Combra
TermsPrivacyDPASub-processors

Combra — Privacy Policy

Last updated: 6 July 2026

This Privacy Policy explains how Fabrique-Futur LLC, a Wyoming limited liability company ("Fabrique-Futur," "we," "us," "our"), handles personal data in connection with Combra (the "Service") at combra.ai.

Combra is a business-to-business service. This policy covers personal data we handle as a controller — that is, where we decide how and why it is processed (for example, account and billing data, and data about how the Service is used). For the content you and your team submit to the Service ("Customer Data"), we act as a processor on your organization's behalf; that processing is governed by our Data Processing Addendum, and your organization's own privacy notice applies to the individuals in that content.


1. Who we are and how to contact us

Fabrique-Futur LLC is the controller for the processing described in this policy.

  • Privacy, legal, and security contact: [email protected]
  • General enquiries: [email protected]
  • Postal: 30 N Gould St, Ste R, Sheridan, WY 82801, United States
  • EU / UK representative (Article 27): Where required under Article 27 of the EU or UK GDPR, our representative's details are available on request at [email protected].

2. The data we collect

You give us:

  • Account data — name, work email, password (stored only as a hash), and your role and team memberships within a workspace.
  • Workspace / company data — company name, description, team size, and settings.
  • Billing data — plan, seat count, and subscription status. Card payments are handled by Stripe; we do not store full card numbers.
  • Communications — messages you send us (support, email) and your email preferences (for example, digest opt-in).
  • Customer Data — documents, files, messages, queries, and other content you or your team submit or connect. We process this as a processor (see the DPA). It may contain personal data about your personnel or third parties; you are responsible for having a lawful basis to provide it.

We collect automatically:

  • Usage and log data — non-content metadata about use of the Service: actions taken, whether a query was answered, feature usage, request identifiers, timestamps, and approximate technical data (browser/device type). We use this metadata for security, debugging, billing/metering, and to improve the Service. The content of your queries and the answers generated is Customer Data: we process it only for the Permitted Purposes described in Section 3, and use it to improve the Service only in aggregated or de-identified form.
  • Cookies — see Section 6.
  • Product analytics — see Section 7.

From third parties you connect:

  • When you connect a source such as Slack, Notion, or Google Drive, we receive content and limited metadata (for example, a Slack user's name and email for attribution) within the scope you authorize. Connector credentials are stored encrypted.

We do not intentionally collect special categories of data (such as health or biometric data), and you should not submit them to the Service unless separately agreed in writing.


3. How we use data

We use personal data to:

  • provide, operate, secure, and maintain the Service, including authentication, tenant isolation, and access control;
  • generate answers and Output from Customer Data in response to your queries;
  • process billing and manage subscriptions;
  • meter usage and enforce plan limits and rate limits;
  • provide support and respond to requests;
  • send service and transactional messages, and (with your opt-in or as permitted) digests;
  • monitor, debug, and improve the Service and develop new features;
  • detect, prevent, and address security incidents, fraud, and abuse;
  • comply with legal obligations and enforce our Terms.

We do not sell personal data. We do not use Customer Data, your queries, or the Output generated for you to train our own generative-AI or machine-learning models. See Section 8 for how AI sub-processors handle this content.

The "monitor, debug, and improve / develop new features" use above applies to account, usage, and log data that we control. We use Customer Data only to provide, secure, support, and debug the Service for you and on your organization's instructions (see the Data Processing Addendum). We do not use Customer Data to improve or develop our products except as aggregated or de-identified data that cannot reasonably be used to identify you or any individual.


4. Legal bases (EU / UK GDPR)

Where the EU or UK GDPR applies, we rely on:

  • Performance of a contract — to provide the Service to you and your organization.
  • Legitimate interests — to secure, debug, and improve the Service, prevent abuse, and run our business, balanced against your rights.
  • Consent — for non-essential cookies/analytics where required, and for optional communications; you can withdraw consent at any time.
  • Legal obligation — to comply with applicable law.

