Legal
Privacy Policy
Reworks Intelligence LLP(“GetConsenso,” “we,” “us”) operates GetConsenso, a hosted service that helps engineering teams agree on API contracts, generate types and mocks, and catch breaking changes before they ship. This policy explains what personal data we collect when you use GetConsenso, why we collect it, who we share it with, and the choices you have.
This policy applies to the GetConsenso web application, our CLI (ckit), and our public API. It does not cover third-party sites we link to (e.g. GitHub, Linear, Slack) — their own privacy policies govern how they handle your data.
1. What we collect
Account information. When you sign up, our authentication provider (Clerk) collects your name, email address, and — if you use Google or GitHub sign-in — the basic profile fields those providers share with us. We never see or store your password directly.
Workspace content. The API contracts, endpoints, schemas, comments, and review history you create in GetConsenso. This is your data — we store it to run the product, not to use it for anything else.
Connected-account tokens. If you connect GitHub, Linear, Jira, or Slack, we store an encrypted access token so GetConsenso can publish specs, sync tickets, or post notifications on your behalf. Tokens are encrypted at rest (AES-256-GCM) and are never displayed back to you or anyone else in plaintext.
Billing information. For paid plans, payment is processed by Razorpay. We store your plan, billing status, and transaction references — GetConsenso never sees or stores your full card or bank details; Razorpay handles that directly under PCI-DSS scope.
Usage & log data. Standard operational data — IP address, browser/device type, timestamps, API request counts, and error logs — used to keep the service reliable, secure, and within fair-usage limits.
Cookies. Session cookies from Clerk to keep you signed in, and minimal first-party cookies for preferences (like theme). We do not use third-party advertising trackers.
2. How we use it
- To provide, maintain, and secure the GetConsenso service.
- To generate types, mocks, and diffs from the contracts you create.
- To publish or sync content to third-party services you have explicitly connected.
- To send transactional email (approvals, drift alerts, billing receipts) — never marketing email without your consent.
- To enforce fair-usage limits and prevent abuse of the platform.
- To comply with legal obligations, such as tax and billing records.
We do not sell your personal data, and we do not use your workspace content (your API contracts) to train any AI model. If you bring your own AI key for AI-assisted features, your prompts and contract content are sent directly to that provider under your own account with them, not ours.
3. Who we share it with
We use a small set of sub-processors to run the service. Each is bound by its own data-processing terms and only receives the minimum data it needs to do its job:
- Vercel — application hosting and edge network.
- Neon — our Postgres database (encrypted at rest).
- Clerk — authentication and session management.
- Razorpay — payment processing for INR billing.
- Resend — transactional email delivery.
- GitHub, Linear, Jira, Slack — only if and when you explicitly connect your account to enable publishing or ticket sync.
We disclose data to law enforcement or regulators only when legally required to, and we will notify affected users where the law permits it.
4. Data retention
We keep your workspace content for as long as your account is active. If you delete a project or your account, we remove the underlying data from production systems within 30 days, subject to what we must retain for billing, tax, or legal records. Audit logs are retained separately for security and compliance purposes, per your plan's retention window.
5. Your rights
Depending on where you're located, you may have rights under applicable law — including the EU/UK GDPR and India's Digital Personal Data Protection Act, 2023 — to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can manage most of this yourself from your account settings; for anything else, email us at sales@reworksintelligence.com and we will respond within 30 days.
6. International transfers
GetConsenso is operated from India, and our infrastructure providers operate global networks. Where personal data is transferred internationally, we rely on our providers' own safeguards (such as standard contractual clauses) to protect it in transit and at rest.
7. Children's privacy
GetConsenso is a developer tool intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
8. Security
We take reasonable technical and organizational measures to protect your data — see our Security page for details on encryption, access controls, and how to report a vulnerability.
9. Changes to this policy
We'll update the “Last updated” date above whenever this policy changes, and post material changes here. Continued use of GetConsenso after a change means you accept the updated policy.
10. Contact us
Questions about this policy or your data? Email sales@reworksintelligence.com.
Last updated: August 15, 2026