Privacy Policy
What we collect, on what legal basis, how long we keep it, and the rights you keep. No ads, no data selling, no third-party sharing.
Who Is Responsible
Konterra (konterra.space) is the data controller for the personal data described below. Written requests reach us at privacy@konterra.space and are answered within 30 days.
This policy covers the Konterra web application, its public atlas pages at /u/, and the Konterra MCP API.
What We Collect
Account data: name, email address (used only as your sign-in identifier), a bcrypt hash of your password, optional profile image URL, optional username and bio, sign-in timestamps, and the invite you arrived through if any.
Contact records you create: names, emails, phone numbers, social handles, cities, countries, coordinates, companies, job titles, tags, free-text notes, birthdays, and the relationship attributes you choose to fill in.
Activity you log: interactions (type, date, location, notes), connections between contacts, introductions, favors, and the location history you record for a contact.
Travel data: visited countries, trips (city, country, arrival and departure dates, notes, coordinates), and your country wishlist.
Technical data: a security audit log of sign-ins, password changes, exports, deletions and similar events, recorded with a truncated IP address; rate-limit counters; and cached geocoding lookups.
Usage analytics: Google Analytics 4 records page views and product events (for example, completing onboarding or opening the days-per-country table). These events carry no contact data and no note content.
Lawful Basis
Performance of a contract (GDPR art. 6(1)(b)): running your account, storing the records you enter, and delivering the product features you asked for.
Legitimate interests (art. 6(1)(f)): keeping the service secure (audit log, rate limiting) and preventing abuse. We have weighed these against your rights and limited each to what the purpose needs.
Consent (art. 6(1)(a)): publishing your atlas at a public URL, allowing search engines to index it, and analytics cookies. Each is off unless you turn it on, and each can be withdrawn without affecting anything else.
Data About Other People
Konterra is a personal CRM, so most of what you store is personal data about third parties who are not our users. You remain responsible for having a lawful reason to record it and for keeping it accurate and proportionate.
We process that data only on your behalf: to display it back to you, to geocode a place name into coordinates, and to compute your own insights. We never contact the people in your address book, never use their data to build profiles of our own, and never share it with anyone.
Contacts are never shown on your public atlas at any privacy setting. The public page exposes countries, and, only if you opt into "full travel history", your own trips.
If someone in your records asks us to erase their data, we will route the request to you as the controller of that record and help you action it.
Where Your Data Is Stored
Database: Neon PostgreSQL in the EU (Frankfurt, aws-eu-central-1), encrypted at rest and in transit. Backups stay in the same region.
Application hosting: Vercel serverless compute on a global edge network. Vercel processes requests but stores no user records.
Transfers outside the EEA to US-based processors (Vercel, Google Analytics, OpenRouter) rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Who Has Access
You, through your authenticated session or an API token you issued yourself. API tokens are scoped, hashed at rest, and revocable.
Administrators, for operational support only. Passwords are never readable, they are stored as bcrypt hashes. Administrative actions on accounts are written to the audit log.
Processors listed below, each limited to the specific data their function requires.
Nobody else. We do not sell data, we do not share it for advertising, and we run no advertising.
Security Measures
HTTPS everywhere with HSTS preload, and a Content-Security-Policy restricting where the page may load code and connect.
Passwords hashed with bcrypt at cost factor 12, never stored or recoverable in plain text.
Sign-in attempts are rate limited per email and per IP across all servers, and repeated failures are throttled persistently.
Account deletion and full data wipes require re-entering your password. Cross-site request protection is enforced on every state-changing request.
Deleting your account cascades through every table that references it, so no orphaned records survive.
Data Retention
Account and content data: kept while your account exists, and erased when you delete it. There is no soft-delete and no recovery window.
Security audit log: 400 days, then automatically deleted. It is kept beyond account deletion only as evidence that the deletion happened.
Rate-limit counters: deleted once their window closes.
Cached geocoding results (place name to coordinates, containing no personal identifiers): 365 days.
A scheduled job enforces this schedule nightly. These are the periods the system actually applies, not aspirations.
Your Rights
Access and portability: export everything from Settings in JSON, CSV or vCard at any time. No request or waiting period.
Rectification: edit or correct any record directly in the app.
Erasure: delete your account from Settings. It is immediate and irreversible.
Restriction and objection: unpublish your atlas, remove it from search engines, or decline analytics, each independently, in Settings.
Withdrawing consent does not affect processing that already happened lawfully before you withdrew it.
You may lodge a complaint with your local data protection supervisory authority. We would rather you write to us first at privacy@konterra.space.
Konterra does not send email. There are no newsletters, no digests, no marketing and no automated notifications, and no email provider processes your address on our behalf.
Your email address exists only as your sign-in identifier. Because we send nothing, password recovery is handled by an administrator on request rather than by an automated reset link.
Processors We Use
Neon (neon.tech): database hosting in the EU. Holds all account and content data.
Vercel (vercel.com): application hosting and compute. Processes requests; stores no records.
OpenCage (opencagedata.com) and OpenStreetMap Nominatim: geocoding. Receive only a place name such as "Lisbon, Portugal". No names, emails or identifiers are sent.
OpenRouter (openrouter.ai): the AI features you invoke explicitly, such as drafting an introduction or generating contact insights. Receives only the contact details relevant to that request, and only when you press the button.
Google Analytics (google.com): usage measurement. Receives page paths and product events, never contact data or note content.
Cookies
A session cookie keeps you signed in. It is strictly necessary and cannot be switched off while you use an account.
Google Analytics cookies measure usage. They are not required for the product to work.
We set no advertising cookies and no cross-site trackers.
Changes and Contact
Material changes to this policy are announced in the app before they take effect. The date at the top of this page is the last revision.
Privacy questions, data requests and complaints: privacy@konterra.space.