Privacy Policy
Effective August 9, 2026
1. Who this policy covers
Aqenra (“we”, “us”) operates Aqenra (the “Service”), a client relationship management tool that lets a business (an “Organization”) manage its own clients, projects, tasks, invoices, and files, and optionally invite its clients to a limited self-service “Client Portal”.
This policy applies to everyone who uses the Service: staff members of an Organization, and Client Portal users invited by an Organization. If you are a client of one of our Organizations, that Organization — not us — controls the business data it enters about you, and is the right party to contact about that data. We act as the Organization’s data processor for that information.
2. Information we collect
We collect the following categories of information:
- Account information. Name, email address, and password for staff and Client Portal accounts. Passwords are handled entirely by our authentication provider (Supabase Auth) and stored as a salted hash — we never see or store a plaintext password.
- Organization and business data. Information an Organization’s staff enter into the Service, including organization/business identity details, client contacts, projects, tasks, invoices, comments, and activity history.
- Files you upload. Documents and other files attached to clients, projects, or tasks are stored in our file storage provider (Supabase Storage) under an access-controlled path scoped to the uploading Organization.
- Client Portal data. If an Organization invites you to its Client Portal, we store your name, email address, and the record of which Organization/client relationship the invitation was for.
- Notification preferences. Which in-app and email notifications you have chosen to receive.
- Technical data. Requests to the Service are processed transiently (e.g. to enforce rate limits that protect against abuse) and are not written to a persistent log we control. Our hosting provider (Vercel) may separately retain standard infrastructure request logs (such as IP address and timestamps) as part of operating the servers the Service runs on.
3. How we use information
We use the information above only to:
- Provide, operate, and maintain the Service, including authenticating you and enforcing access controls between Organizations;
- Send transactional email you’ve triggered or that is necessary to your account, such as invitations, password reset links, and notifications you’ve opted into;
- Detect, prevent, and respond to abuse, fraud, and security incidents; and
- Comply with legal obligations.
We do not sell personal information, and we do not use your data for advertising. We do not run any third-party analytics or advertising trackers on the Service, and the Service does not set any cookies beyond those strictly necessary to keep you signed in and remember your active workspace.
4. Who we share information with
We do not sell or rent personal information. We share information only with the service providers that operate the infrastructure the Service is built on (our “sub-processors”), each acting under its own data protection terms:
- Supabase — database hosting, authentication, and file storage.
- Resend — delivery of transactional email (invitations, password resets, notifications).
- Vercel — application hosting and infrastructure.
Staff data you enter about your own clients is visible to other staff members of your Organization according to their role, and to any Client Portal user you explicitly invite, scoped to that client’s own records. We otherwise never share your data across Organizations.
5. Payments
The Service does not currently process live payments through any payment provider. No card or bank details are collected or stored by us today. If we begin processing real subscription payments in the future, this policy will be updated first to name the payment processor and describe what it collects, before any such feature is enabled.
6. Data retention
We retain account and business data for as long as your account or Organization remains active. Read in-app notifications are automatically deleted 90 days after they are marked read; unread notifications are kept until you read or otherwise clear them.
We do not currently offer a self-service “delete my account” or “export my data” control inside the Service. To request deletion or a copy of your data, contact us using the details in Section 9 and we will handle the request manually.
7. Security
Data is encrypted in transit over HTTPS. Access to an Organization’s data is restricted to its own staff and any Client Portal users it invites; our infrastructure enforces this separation at the database and storage layer. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Changes to this policy
We may update this policy as the Service changes. If we make a material change, we will update the effective date above; continued use of the Service after a change constitutes acceptance of the updated policy.
9. Contact us
Questions about this policy, or requests to access, correct, or delete your data, can be sent to no-reply@aqenra.com. This policy is interpreted under the laws applicable in the jurisdiction in which the Service operator is located.