Regra

Privacy Policy

Last updated: July 29, 2026

Regra is operated by Pinewood Labs1 LLC. This policy explains what we collect, why, and the choices you have. The short version: we collect the minimum needed to run a compliance scanner, we run no advertising trackers, and your card number never touches our servers.

What we collect

What we don't do

Who processes data for us

We use a small set of infrastructure providers, each bound by their own data terms:

Legal bases (GDPR)

Where the GDPR applies, we process personal data on these bases:

International transfers

We are a US company and data is processed in the United States by us and the providers listed above. Where EU/UK data protection law applies, transfers rely on safeguards such as the EU-U.S. Data Privacy Framework certifications of our providers and/or Standard Contractual Clauses.

Retention

Account and scan data are kept while your account is active. If you delete your account or ask us to, we delete your profile, sites, scans, and findings; billing records are retained as long as tax and accounting law requires.

Your rights

Depending on where you live (including under GDPR and CCPA), you may have rights to access, export, correct, or delete your personal data. Email support@regra.app and we will respond within 30 days. You can also stop all collection by cancelling your subscription and requesting deletion. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.

Children

The Service is for businesses and is not directed to anyone under 16.

Changes and contact

Material changes to this policy will be announced by email or in the app. Questions: support@regra.app.