Kanvify

Privacy Policy

Last updated: July 20, 2026

1. Who We Are and Scope

Plus Ultra Industries, LLC (“Plus Ultra,” “we,” “us,” or “our”) operates Kanvify (the “Service”). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our site, create an account, or use the Service.

For account administration, billing, security, analytics, and our direct relationship with you, Plus Ultra generally acts as a controller or business. For personal data a customer places in the Service for us to process on its behalf, Plus Ultra generally acts as a processor or service provider under our Data Processing Addendum. The customer’s privacy notice governs its own processing.

2. Information We Collect

Information You Provide

  • Account and profile information: name, email address, avatar, organization or account name, workspace memberships, role, preferences, and communications
  • Authentication information: magic-link records, signed-in sessions, and, if you choose Google sign-in, Google account identifiers and basic profile information provided through the sign-in flow
  • Credentials and integrations: scoped API keys, OAuth applications and grants, execution-token records, registry credentials, customer-provided LLM provider credentials, GitHub integration and runner configuration, and related metadata
  • Billing information: usage-subscription, credit, invoice, tax, and transaction information; Stripe handles payment-card data under its own terms
  • Customer content: code, files, environment variables, sandbox filesystems, checkpoints, service-process configuration, network-policy configuration, prompts and responses processed through an enabled LLM route, and support material you choose to provide

User API keys are stored with bcrypt, a one-way password hash. OAuth secrets are hashed, and short-lived execution-token identifiers are stored for revocation. Recoverable registry and customer-provided LLM credentials are encrypted because the Service must retrieve them to carry out your instructions.

Information Collected Through Use

  • Session and device data: IP address, browser user agent, session creation and last-active times, device or browser information, and authentication events
  • Usage and billing data: compute seconds, storage gigabyte-hours, LLM request metadata and token counts, requested and actual model, calculated usage amounts, spend-cap events, and Stripe reporting or reconciliation state. LLM usage is not billed by Plus Ultra.
  • Activity records: selected administrative and security-relevant actions, the actor, action, time, account or workspace, and IP address. The activity record does not currently include browser user agent.
  • Operational logs: request identifiers, access time, route, status, error and diagnostic information, and security or abuse signals
  • Cookies and similar technologies: authentication, session, workspace, interface, theme, analytics, measurement, and session-replay technologies described in Section 12

3. How We Use Information

We use information to:

  • Provide, operate, troubleshoot, and support sandboxes, checkpoints, inside-sandbox processes, accounts, workspaces, APIs, integrations, and the optional bring-your-own-provider LLM proxy
  • Authenticate users, protect credentials, enforce tenant boundaries, rate limits, quotas, network policies, and spend controls, and maintain platform security
  • Meter compute and storage, administer credits, process payments, reconcile billing, and meet tax and accounting obligations
  • Communicate about accounts, transactions, support, security, policy updates, and the Service
  • Monitor for suspected fraud or abuse and investigate or act where appropriate; we do not claim that automated systems detect every cryptomining workload, attack, or violation
  • Measure use of our site and Service, understand product performance, and improve user experience using the consent-gated tools described in Section 12
  • Enforce our agreements, protect legal rights, comply with law, and respond to lawful requests

Plus Ultra does not use Customer Content, prompts, responses, or sandbox files to train its own machine-learning models.

Where applicable, we rely on:

  • Contract: processing needed to provide the Service or take requested pre-contract steps
  • Legitimate interests: security, fraud and abuse prevention, service administration, support, measurement that does not require consent, and protecting our rights, balanced against your rights
  • Consent: nonessential analytics, advertising measurement, session replay, and other processing where consent is required; consent can be withdrawn prospectively
  • Legal obligation: tax, accounting, regulatory, litigation, and lawful-request obligations

Where we process Customer Personal Data as a processor, the customer determines the applicable legal basis.

