Privacy Policy
Last updated: June 14, 2026
This policy explains what data kinora collects, why, and your rights over it. kinora is a dashboard for Playwright test reports. The data controller is Joris Gallot, and the service is hosted in the European Union (Hetzner). Questions: contact@kinora.dev.
This policy may evolve as the product does; material changes will be reflected by the date above.
Data we collect
- Account. Email, name, a hashed password, and (if you sign in with Google or GitHub) the basic profile they return (id, email, avatar). Plus session and email-verification state.
- Test data you upload. Project and run metadata (timing, pass/fail counts), git info (commit SHA, branch), CI details, and per-test results (title, file, status, errors, retries, tags, annotations), along with any trace, screenshot, or video artifacts you push.
- API keys. Stored hashed; used to authenticate uploads from your CI.
- Workspace. Workspace name, members, and pending invitation emails.
- Billing. Handled by our payment provider (Polar). We store only your plan, status, and a customer reference, never card details.
- Usage analytics. Aggregate, cookie-less page and event analytics (Umami).
- Diagnostics. Error reports to help us fix bugs (Sentry), configured to exclude personal data by default.
Your test artifacts
Playwright traces can capture your application's DOM, network traffic, console output, and screenshots. These may contain data from your own users or secrets from your app. kinora stores exactly what you upload and never inspects it. You are responsible for what you send - mask sensitive values in Playwright or avoid uploading them. When kinora processes test data on your behalf, we act as a data processor; enterprise customers can request a Data Processing Agreement.
How we use your data
- Run the service: store and display your test history, traces, trends, and alerts.
- Authenticate you and secure your account.
- Send transactional email (verification, password reset, invitations, billing and usage notices, regression alerts).
- Process subscriptions and billing.
- Understand aggregate usage and fix errors to improve the product.
Service providers
We share data only with the providers needed to run kinora:
- Hetzner (EU): hosting and artifact storage.
- Polar: billing and payments (merchant of record).
- Resend: transactional email delivery.
- Sentry (US): error monitoring (no personal data by default).
- Umami: self-hosted, cookie-less analytics (EU).
- Google / GitHub: only if you choose social sign-in.
Your data is stored in the EU. The exception is Sentry, which ingests crash reports on US infrastructure; we send it no personal data by default.
Cookies
We use a single essential cookie to keep you signed in. Our analytics (Umami) is cookie-less and does not track you across sites. We do not use advertising or third-party tracking cookies.
Data retention
Test history is kept according to your plan's retention window (7 days on Free, longer on paid plans); older runs and their artifacts are deleted automatically. Deleting your account removes your workspace and all of its projects, runs, and stored artifacts.
Your rights
You can access, correct, export, or delete your data. Most of this is self-service in your account settings (including account deletion). For anything else, email contact@kinora.dev. If you are in the EU/UK, you have rights under the GDPR, including the right to lodge a complaint with your local data protection authority.
Security
Data is encrypted in transit (TLS). Passwords and API keys are stored hashed. Outbound webhooks are HTTPS-only. No system is perfectly secure, but we work to protect your data.
Children
kinora is not intended for anyone under 16, and we do not knowingly collect their data.
Contact
Questions about this policy or your data: contact@kinora.dev.