Scope of this notice
This draft describes the limited hosted beta for ZIP source reviews, saved reports and editor review packets. Render serves the website and runs the hosted source scanner. Supabase provides account authentication and private storage for uploads, jobs, projects and reports. The separate local app and CLI have different processing and storage settings. Operator identity, public privacy contact and applicable rights procedures remain pending.
Account and project information
Supabase authenticates your account and stores workspace and project records. Signing in uses your email and password through that service. Produra also processes project names, scan identifiers, source findings, usage counts and security-related session information. Account email delivery uses the SMTP provider configured in Supabase; the current account setup uses Resend.
Code and source reports
A submitted ZIP can include personal information or secrets in source code. Remove live credentials and unnecessary customer records before uploading it. Starting a scan stores the archive privately in Supabase; the hosted scanner on Render retrieves it for bounded source inspection and saves the resulting report in Supabase. This beta does not run your application, install its dependencies or execute its build scripts or tests. Reports can include source excerpts; redaction can miss secrets or personal information.
AI and editor tools
Guided AI review is off in this hosted beta, and Produra does not send your source to a model provider for that feature. You can download or copy report evidence and an editor review packet. Sharing that material with an editor or model provider is a separate action under your chosen tool’s settings. The hosted beta does not provide a scan MCP connection, retained-source repair workflow or application verification.
Connected services
The hosted beta accepts project ZIPs and does not connect to GitHub or store GitHub authorization tokens. It does not offer account settings inspection. The separate local app can have optional integrations with their own controls and storage. Do not paste broad account credentials into source or review packets.
Retention and deletion
Source uploads have a 24-hour expiry window and may be queued for earlier cleanup when processing finishes. Saved reports expire after 30 days. Scheduled maintenance processes eligible cleanup even when no visitor has the website open. Maintenance failures or delayed jobs can postpone physical deletion; an expiry time is not a promise of immediate erasure. This hosted beta does not retain a separate repair-source copy.
Your deletion controls
The report offers a control to delete that report and queue its uploaded source for cleanup. Usage, job and idempotency records may remain to prevent replay or allowance abuse. Other reports and downloaded copies must be handled separately. Provider backups, operational logs and legally required records may have separate retention. There is no self-service account-wide deletion screen in this beta. Contact the operator who provided access for an account request; the public privacy contact remains pending.
Cookies and other storage
The website uses cookies for sign-in, account email flows and request security. This build does not include third-party advertising or analytics scripts. Hosting providers may process network and operational information under their own policies. Security cookies are required for the account workflow.
Providers, locations and security
Render, Supabase and the configured email provider process information for this hosted beta. Their service arrangements can permit processing in multiple locations; this draft does not promise a particular data residency. Access checks, private storage policies and bounded processing reduce risk but do not make storage or transmission infallible.
Contact and rights
This draft still needs a named operator, reachable public privacy contact, applicable access and deletion procedure and any required processor agreements. During this limited beta, ask the person who provided access about access, correction, export or deletion. No jurisdiction, operator entity or certification is asserted here.