Privacy Policy

Effective date: July 22, 2026

This policy explains what data Reprova collects, how we use it, and the choices you have. Reprova is operated by Reprova Inc. (“Reprova”, “we”, “us”). The defining fact of our design: the rows in your database never reach us — they are extracted, anonymized, and encrypted inside your own infrastructure. We store metadata about your errors, not your data.

1. The short version

2. Information we collect

Account information

When you create a tenant we collect your email address, a team/tenant name, and a securely hashed password. We generate session tokens to keep you logged in.

Error metadata sent by the SDK

When your application captures an error, the Reprova SDK sends us metadata about it: the error type and message, the stack trace, a W3C trace id, the release (git SHA), the applied migration id, the request method and path, header names, a “data footprint” (which tables and row primary keys the request touched, plus query shapes), metadata about outbound calls, and timestamps.

Error messages, stack traces, and request context can incidentally contain personal data (for example, an identifier in a URL). This metadata is stored as sent and is not anonymized by us. You control what your application reports and can avoid placing sensitive values in error messages, paths, or headers.

What we do not collect

We do not receive or store the contents of your database rows, or the encrypted reproduction packages built from them. Those are produced and served entirely within your infrastructure. We hold only pointers and checksums to them.

Technical and security data

We process basic request logs and IP addresses for security, abuse prevention, and rate limiting.

Payment information

The service is currently free of charge, so we do not collect or process payment information. If we introduce paid plans, this section will be updated to name the payment processor before any payment information is collected; we will not receive or store full card numbers, only billing metadata (such as plan and status) as provided by the processor.

3. How we use information

4. Legal bases (EEA/UK)

Where GDPR applies, we process personal data to perform our contract with you (providing the service), for our legitimate interests (securing and improving the service), to comply with legal obligations, and with your consent where required.

5. Sharing and sub-processors

We do not sell personal data. We share it only with service providers that help us run Reprova (such as infrastructure hosting), under contracts that limit their use of it to providing that service to us. We may disclose information if required by law or to protect the rights, safety, and security of Reprova and its users.

6. Data retention

We retain account information for the life of your account. Issues and their occurrence metadata are retained until you delete them or close your account; the product supports deleting individual issues. Closing your account from Settings deletes your tenant's issues, occurrences, jobs, agents, API keys, and account information immediately — this is irreversible. Data may be retained longer where required by law.

7. Your rights

Depending on your location, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@reprova.io. Because we never hold your database rows, requests concerning that data are handled entirely within your own systems.

8. Security

Data-plane jobs are cryptographically signed and verified; reproduction packages are encrypted to a key we never hold; the keys your application uses are least-privilege and can only submit captures, never read data back. No system is perfectly secure, but our architecture is designed so that a compromise of our infrastructure would not expose your database rows.

9. International transfers

We process data in Finland and elsewhere within the European Economic Area (EEA). Where we transfer personal data outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.

10. Children

Reprova is a tool for businesses and is not directed to children under 16.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here and, for material changes, notify you by email or in the product.

12. Contact

Questions about this policy or your data: privacy@reprova.io, Reprova Inc., Tampere, Finland.