inkvo/legal/privacy

Privacy Policy

What we collect, why we collect it, and the rights you have over it. Plain language first; the details follow.

Effective June 1, 2026·Version 1.2

Summary

Inkvo processes two kinds of data: Customer Data (the telemetry you send us to monitor) and account data (who you are, so we can run your account). We use both only to provide the Service. We don't sell data, and we don't use your telemetry to train models for other customers.

Our two roles

Inkvo handles personal data in two distinct roles, and your rights differ depending on which applies:

  • As a controller — for account, billing, and marketing data about the people who sign up for and use Inkvo, we decide why and how it's processed. This policy governs that data.
  • As a processor — for the telemetry you send us (logs, traces, metrics, which may contain personal data), you are the controller and Inkvo processes it only on your behalf, under our Terms and DPA. You decide what is sent and remain responsible for it.

What we collect

Customer Data (telemetry)

Traces, metrics, logs, and deploy events you send via OpenTelemetry or our connectors. You control what's in it. We encourage scrubbing personal data from spans at your collector before ingest.

Account & usage data

  • Account details: name, work email, organization, role
  • Billing details, handled by our payment processor (we don't store card numbers)
  • Product usage: features used, sessions, and diagnostic logs of the app itself

How we use it

  • To operate the Service: ingest, detection, narratives, notifications
  • To support you and respond to requests
  • To secure the Service and investigate abuse
  • To improve features in aggregate — never by exposing one customer's data to another

Where the GDPR applies, we process personal data under the bases of contract (to provide the Service you signed up for), legitimate interests (securing and improving the Service), and consent (where required, e.g. certain cookies). Where Brazil's LGPD applies, we rely on the equivalent bases — execution of a contract, our legitimate interests, and consent — and honor the same data-subject rights described below. For Customer Data, Inkvo acts as a processor (operator under the LGPD) and you are the controller; our DPA governs that relationship.

Sharing

We share data only with the subprocessors listed below, each bound by contract to protect it, and where required by law. We do not sell personal data or share it for cross-context behavioral advertising.

Subprocessors

We use a short list of subprocessors to deliver the service. Each is bound by a data-processing contract. Customers can request advance notice of changes under our DPA.

SubprocessorPurpose
PaddlePayments, billing, and tax as our merchant of record. We do not store full card numbers.
SupabaseAuthentication and user accounts.
HetznerInfrastructure and storage of ingested telemetry.
GroqGenerating incident narratives from your telemetry.

Each subprocessor's processing region is specified in the DPA. We do not use your telemetry to train models for other customers, and each subprocessor is contractually bound to the same restriction.

Retention

Customer Data is retained per your plan and configuration (3 / 30 / 90 days, or custom). Account data is retained while your account is active and for a limited period afterward as required for legal and accounting purposes. Deletion details are in our data-handling policy.

Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Account holders can do most of this in-app; for anything else, email privacy@inkvo.dev and we'll respond within the legally required window.

Cookies

The marketing site uses a minimal set of cookies for essential functionality and privacy-respecting analytics. The application uses cookies strictly necessary to keep you signed in. We don't use third-party advertising cookies.

International transfers

Your telemetry is processed and stored on infrastructure in the EU. To generate incident narratives, relevant telemetry is sent to our model provider in the United States; that transfer is covered by Standard Contractual Clauses. Account and billing data may also be processed outside your country by the subprocessors listed above, under equivalent safeguards.

Contact

Privacy questions or requests: privacy@inkvo.dev. EU/UK representatives are named in the full policy provided to customers.