Privacy Policy

Effective date: [DATE]

This policy explains what data Reprova collects, how we use it, and the choices you have. Reprova is operated by [Your Legal Entity] (“Reprova”, “we”, “us”). The defining fact of our design: the rows in your database never reach us — they are extracted, anonymized, and encrypted inside your own infrastructure. We store metadata about your errors, not your data.

1. The short version

2. Information we collect

Account information

When you create a tenant we collect your email address, a team/tenant name, and a securely hashed password. We generate session tokens to keep you logged in.

Error metadata sent by the SDK

When your application captures an error, the Reprova SDK sends us metadata about it: the error type and message, the stack trace, a W3C trace id, the release (git SHA), the applied migration id, the request method and path, header names, a “data footprint” (which tables and row primary keys the request touched, plus query shapes), metadata about outbound calls, and timestamps.

Error messages, stack traces, and request context can incidentally contain personal data (for example, an identifier in a URL). This metadata is stored as sent and is not anonymized by us. You control what your application reports and can avoid placing sensitive values in error messages, paths, or headers.

What we do not collect

We do not receive or store the contents of your database rows, or the encrypted reproduction packages built from them. Those are produced and served entirely within your infrastructure. We hold only pointers and checksums to them.

Technical and security data

We process basic request logs and IP addresses for security, abuse prevention, and rate limiting.

Payment information

If you subscribe to a paid plan, payments are handled by our payment processor, [Payment Processor]. We do not receive or store full card numbers; we retain only billing metadata (such as plan, status, and the last four digits) as provided by the processor.

3. How we use information

4. Legal bases (EEA/UK)

Where GDPR applies, we process personal data to perform our contract with you (providing the service), for our legitimate interests (securing and improving the service), to comply with legal obligations, and with your consent where required.

5. Sharing and sub-processors

We do not sell personal data. We share it with service providers that help us run Reprova, under contracts that limit their use of it: [Hosting Provider] (infrastructure), [Payment Processor] (billing), and [Email Provider] (transactional email). We may disclose information if required by law or to protect the rights, safety, and security of Reprova and its users.

6. Data retention

We retain account information for the life of your account. Issues and their occurrence metadata are retained until you delete them or close your account; the product supports deleting individual issues. On account closure we delete or anonymize your data within [N] days, except where retention is required by law.

7. Your rights

Depending on your location, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at [privacy@reprova.io]. Because we never hold your database rows, requests concerning that data are handled entirely within your own systems.

8. Security

Data-plane jobs are cryptographically signed and verified; reproduction packages are encrypted to a key we never hold; the keys your application uses are least-privilege and can only submit captures, never read data back. No system is perfectly secure, but our architecture is designed so that a compromise of our infrastructure would not expose your database rows.

9. International transfers

We process data in [region/country]. Where we transfer personal data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses.

10. Children

Reprova is a tool for businesses and is not directed to children under 16.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here and, for material changes, notify you by email or in the product.

12. Contact

Questions about this policy or your data: [privacy@reprova.io], [Your Legal Entity], [Address].