Privacy Policy
1. Who controls your data
kenovislabs is operated by Rafa Barranco Vela, acting as data controller for the personal data described below. Contact: privacy@kenovislabs.com.
2. What we collect
We collect only what the account/key/subscription relationship requires:
- GitHub identity. When you sign in with GitHub OAuth, we store the linked GitHub user id. We do not collect your name or email directly — GitHub's own OAuth consent screen controls what it shares with us.
- API key. A hashed credential your kenovislabs CLI uses to authenticate. The raw key is shown to you once and never stored — only its hash.
- Subscription reference. If you subscribe, we store Paddle's own subscription and customer ids and a status (active, canceled, etc.). We never store your card number or any other payment instrument — Paddle, our payment processor and merchant of record, holds that.
3. Paddle as payment processor
Checkout, billing, invoicing, and tax collection are handled by Paddle.com Market Limited, acting as merchant of record. Paddle processes the personal and payment data your checkout requires (name, billing address, card details, tax information) under its own Privacy Policy. We only ever receive Paddle's own opaque subscription/customer ids back — never your card details.
4. Legal basis
We process your GitHub identity on the basis of your own affirmative GitHub OAuth sign-in action. We process your subscription reference on the basis of your own affirmative checkout action and the contract that action forms between you and us (and, for the payment itself, between you and Paddle).
5. Retention
We keep account and subscription records for as long as your account exists, plus a reasonable period afterward for legitimate business records (e.g. a cancelled subscription's history is kept, not deleted, so past billing periods stay explainable). A revoked API key's record is kept for the same reason — never hard-deleted.
6. Your rights
If you are in the EU/EEA or UK, you have the right to access, correct, or request deletion of your personal data, and to object to or restrict our processing of it. Contact privacy@kenovislabs.com to exercise any of these. For data Paddle holds directly (billing/payment details), contact Paddle.
7. Data sharing
We share data with: Paddle (payment processing, as described above), and our infrastructure providers (Supabase for database/authentication hosting, Vercel for application hosting) as processors acting on our instructions. We do not sell your data.
8. Changes to this Policy
We may update this Policy as the product evolves. Material changes will be reflected here with an updated "Last updated" date.
This Policy was prepared with AI assistance as a reasonable starting point for an early-stage, individual-seller product and has not yet been reviewed by a lawyer. It will be reviewed before the product moves beyond its current early-access, test-mode billing phase.