Skip to content

Privacy Policy

Last updated: August 20, 2026

This policy explains how Kurcz Software GmbH processes personal data when you use Coauthr. It also explains what collaborators can see and which document data never enters analytics.

Controller

Kurcz Software GmbH Widmaierstraße 60 70567 Stuttgart, Germany kevin@kurczsoftware.com

What Coauthr processes

  • Account data: email address, profile choices, active sessions, plan, entitlements, and subscription status.
  • Document data: published HTML, optional Markdown source, versions, comments, proposed edits, attachments, projects, and access invitations.
  • Agent data: hashed agent tokens, terminal labels, publishing activity, and short-lived live-session and presence records.
  • Service data: sanitized routes, release information, opaque document or project identifiers, interaction type, and server-confirmed publishing, review, subscription, and error events.
  • Payment data: Paddle customer, transaction, and subscription identifiers. Kurcz does not store full card details.

Why we process it

  • To create your account, publish documents, manage collaboration, and provide paid features under our contract with you.
  • To secure accounts, prevent payment or sharing abuse, diagnose failures, and measure whether the service works, based on our legitimate interests in operating Coauthr.
  • To connect activity across browser visits only after you allow optional analytics. You may withdraw that consent in Settings.
  • To comply with tax, accounting, fraud-prevention, and other legal obligations that apply to Kurcz or its payment provider.

Who can see document data

Project owners and staff control document access. Invited reviewers see the documents and discussion data their role permits. Anyone holding a public share link can read the linked document until the owner closes that access.

Reviewer email addresses are visible to project owners for access management. Other reviewers see display names, not email addresses.

Service providers

Kurcz uses Convex for application data and first-party service measurement, Vercel for hosting and web performance, Resend for email, PostHog EU Cloud for operational diagnostics and optional product analytics, and Paddle for payments. EU regions are selected where offered. Data processing agreements and appropriate transfer safeguards apply.

Cookies and analytics

Essential first-party storage keeps sessions, security state, analytics choice, and display preferences. Coauthr does not use advertising cookies.

Optional analytics creates a random first-party browser identifier only after you allow it. PostHog uses memory persistence and session recording is disabled. Coauthr never sends document text, comments, proposed edit text, email addresses, share keys, invite tokens, or agent tokens to analytics.

Retention and deletion

Account data is kept while your Kurcz account exists. Account deletion immediately closes Coauthr access and public links, then removes documents, versions, comments, edits, attachments, tokens, invitations, and presence records in bounded background batches.

Coauthr raw first-party journey events are kept for up to 365 days and first-party exception records for 90 days. PostHog EU event history follows its active one-year retention window. Payment providers may retain transaction records under their legal obligations.

Your rights

Depending on where you live, you may access, correct, erase, restrict, or port your personal data, withdraw consent, and object to processing based on legitimate interests. Delete your account from account settings or email kevin@kurczsoftware.com. You may also complain to a data protection authority.

Changes to this policy

We update this policy when Coauthr's data practices, providers, or legal obligations change. The date above identifies the current version, and we will provide notice when a change materially affects your rights.