Privacy Policy
Korbition ("we", "our", or "us") is dedicated to protecting your privacy and upholding the highest standards of data security. This Privacy Policy explains how our applications (including Rulekestra and associated integration connectors) process and protect information when you use our software and services.
1. Information We Process
Our automation engine processes data solely to fulfill user-configured workflow rules and notifications:
- Account & Authentication Data: OAuth tokens, tenant IDs, and authorized credentials necessary to communicate with your connected platforms (e.g., Atlassian Jira, GitHub, GitLab, Slack, Microsoft Teams, Google Workspace). All credentials are encrypted at rest using industry-standard cryptography.
- Workflow & Issue Context: Information contained in Jira issues, pull/merge requests, webhooks, or chat messages that trigger or are targeted by user-defined automations. We do not store or retain issue contents beyond the transient execution lifecycle required to process the action.
- Telemetry & Diagnostics: Aggregated execution counts, latency, error status codes, and non-identifying operational metrics required to monitor system stability.
2. Use of Third-Party APIs (Including Google API Services)
When connecting third-party services such as Google Workspace / Gmail:
- Our application accesses third-party APIs solely via user-approved OAuth 2.0 scopes (such as
gmail.sendfor automated email dispatch). - Google API Limited Use Disclosure: Korbition's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not read your inbox, store your private emails, or use your data for advertising or model training.
3. Data Retention & Tenant Isolation
Korbition enforces strict logical tenant isolation. Each tenant's configurations, rules, and encrypted credentials reside in isolated partitions. When an organization uninstalls our application or disconnects an integration, all associated tokens and configuration records are permanently purged.
4. Data Sharing & Disclosure
We do not sell, rent, or monetize your data. We only share information with third-party service providers (such as cloud hosting infrastructure) strictly necessary to run our service under binding data processing agreements, or as required by applicable law.
5. Security Standards
We implement robust technical and organizational security measures, including HTTPS/TLS 1.3 in transit, AES-256 encryption at rest, principle of least privilege, and automated vulnerability scanning.
6. Contact Us
For questions or requests regarding your data and privacy, please contact our security team at privacy@korbition.com or support@korbition.com.