Privacy
Last updated September 23, 2026
BORGWARE PTY LTD, trading as Kensa (“Kensa”, “we”, “us”, or “our”), operates the Kensa service at kensa.sh, including the web application, API, MCP server, and documentation (the “Service”). This policy explains what personal data we collect, how we use and share it, and the choices you have. For connected services such as Langfuse, this policy covers the data Kensa receives through the integration.
1. Personal data we collect
Directly from you
- Account details: your name and email address when you sign up with an email address and password or connect your GitHub identity.
- Organization and project details: names and settings you create for your projects.
- Communications: anything you send through the in-app feedback form or by emailing us directly.
- Payment details: if you subscribe to a paid plan, billing information collected and processed by our payment processor.
From using the Service
- Trace and telemetry data: spans, inputs, outputs, and metadata your agents send to Kensa over OpenTelemetry, the Langfuse integration, or MCP tools, for the projects you connect. This is redacted before it is stored; see “How we handle trace data” below.
- Repository content: if you connect a GitHub repository, Kensa reads selected files using a repository-scoped read token, only when you request an initial agent job draft, and sends their contents to our model provider to generate that draft. Repository access is read-only and scoped to the selected repository.
- Usage and device data: IP address, browser and device information, and how you interact with the Service, collected for security, debugging, and product analytics.
Sensitive data and age requirements
Kensa does not knowingly collect sensitive categories of personal data, such as health, biometric, or genetic data, about you, and the Service is not directed at anyone under 18.
2. How we handle trace data
- Traces are redacted before storage; only the redacted version is retained.
- Use trace and span IDs that are free of personal data; Kensa preserves these identifiers for correlation across systems.
- Redacted traces are retained according to your plan: 14 days on Free, 90 days on Pro, and a custom retention period on Enterprise. Deleting a project or account removes its associated traces.
- Project API keys authenticate trace ingest and are shown once. Store them securely, and generate a replacement if one is exposed.
- OAuth-connected agents get project-scoped access you can revoke from Agent connections. Agent access and tracing keys are managed independently.
- Langfuse credentials you provide are encrypted in storage and hidden after submission.
3. How we use personal data
- Provide, maintain, and secure the Service.
- Detect potential issues in your agents' traces and generate agent job drafts and issue evidence, which may involve sending trace content or selected repository files to our model provider.
- Communicate with you about your account, the Service, and its updates.
- Monitor for abuse, debug problems, and enforce our Terms.
- Comply with legal obligations.
We do not use your trace data or repository content to train our own models, and our agreements with model providers do not permit them to train on it either.
4. How we share personal data
- Subprocessors who help us run the Service: infrastructure and hosting, product analytics, and AI providers that support issue detection and context drafts.
- Integrations you connect: if you connect GitHub or Langfuse, data flows to and from those services under their own terms; Kensa only accesses what those integrations authorize.
- Legal and safety: when required by law, or to protect the rights, safety, or property of Kensa, our users, or the public.
We never use your data for training models.
5. Retention
Redacted trace retention follows your plan, as described above. We retain other personal data for as long as your account or project exists, or as needed to comply with legal obligations, resolve disputes, and enforce agreements. Deleting a project or account removes all its associated data, including redacted traces.
6. Security
Kensa protects trace data through redaction before storage, project-scoped access, and encrypted integration credentials. Our Security page explains these controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict some processing. You can delete a project or your account directly from the app, or email us to exercise any of these rights.
8. International data transfers
Kensa and its subprocessors may process personal data in countries other than the one you're in. Where we transfer personal data internationally, we take steps to protect it in accordance with this policy.
9. Children
The Service is not directed at children, and we do not knowingly collect personal data from anyone under 18.
10. Changes to this policy
We'll update the date at the top of this page when we make changes, and give more prominent notice for changes we consider material.
11. Contact
If you have any questions about this policy, contact us at support@kensa.sh.