5. How We Disclose Information

We disclose information as follows:

  • Service providers and subprocessors. We use vendors for infrastructure, database hosting, object storage and content delivery, billing, email, customer-provided LLM routing, analytics, measurement, fonts, sign-in, and GitHub runner integration. Our Subprocessor List identifies Stripe, Anthropic, OpenAI, Hetzner, Neon, Cloudflare, Postmark, Google Tag Manager and Google Analytics, Meta Pixel, FullStory, Bunny Fonts, Google sign-in, and GitHub, with functions, data categories, and locations.
  • Customer-directed providers. When you configure a bring-your-own-provider LLM route, we transmit the request to the provider using your credential. You contract with and pay that provider directly. The provider processes information under your provider account and terms.
  • Other members and administrators. Workspace and account information is visible to authorized members according to roles and product functionality.
  • Legal and safety reasons. We may preserve or disclose information when reasonably necessary to comply with law or legal process; protect rights, safety, and security; investigate abuse; or enforce agreements.
  • Business transactions. Information may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and this policy until replaced.
  • At your direction. We disclose information when you enable an integration, direct a transfer, or otherwise consent.

We do not sell personal information for money. Use of Google and Meta measurement technologies may be considered “sharing,” targeted advertising, or cross-context behavioral advertising under some U.S. state laws even when no money changes hands. Section 12 explains the consent and opt-out choices for those tools.

6. Bring-Your-Own-Provider LLM Data

Kanvify does not provide or bill an LLM. If you enable the optional proxy, you supply the provider key, contract with the provider, and pay the provider directly. The proxy is designed to keep that key out of the sandbox, route requests to the selected provider, and provide optional workspace-scoped caching and model aliases or fallbacks.

Anthropic and OpenAI are supported customer-provided routes. The selected provider receives prompts, context, parameters, and other request data and returns the response. Its terms and privacy practices apply. Deleting data from Kanvify does not delete copies already processed by your provider account.

When caching is enabled, the Service stores eligible request parameters and responses within the workspace until the configured time-to-live. Expired entries stop being served and are physically purged by a recurring sweep. Usage metadata can include model identifiers, token counts, request timing, and cost estimates, but Plus Ultra does not charge for LLM usage.

7. Sandbox and Checkpoint Data

Sandbox filesystems persist for the sandbox lifecycle. Processes configured as services run inside the sandbox; Kanvify does not currently provide public Internet routing for them. Explicit sandbox destruction removes the sandbox filesystem through the backend lifecycle.

Checkpoint records and their corresponding backend snapshots are retained for the account-configured operational period, which defaults to 90 days, and are pruned daily. Checkpoints are not a backup service.

Sandboxes use isolated micro-VMs. Scoped database tables use row-level security to help enforce account and workspace boundaries. Operational access is limited to purposes such as support you request, security and abuse investigation, maintenance, and legal compliance.

8. Retention

We retain information for the purposes described below, subject to legal holds, disputes, security needs, and applicable law:

  • Account and workspace data: while the account is active, then processed under the Data Deletion Instructions; deletion may require automated and manual steps
  • Sandbox filesystems: for the sandbox lifecycle, with destruction through the backend lifecycle when a sandbox is explicitly destroyed
  • Checkpoints: for the account-configured operational period, 90 days by default; a daily job prunes both the record and backend snapshot
  • LLM response cache: until the workspace-configured time-to-live; expired request and response rows are purged by a recurring sweep
  • Sessions: rejected and swept after 14 days of inactivity or 30 days from creation, whichever occurs first
  • OAuth tokens: revoked by scheduled sweeps after their configured expiration and retention thresholds; consent-audit records may be retained for security and compliance
  • Processed Stripe webhook payloads: swept after 30 days
  • Usage and activity records: while needed for active-account operation, reconciliation, security, and disputes
  • Billing and transaction records: retained in a minimized, de-identified form for the period needed to meet tax, accounting, audit, and legal requirements
  • Support and legal communications: for as long as reasonably needed to resolve the request, protect rights, and meet legal obligations
  • Backups: deleted data may remain in restricted backups for no more than 30 days before aging out, unless a legal hold requires retention; restored backups remain subject to the deletion process

9. Security and Incident Notices

We use technical and organizational measures designed to protect information, including encrypted network transport, one-way hashing for user API keys and OAuth secrets, encryption for recoverable integration credentials, isolated micro-VM sandboxes, outbound-network controls, row-level database security, scoped roles, rate limits, logging, and scheduled retention jobs. No system is completely secure, and we cannot guarantee that loss or unauthorized access will never occur. See our Security page for more detail.

