LEGAL

Privacy policy

Version 1.0 · Effective October 13, 2026 · Draft for legal review before publication.

1. Data controllers

NOVACODIFY S.A.S. Privacy officer: privacidad@aura-control.com.

2. What data we process

  • Account data: name, email, GitHub identifier, organization, role.
  • Usage data: connected repositories, reviewed Pull Requests, verdicts, findings, specs, approved or rejected agent actions, credit consumption.
  • Runtime metadata (free version): linked machine identifier, operating system, agent name, action type, and approval decision. Not the code, the prompt, or keystrokes. Current list on the security page, pending legal review.
  • Source code: processed ephemerally to provide the service and not stored after review.
  • Payment data: handled by Stripe, Mercado Pago, or OrbiPay; AURA does not store card data.
  • Technical data: access logs, IP address, user agent, errors (without source code).

3. What we use it for

To provide and improve the service, bill, send you operational notifications, calculate aggregated anonymous metrics (for example, the State of Agentic Development Report), meet legal obligations, and prevent fraud. Never to train artificial intelligence models with your code.

4. Who we share it with

With the subprocessors needed to operate (infrastructure, AI model providers, payments, transactional email, monitoring), listed on the security page. We do not sell personal data.

5. How long we keep it

While your account is active and for up to 90 days after deletion, except for legal retention obligations (for example, billing records). Source code is not retained.

6. Your rights

Access, rectification, erasure, portability, and objection, under Colombia's Law 1581 of 2012 and the GDPR where applicable. Write to us at privacidad@aura-control.com; we respond within a maximum of 30 days.

7. Cookies and analytics

The site uses only strictly necessary technical cookies and, if enabled, analytics without cookies or personal identification. The application uses session cookies. We do not use third-party advertising tracking.

8. International transfers

Data may be processed in the United States, the European Union, and other regions of the subprocessors listed on the security page, under appropriate contractual safeguards. On the Enterprise plan, the customer may restrict the processing region for AI models.

9. Changes

Material changes are notified by email with 30 days' notice.