Privacy Policy
Last updated: July 29, 2026
Regra is operated by Pinewood Labs1 LLC. This policy explains what we collect, why, and the choices you have. The short version: we collect the minimum needed to run a compliance scanner, we run no advertising trackers, and your card number never touches our servers.
What we collect
- Account data — your email address, an optional display name, and, if you sign in with Google, the basic profile Google shares (name, email).
- Billing data — your subscription plan and status, and Stripe identifiers. Card numbers are collected and stored by Stripe, never by us.
- Scan data— the domains you register, the publicly accessible page content our crawler fetches from them, and the findings we generate. We only read pages that are public; we never log into your site and never collect your customers’ data.
- Operational logs — standard request logs and per-scan cost records used to run and secure the Service.
What we don't do
- No advertising or cross-site tracking. No analytics trackers are installed.
- No sale of personal data, ever.
- Only essential cookies — the ones that keep you signed in.
Who processes data for us
We use a small set of infrastructure providers, each bound by their own data terms:
- Vercel — application hosting.
- Supabase — database, authentication, and file storage.
- Stripe — payments and subscription billing.
- Resend — transactional email (magic links come from Supabase; scan and alert emails from Resend).
- Firecrawl — fetching the public pages of sites you register.
- Anthropic — AI analysis of crawled public page content during scans.
- Inngest — background job orchestration for scans.
Legal bases (GDPR)
Where the GDPR applies, we process personal data on these bases:
- Performance of a contract (Art. 6(1)(b)) — account, billing, and running the scans you request.
- Legitimate interests (Art. 6(1)(f)) — securing the Service, preventing abuse, and operational logging.
- Legal obligation (Art. 6(1)(c)) — retaining billing records for tax and accounting law.
International transfers
We are a US company and data is processed in the United States by us and the providers listed above. Where EU/UK data protection law applies, transfers rely on safeguards such as the EU-U.S. Data Privacy Framework certifications of our providers and/or Standard Contractual Clauses.
Retention
Account and scan data are kept while your account is active. If you delete your account or ask us to, we delete your profile, sites, scans, and findings; billing records are retained as long as tax and accounting law requires.
Your rights
Depending on where you live (including under GDPR and CCPA), you may have rights to access, export, correct, or delete your personal data. Email support@regra.app and we will respond within 30 days. You can also stop all collection by cancelling your subscription and requesting deletion. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
Children
The Service is for businesses and is not directed to anyone under 16.
Changes and contact
Material changes to this policy will be announced by email or in the app. Questions: support@regra.app.