For Customer Data, your organization (the controller) is responsible for the legal basis; we process it on its instructions.


5. How we share data

We share personal data with:

  • Processors, sub-processors, and service providers that help us run the Service (hosting, AI inference, email, billing, analytics), under contracts that restrict their use of the data. See our Sub-processor List.
  • Professional advisers (legal, accounting) under confidentiality, where needed.
  • Authorities or third parties where required by law, to protect rights and safety, or to enforce our Terms.
  • A successor in a merger, acquisition, financing, or sale of assets, subject to this policy.

We do not sell personal data and do not share it for cross-context behavioral advertising.


6. Cookies

We use these cookies:

  • Strictly necessary cookies — for authentication and to keep you signed in and scoped to your active workspace (for example, combra_session and combra_company). These are required for the Service to function and do not need consent.
  • Analytics cookies — used by our product-analytics provider (Section 7). Where consent is required (for example, in the EU/UK), these are set only after you consent, and you can decline or withdraw consent without losing access to the core Service.

You can also control cookies through your browser. Blocking strictly necessary cookies may break sign-in.


7. Product analytics

We use PostHog to record feature usage and error paths so we can operate and improve the Service. PostHog receives product-usage metadata only, never the content of your documents, queries, or answers. We run PostHog on PostHog Cloud US, so this analytics data is hosted in the United States. Where PostHog processes personal data of individuals in the EEA or UK, PostHog states that it participates in the EU-US Data Privacy Framework (with the UK Extension where applicable), and the parties additionally rely on Standard Contractual Clauses (with the UK Addendum or IDTA where required). Our PostHog integration runs cookieless (no analytics cookies or device storage), with autocapture and session recording disabled, and we do not permit PostHog to use our analytics data to train its AI models. PostHog publishes its own privacy and sub-processor information at posthog.com.

Our public marketing website at combra.ai uses Umami, a cookieless, self-hosted analytics tool that does not set cookies or track you across sites; it collects only aggregate, anonymous visit statistics and needs no consent banner.

We do not use Google Analytics, advertising pixels, or cross-site tracking.


8. How AI processing works

Combra answers questions and extracts knowledge using retrieval and large language models. To do this, relevant Customer Data (such as document text and your queries) is sent to our AI sub-processors to produce embeddings, rank results, and generate answers:

  • Generation (answers): runs through DigitalOcean's GenAI / serverless inference, which serves the underlying models (including Claude and open models). Under DigitalOcean's commercial terms, this data is not used to train foundation models.
  • Embeddings and reranking: provided by Jina AI, which processes document text and queries to produce embeddings and rank retrieved results.

We do not make decisions about individuals that produce legal or similarly significant effects based solely on automated processing. You remain responsible for reviewing AI Output before relying on it (see the Terms).


9. International transfers

We are based in the United States and use sub-processors in the US and the EU. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, primarily the 2021 EU Standard Contractual Clauses (with the UK Addendum / IDTA for UK transfers), and, for sub-processors that are certified, the EU-US Data Privacy Framework and its UK Extension as an additional basis. You can request information about these safeguards at [email protected].


10. Retention

  • Customer Data is retained while your account is active. After termination you have 30 days to export it; we delete or de-identify it from active systems within 60 days of termination, and backups are purged on the normal cycle within 90 days, except where law requires longer. The Service uses an archive-then-delete model: deleting items first archives them (recoverable and excluded from results), and permanent deletion removes them; cascaded data (such as derived facts and embeddings) is removed with the source. For Personal Data within Customer Data, the DPA controls.
  • Account and billing data is retained for the life of the account and then for up to 7 years as needed for legal, tax, accounting, and dispute purposes.
  • Logs and usage data are retained for up to 18 months for security, debugging, and product analysis, then deleted or aggregated.
  • Product-analytics data is retained per our analytics configuration, generally no longer than 12 months in identifiable form.
  • Authentication tokens are short-lived: sessions expire (24-hour maximum) and can be revoked; access tokens have enforced maximum lifetimes.
  • Residual copies in routine backups are deleted on the normal backup cycle (no later than 90 days).

