Privacy Policy
Effective 2026-05-28
This policy explains what personal data Enginara collects, why, how long we keep it, and the rights you have over it under GDPR, the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA).
1. Who we are
Enginara ("we", "us") provides an engineering intelligence platform that summarises metadata from code hosts and project trackers. For the purposes of EU/UK GDPR, the data controller is the entity that signed up for the workspace; we act as a data processor on your behalf for source-tool metadata, and as a data controller for account-holder personal data (name, email, billing).
2. What we collect
Account holder data (controller)
- Name, email address, hashed password (or OAuth identifier from Google/GitHub/GitLab)
- Workspace name, billing plan, payment metadata (tokenised; we never store card numbers)
- IP address and user-agent of session requests (security log, 30-day retention)
Source-tool metadata (processor)
- Repository names, commit SHAs and metadata (author, timestamp, message), branch names
- Pull / merge request metadata: title, state, reviewers, approvals, CI run results
- Project tracker metadata: task titles, status transitions, sprint membership, assignees
- We do not clone repositories. We do not store source code, diffs, or commit content. We only persist metadata required to produce engineering reports.
3. Why we collect it
- To deliver the service you signed up for (legal basis: contract performance, GDPR Art. 6(1)(b)).
- To bill you and prevent fraud (legal basis: contract + legitimate interest, Art. 6(1)(b),(f)).
- To detect and mitigate abuse (legal basis: legitimate interest, Art. 6(1)(f)).
- To send service-related emails (security notices, billing). Marketing emails are opt-in and you may withdraw consent at any time.
4. AI processing
Weekly reports are generated by a language model. The model receives only the deterministic metric snapshot for the workspace; it does not see source code or full task descriptions. Reports are produced in your tenant and are not used to train any third-party model. Customers may opt to self-host the model (Ollama) so prompts never leave your infrastructure.
5. Sub-processors
We use the sub-processors listed at enginara.app/legal/sub-processors. Material changes (additions or removals) are announced via in-app notice 30 days before they take effect.
6. Data retention
- Account data: lifetime of the account, plus 90 days after closure (for billing reconciliation).
- Source-tool metadata: configurable per plan (default 12 months rolling).
- Security logs (IP, user-agent): 30 days.
- Backups: 35-day retention window before automatic destruction.
7. Your rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion (subject to legal-hold exceptions)
- Request a portable export
- Object to processing or restrict it
- Lodge a complaint with your local data-protection authority
To exercise any of these rights, email privacy@enginara.app. We respond within 30 days.
8. International transfers
Data may be processed in regions where our sub-processors operate. Where data leaves the EU/UK, we rely on Standard Contractual Clauses (2021/914) as the transfer mechanism, supplemented by encryption-in-transit and at-rest controls.
9. Children
The service is intended for business users. We do not knowingly collect data from children under 16.
10. Changes to this policy
Material changes are announced via in-app notice 30 days before they take effect. The effective date at the top of this page records the most recent revision.
11. Contact
Data Protection Officer: privacy@enginara.app.

