Privacy Policy
Last updated: August 20, 2026
This policy explains how Kurcz Software GmbH processes personal data when you use Coauthr. It also explains what collaborators can see and which document data never enters analytics.
Controller
Kurcz Software GmbH Widmaierstraße 60 70567 Stuttgart, Germany kevin@kurczsoftware.com
What Coauthr processes
- Account data: email address, profile choices, active sessions, plan, entitlements, and subscription status.
- Document data: published HTML, optional Markdown source, versions, comments, proposed edits, attachments, projects, and access invitations.
- Agent data: hashed agent tokens, terminal labels, publishing activity, and short-lived live-session and presence records.
- Service data: sanitized routes, release information, opaque document or project identifiers, interaction type, and server-confirmed publishing, review, subscription, and error events.
- Payment data: Paddle customer, transaction, and subscription identifiers. Kurcz does not store full card details.
Why we process it
- To create your account, publish documents, manage collaboration, and provide paid features under our contract with you.
- To secure accounts, prevent payment or sharing abuse, diagnose failures, and measure whether the service works, based on our legitimate interests in operating Coauthr.
- To connect activity across browser visits only after you allow optional analytics. You may withdraw that consent in Settings.
- To comply with tax, accounting, fraud-prevention, and other legal obligations that apply to Kurcz or its payment provider.
Service providers
Kurcz uses Convex for application data and first-party service measurement, Vercel for hosting and web performance, Resend for email, PostHog EU Cloud for operational diagnostics and optional product analytics, and Paddle for payments. EU regions are selected where offered. Data processing agreements and appropriate transfer safeguards apply.
Cookies and analytics
Essential first-party storage keeps sessions, security state, analytics choice, and display preferences. Coauthr does not use advertising cookies.
Optional analytics creates a random first-party browser identifier only after you allow it. PostHog uses memory persistence and session recording is disabled. Coauthr never sends document text, comments, proposed edit text, email addresses, share keys, invite tokens, or agent tokens to analytics.
Retention and deletion
Account data is kept while your Kurcz account exists. Account deletion immediately closes Coauthr access and public links, then removes documents, versions, comments, edits, attachments, tokens, invitations, and presence records in bounded background batches.
Coauthr raw first-party journey events are kept for up to 365 days and first-party exception records for 90 days. PostHog EU event history follows its active one-year retention window. Payment providers may retain transaction records under their legal obligations.
Your rights
Depending on where you live, you may access, correct, erase, restrict, or port your personal data, withdraw consent, and object to processing based on legitimate interests. Delete your account from account settings or email kevin@kurczsoftware.com. You may also complain to a data protection authority.
Changes to this policy
We update this policy when Coauthr's data practices, providers, or legal obligations change. The date above identifies the current version, and we will provide notice when a change materially affects your rights.