11. Security

We protect personal data with measures including tenant isolation via database row-level security, role- and team-based access controls, encryption in transit (TLS) and encryption at rest for stored credentials, short-lived revocable sessions, rate limiting and login lockout, signed-and-replay-protected integration webhooks, and PII-minimizing error logging. Annex II of the DPA contains the full description.

If a breach affects your personal data, we will notify you and the relevant authorities as required by applicable law, including US state data-breach-notification laws and, where it applies, the GDPR.


12. Your rights

Depending on where you live, you may have rights to:

  • access a copy of your personal data;
  • rectify inaccurate data;
  • erase data ("right to be forgotten");
  • restrict or object to processing;
  • port data to another provider;
  • withdraw consent where processing is based on consent;
  • not be discriminated against for exercising privacy rights.

To exercise these rights, contact [email protected]. We will verify your request and respond within the time required by law. If you are an individual whose data appears within a customer's Customer Data, please contact that customer (the controller); we will assist them as their processor.

United States

We honor privacy rights across the United States. We do not sell or share personal information — not for money, and not for cross-context behavioral or targeted advertising — and we do not use sensitive personal information for any purpose beyond providing the Service. Wherever you live in the US, you can ask us to access, correct, or delete your personal information, and you may use an authorized agent. Contact [email protected]; we will not discriminate against you for exercising these rights. If we deny a request, you may appeal by replying to our decision or emailing [email protected] with "Privacy appeal."

  • California (CCPA/CPRA). In the preceding 12 months we have collected the following categories of personal information for the business purposes in Section 3, retaining each only as long as described in Section 10:

    • Identifiers (name, email, account identifiers) — to operate accounts and provide the Service.
    • Commercial information (plan, billing, subscription status) — to bill and manage subscriptions.
    • Internet/network activity (usage and log data) — for security, debugging, and analytics.
    • Other information you submit (the contents of Customer Data, which may contain personal information) — processed as a service provider on your organization's behalf.

    We collect these from you, your Authorized Users, your connected sources, and automatically through your use of the Service. We disclose them only to the sub-processors and recipients in Section 5, for business purposes. We do not "sell" or "share" personal information as defined by the CCPA, and we do not use or disclose sensitive personal information beyond permitted purposes. California residents have the rights to know/access, delete, correct, and opt out of sale/sharing — there is nothing to opt out of, as we do not sell or share.

  • Other US states. Where another US state's comprehensive privacy law applies to you (for example, Virginia, Colorado, Connecticut, Texas, Utah, or Oregon), you may have rights such as to access, correct, or delete your personal information and to opt out of its sale, targeted advertising, or certain profiling. Some of these laws apply only to data about individuals acting in a personal (not commercial) capacity. In any case there is nothing to opt out of — we do not sell data, share it for cross-context advertising, or run such profiling.

EU / EEA

You may lodge a complaint with your local data-protection supervisory authority.

UK

Under the Data (Use and Access) Act 2025, you may complain to us directly first. Email [email protected] with "Data protection complaint" in the subject. We will acknowledge your complaint within 30 days, investigate it, and respond with the outcome without undue delay. If you are not satisfied, you may escalate to the UK Information Commissioner's Office (ICO) at ico.org.uk.


13. Children

The Service is for business use and is not directed to children. We do not knowingly collect personal data from children through account registration or use of the Service.

  • For data we control (such as account data): if we learn we have collected personal data from a child under 18, we will delete it.
  • For Customer Data (which we process on a customer's behalf as a processor): we do not control its contents. If a child's personal data appears within a customer's Customer Data, the customer is the controller; please contact that customer, and we will assist them in addressing the request as their processor.

14. Changes

We may update this policy. If changes are material, we will give notice (by email or in-product) before they take effect. The "Last updated" date shows the current version.


15. Contact

Questions or requests: [email protected] Fabrique-Futur LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States

© 2026 Fabrique-Futur LLC[email protected] · combra.ai