Privacy Policy
Last updated: January 16, 2026
This Privacy Policy explains how Kourtra (“Kourtra”, “we”, “us”) collects, uses, shares, and retains information when you use our websites, applications, and services (collectively, the “Service”).
Highlights
- You can export your account data from within the app (a JSON download).
- You can delete your account from within the app; deletion requires re-authentication for safety.
- When you delete uploaded files, we keep them for a short retention window (default 30 days) before permanent deletion from storage.
- We use a device identifier cookie (HttpOnly) to help secure session refresh/rotation.
- We maintain security audit logs to protect accounts and the Service; some of these logs are designed to be append-only.
Scope
This policy applies to information we process when you (i) visit our public website, (ii) create an account, (iii) join or administer an organization (a “Community”) on Kourtra, or (iv) otherwise use the Service.
Roles (Controller / Processor)
Depending on how you use Kourtra, we may process personal data as:
- Controller for our own business operations (e.g., operating our website, account administration, billing, and security).
- Processor when we host and process Community content on behalf of a Community (the Community is typically the controller for that content).
If you use Kourtra through a Community, that Community’s admins may control certain settings and access to data within that Community.
Information We Collect
Information you provide
- Account details such as email address, and (if you choose password login) a password (stored as a cryptographic hash, not in plaintext).
- Profile details such as name, bio, and profile photo.
- Community content you create or upload, such as announcements, choices, foundations, teams, and files.
- Support and communicationsyou send to us.
Information collected automatically
- Session and security datasuch as session identifiers, refresh-token hashes, IP address, and user agent.
- Device identifier cookieused to help secure session refresh/rotation.
Information from third parties
We may receive information from service providers involved in operating the Service (for example, payment processors for subscription management). The information we receive depends on your plan and configuration.
How We Use Information
- Provide and operate the Service (authentication, Community features, storage).
- Secure the Service (fraud prevention, abuse detection, audit and monitoring).
- Process billing and subscriptions (where applicable).
- Communicate with you about service messages and support.
- Comply with legal obligations and enforce our terms.
Legal Bases (EEA/UK)
If you are in the European Economic Area (EEA) or the United Kingdom, we process personal data under one or more of these bases: (i) to perform a contract (provide the Service), (ii) legitimate interests (secure and improve the Service), (iii) compliance with legal obligations, and (iv) consent where required (e.g., certain optional features).
How We Share Information
We share information only as needed to operate the Service, including with:
- Infrastructure and hosting providers(compute, databases, backups, and networking).
- Object storage providersfor files and images (S3-compatible storage).
- Email delivery providersto send authentication and service emails.
- Payment processors for subscriptions and contributions (e.g., Stripe). We do not store full payment card numbers.
- AI providers if your Community enables AI-powered features. When enabled, prompts/content you submit may be sent to the configured AI provider (e.g., OpenAI-compatible API endpoints).
- Your Community administratorsfor data within that Community, depending on permissions and settings.
- Legal and safety when required by law or to protect rights, safety, and security.
Subprocessors and configurations can vary by deployment. You can contact us for the current list of subprocessors used for your environment.
Cookies and Similar Technologies
We use cookies and similar technologies to provide and secure the Service.
- Device ID cookie: we set an HttpOnly cookie used as a stable device identifier (not an authentication credential) to help secure session refresh/rotation.
- Local storage: the web app stores an access token in browser storage to authenticate API requests.
You can control cookies through your browser settings, but disabling certain cookies may affect Service functionality.
Security
We use administrative, technical, and physical safeguards designed to protect personal data. For example, we use encryption in transit (TLS) and enforce re-authentication for sensitive actions like account deletion and exports.
We may scan uploaded files for malware using antivirus tooling (for example, ClamAV) and quarantine files during processing.
Retention
We retain information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
- Sessions: refresh sessions are time-limited (for example, 30-day expirations) and can be revoked.
- Deleted files: when a file is deleted in the Service, it is soft-deleted first; we retain it for a short period (default 30 days, configurable) before permanently deleting it from storage and removing the database record.
- Security audit logs: we keep security audit events to protect the Service. Some security audit logs are designed to be append-only and may persist even after an account is deleted.
We may also retain limited information in backups for a period of time, after which it is overwritten or deleted according to our backup lifecycle.
Your Choices and Rights
Depending on where you live, you may have rights regarding your personal data. These may include access, correction, deletion, portability, and objection.
In-app controls
- Export: you can request a data export from your Account settings. The export is provided as a JSON download.
- Delete account: you can delete your account from your Account settings. For security, we require re-authentication.
- Sessions: you can revoke sessions/devices in your account security settings.
EEA/UK (GDPR/UK GDPR)
If GDPR/UK GDPR applies to you, you may have the right to access, rectify, erase, restrict processing, object, and receive a copy (port) of your personal data, and to lodge a complaint with your supervisory authority.
California (CCPA/CPRA)
If you are a California resident, you may have rights to know, access, delete, correct, and opt out of certain data sharing as defined by applicable law. Kourtra does not sell personal information in the ordinary sense.
Texas (TDPSA)
If you are a Texas resident, you may have rights to access, correct, delete, and obtain a copy of your personal data, and to opt out of certain processing as defined by the Texas Data Privacy and Security Act.
Account Deletion (What Happens)
When you delete your account, we revoke your active sessions and remove your user record from our authentication database. Some information may remain as part of a Community’s records (for example, security audit logs or historical Community records) or in backups for a limited period.
If you are using Kourtra through a Community, certain content or records may be managed by the Community and may be retained according to the Community’s policies.
International Transfers
The Service may be hosted and operated in the United States and other countries. Where required by law, we use appropriate safeguards for cross-border transfers.
Children
The Service is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date.
Contact Us
For privacy questions or requests, contact us at support@kourtra.com.