When Plus Ultra acts as a processor and becomes aware of a Personal Data Breach affecting Customer Personal Data, we notify the relevant customer controller without undue delay. A controller must notify the competent supervisory authority within 72 hours after awareness where the GDPR risk threshold requires it, and notify affected people without undue delay where the breach is likely to create a high risk, subject to applicable exceptions. When Plus Ultra acts as controller, we provide notices as required by applicable law based on those role and risk thresholds.

10. International Transfers

Our service providers process data in Germany, the United States, and other locations described on the Subprocessor List. In particular, sandbox and application compute is located in Germany; the primary Neon database is on AWS us-west-2 in the United States; and Cloudflare uses distributed infrastructure.

For restricted transfers that require contractual safeguards, we use the European Commission’s 2021 Standard Contractual Clauses and the UK International Data Transfer Agreement, as applicable. The correct SCC module, annexes, IDTA tables, transfer assessment, and supplementary measures must be completed for the specific transfer before those instruments are relied upon. We may use another lawful mechanism when available.

11. Your Rights and Choices

Depending on where you live, you may have rights to access, know, correct, delete, restrict, or receive a portable copy of personal information; object to or opt out of certain processing; withdraw consent; appeal a decision; and complain to a regulator. Rights are subject to legal exceptions and verification.

Use available profile and deletion controls in account settings or email privacy@plusultra.industries. We may ask for information needed to verify identity and authority. We respond within the period required by applicable law.

California and other U.S. state residents may opt out of covered sale, sharing, targeted advertising, or profiling. You can withhold or withdraw analytics consent and may contact privacy@plusultra.industries for an opt-out request. The Service does not currently promise automated recognition of Global Privacy Control or Do Not Track browser signals; a separate consent-control build is required for that automation.

12. Cookies, Analytics, and Measurement

We use cookies and similar technologies in these categories:

  • Essential: transient Rails session state, authentication, signup verification, security, and load or request handling
  • Preferences: active or last workspace, sidebar state, language, appearance, and theme, including local storage
  • Analytics and measurement: Google Tag Manager and Google Analytics for tag delivery, traffic and product measurement; Meta Pixel for campaign and conversion measurement; and FullStory for product analytics and session replay

The analytics and measurement tools can receive IP address, browser and device details, page URLs, referrers, timestamps, cookie or device identifiers, events, and interaction data. FullStory may capture interaction and rendered-page data; do not enter secrets or sensitive personal data where avoidable.

These nonessential measurement features are intended and required to be consent-gated. Google tag code may initialize with analytics and advertising storage denied to establish the consent state; analytics storage and advertising permissions are granted only when an analytics_consent choice has been recorded. Meta Pixel and FullStory are configured to load only after that choice. Withholding or withdrawing consent should leave essential Service functions available, although browser blocking may affect some preferences.

We do not authorize Google Tag Manager containers to add undisclosed purposes or vendors. We do not claim that consent mode prevents every network request before opt-in. Until a complete preference center and automated privacy-signal handling are available, you can block nonessential scripts using browser controls, clear the analytics-consent cookie, or contact privacy@plusultra.industries.

13. Age Restriction

The Service is for people aged 18 or older. We do not knowingly collect personal information through the Service from anyone under 18. If you believe a minor has provided information, contact privacy@plusultra.industries so we can investigate and take appropriate action.

14. Data Protection Contacts

We have assessed our current processing and do not currently consider appointment of a Data Protection Officer or an EU or UK representative to be required. We have therefore not named one. We will reassess if our processing or legal obligations change.

Privacy requests: privacy@plusultra.industries

Security reports: security@plusultra.industries

Legal questions: legal@plusultra.industries

Plus Ultra Industries, LLC accepts privacy contact by email only.

15. Changes to This Policy

We may update this Privacy Policy. We post changes with an updated effective date and make reasonable efforts to notify affected users. A change applies on the date stated in the updated policy unless applicable law requires otherwise.