Privacy
Data follows the route you choose.
This notice describes how Kolvra currently handles data across the website, desktop app, and managed services.
Effective 26 August 2026
Who is responsible
Kausora Technologies Limited, based in Masdar City, Abu Dhabi, United Arab Emirates, operates Kolvra and is responsible for the personal data described here. Privacy questions, data requests, and complaints can be sent to contact@kolvra.com.
What we process and why
We process account identifiers and service records to provide and secure Kolvra; billing and entitlement records to perform our contract and meet accounting duties; support messages to answer you; and limited security and diagnostic information as necessary to prevent abuse and keep the service reliable. We ask for consent where law requires it and do not sell personal data.
The website
The website does not use advertising pixels, third-party font networks, embedded media, or browser storage for behavioural tracking. Its host may retain ordinary request and security logs for a limited period. If you email us, we use the information you send to reply.
The desktop app
Local workspace state, files, terminal access, approvals, and Device Local inference remain on your computer unless you deliberately use a connected or managed route, synchronisation feature, or external tool. A selected route receives the context needed for that request.
Accounts, commerce, and operations
Kolvra stores the minimum account, device, entitlement, usage, billing, and security metadata needed to operate the service. Clerk provides identity, Polar provides commerce, Cloudflare provides platform hosting, and selected model providers process the request content needed for their routes under the route label and applicable agreements.
Inference retention
Managed routes are labelled by retention class in the product. Verified ZDR means the qualifying route is configured and verified for no durable prompt or output storage. Other routes may have limited or provider-shared retention. Device Local sends model input to no remote inference service.
Your choices
You can use Kolvra without managed inference, disconnect provider accounts, delete local conversations, and ask us to access, correct, or delete account data where applicable. Some records may be retained when required for security, accounting, disputes, or law.
Retention, transfers, and security
We retain each category only as long as needed for the purpose above, then delete or de-identify it unless law requires longer retention. Providers may process data outside your country using contractual and legal safeguards appropriate to the transfer. We use access controls, encryption in transit, scoped credentials, and operational monitoring, but no system can guarantee absolute security.
Your rights
Depending on where you live, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier processing. You may also complain to your local data-protection authority. We may verify your identity before completing a request.
Changes
We may update this notice as Kolvra changes. We will publish the revised effective date and provide additional notice when a material change or applicable law requires it.