Privacy Policy
Version 1.0 — draft, pending review
This explains what Kodavara Render collects, why, and what we do with it.
What we collect
Account details. Your name, email address, optional phone number, the
account name, country, region and timezone you enter, and your password
stored only as a one-way hash. We never store your password in a form we
could read.
Sign-in and session records. Session tokens (stored hashed), the IP
address and browser user agent a session was created from, sign-in counts and
timestamps, and failed sign-in attempts. These support security
investigations and account lockout.
Workspace credentials. The token authorising access to your ClickUp
workspace, encrypted at rest with a per-connection key that is itself
wrapped by our master key. We keep the last four characters of an API key in
readable form so you can recognise which key is connected; that fragment is
never enough to use.
Workspace content you point us at. The parts of your ClickUp workspace
your configuration covers — tasks, fields, statuses, tags, hierarchy — read
so identifiers can be assigned and documents generated, and cached so the
application is usable without re-reading your workspace on every screen.
What you upload. Document templates and any assets in them.
What we generate. Assigned identifiers, the record of each assignment,
generated documents, and the data snapshot each document was produced from.
Operational records. Actions taken in your account — who changed a
sequence, who assigned or voided a number, who revoked a record, who
downloaded a file, who changed a plan — plus counts of assignments,
documents and bytes stored. These drive your usage meters, our billing, and
any security investigation.
Correspondence. Messages you send through the contact form, and the
emails we send you.
What we do with it
We use it to run the service you asked for, to bill you, to tell you when
something needs attention, to enforce plan limits, to investigate abuse and
security incidents, and to meet legal obligations.
We do not sell your data. We do not use your workspace content to train
models. Render's processing is deterministic: identifiers, formatting,
merging, document generation and writeback are performed by code, not by a
model.
Verification pages
If you enable a public verification page for a record, the fields you choose
to publish become visible to anyone with the link. That is the purpose of the
feature. You decide which records are public and which fields appear, and you
can revoke or expire a record at any time.
Verification pages are not indexed by search engines by default.
Who we share it with
Only the providers needed to operate the service: our hosting and database
provider, our object storage provider, our email delivery provider, and our
payment processor. Each receives only what their function requires. Payment
card details go directly to the payment processor and never reach us.
We disclose data to authorities only where legally required.
How long we keep it
Account and billing records: for as long as the account exists and then as
long as law requires.
Generated files: for the retention period your plan specifies.
Assignment and record history: kept beyond file retention, because the
value of an identifier is that it can still be checked later. This history
is deleted when the account's data is deleted.
Abandoned trial accounts: connections, cached workspace content and generated
files are removed 30 days after the trial ends, after an email warning. The
login itself remains.
Your choices
You can view and correct your account details in the application, revoke
sessions, disconnect a workspace at any time, choose which notification
emails you receive, request a copy of your data, and request deletion of your
account. Requests are recorded and acted on within our policy window.
Security
Tenant data is isolated in the database at the row level, and the application
refuses to start unless that isolation is provably in force. Credentials are
encrypted at rest. Administrative access is restricted and every
administrative action is logged. No system is perfectly secure, and we will
tell you promptly if a breach affects your data.
Changes
We may publish a new version of this policy. Existing accounts keep the
version they accepted until they accept a newer one, and every acceptance is
recorded with the exact text shown.
Contact
Privacy questions or requests: info@kodavara.com
Version 1.0 · effective 9/11/2026