated or de-identified data derived from scans (for example, statistics about finding types and frequency). Once data is aggregated or de-identified it is no longer personal information, and we may retain and use it indefinitely to operate and improve the Service.
4. Legal bases for processing
Where data-protection law (such as the EU/UK GDPR) applies, we rely on the following legal bases:
- Performance of a contract — to authenticate you, run scans, generate reports, and process payments.
- Legitimate interests — to secure, debug, and improve the Service, and to attribute sign-ups to acquisition channels, balanced against your rights.
- Legal obligation — to comply with applicable law, including tax and accounting requirements for payment records.
- Consent — where required, for any processing that depends on it; you may withdraw consent at any time, without affecting processing already carried out.
5. How we share information
We do not sell your personal information. We share data only with service providers and parties that help us operate:
- GitHub — authentication and read-only repository access.
- Stripe — payment processing. Stripe also acts as an independent controller for its own fraud-prevention and regulatory purposes; that processing is governed by Stripe's own terms and privacy policy.
- Error monitoring — if enabled, an error-tracking provider receives diagnostic data, configured by default to exclude personal information and request contents.
We may also disclose information where required by law, to protect the service, or in connection with a merger, acquisition, or sale of assets.
6. International transfers
We are based outside the EU/UK, and our service providers (including GitHub and Stripe) may process your information in the United States and other countries. Where we transfer personal information across borders, we rely on appropriate safeguards — such as the Standard Contractual Clauses or equivalent mechanisms offered by those providers — to protect it.
7. Data retention & deletion
- Your source code is discarded immediately after each scan completes.
- Your account and reports are retained until you ask us to delete them, or until your account has been inactive for an extended period, after which we may delete them.
- Aggregated or de-identified data derived from scans may be retained indefinitely, as described in Section 3.
- Payment records are retained as required by applicable tax and accounting law.
- GitHub access tokens are encrypted at rest. Signing out / disconnecting revokes our access.
- To request deletion of your account and data, contact us (below).
8. Security
We request the least GitHub access needed, mask detected secrets, encrypt access tokens at rest, and serve the application over TLS. No method of transmission or storage is 100% secure, but we work to protect your information.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Withdrawing consent does not affect processing already carried out on that basis. You can disconnect your GitHub account at any time from the app, or contact us to exercise these rights. If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection authority.
10. Children
Kavaca is not directed to children under 16, and we do not knowingly collect their information.
11. Changes to this policy
We may update this policy from time to time. We will revise the "last updated" date above and, for material changes, provide additional notice.
12. Contact
Questions about privacy? Email privacy@kavaca.io.