Privacy Policy

Last updated: March 23, 2026

Kopern ("we", "us", "our") is committed to protecting your personal data in compliance with the EU General Data Protection Regulation (GDPR) and French data protection laws (Loi Informatique et Libertés).

1. Data Controller

The data controller is Kopern, operated from France. For any data protection inquiries, contact us at: privacy@kopern.app

2. Data We Collect

We collect the following categories of personal data:

  • Account data: email address, display name, authentication provider (Google, GitHub, email)
  • API keys: your LLM provider keys (Anthropic, OpenAI, Google, Mistral), stored encrypted in Firestore
  • Usage data: token consumption, costs, request counts, per-agent breakdowns (for billing purposes)
  • Session data: conversation logs, tool call history, timestamps (when functional consent is given)
  • GitHub data: OAuth access token, connected repository names (if you enable GitHub integration)
  • Payment data: processed by Stripe — we store only your Stripe customer ID, not card details

3. Legal Basis for Processing

  • Contract performance: account management, billing, service delivery (Art. 6(1)(b) GDPR)
  • Consent: functional analytics, detailed session tracking (Art. 6(1)(a) GDPR)
  • Legitimate interest: security, fraud prevention, error monitoring (Art. 6(1)(f) GDPR)
  • Legal obligation: invoicing, tax records (Art. 6(1)(c) GDPR)

4. Cookies & Local Storage

Kopern uses minimal cookies:

  • NEXT_LOCALENEXT_LOCALE: stores your language preference (essential, 1 year)
  • Firebase AuthFirebase Auth: session tokens for authentication (essential, session-based)
  • kopern_consentkopern_consent: your cookie preferences (essential, 1 year)

We do not use any third-party analytics, advertising cookies, or tracking pixels.

5. Data Retention

Account data is retained for the duration of your account. Usage data is retained for 24 months for billing purposes. Session data is retained for 12 months. You may request deletion at any time.

6. Third-Party Processors

  • Google Firebase (Firestore, Authentication): EU data center, data storage and auth
  • Stripe: PCI-DSS compliant payment processing
  • Vercel: application hosting (edge functions, EU region available)
  • LLM Providers (Anthropic, OpenAI, Google, Mistral): your prompts are sent to these providers using YOUR API keys — Kopern does not store prompt content on its servers

7. Your Rights (GDPR Art. 15-22)

You have the right to:

  • Access: download all your personal data (Settings → Data & Privacy → Export)
  • Rectification: update your data in Settings at any time
  • Erasure: delete your account and all associated data (Settings → Data & Privacy → Delete Account)
  • Portability: export your data in JSON format
  • Restriction: limit processing by disabling functional tracking
  • Objection: contact us to object to any processing
  • Lodge a complaint with the CNIL (cnil.fr) if you believe your rights are not respected

8. International Transfers

Your data may be processed in the US (Firebase, Vercel, LLM providers). These transfers are covered by Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable.

9. Security Measures

We implement encryption at rest (Firestore), encrypted API key storage, HMAC signature verification for webhooks, CORS whitelisting for widgets, sandboxed code execution for custom tools, and role-based access control.

10. Changes to This Policy

We will notify you of material changes via email or in-app notification. Continued use after notification constitutes acceptance.

11. Contact

For any privacy-related questions or to exercise your rights: privacy@kopern.app