Combra
TermsPrivacyDPASub-processorsLicenses

Combra — Privacy Policy

Last updated: 6 July 2026

This Privacy Policy explains how Fabrique-Futur LLC, a Wyoming limited liability company ("Fabrique-Futur," "we," "us," "our"), handles personal data in connection with Combra (the "Service") at combra.ai.

Combra is a business-to-business service. This policy covers personal data we handle as a controller — that is, where we decide how and why it is processed (for example, account and billing data, and data about how the Service is used). For the content you and your team submit to the Service ("Customer Data"), we act as a processor on your organization's behalf; that processing is governed by our Data Processing Addendum, and your organization's own privacy notice applies to the individuals in that content.


1. Who we are and how to contact us

Fabrique-Futur LLC is the controller for the processing described in this policy.

  • Privacy, legal, and security contact: [email protected]
  • General enquiries: [email protected]
  • Postal: 30 N Gould St, Ste R, Sheridan, WY 82801, United States
  • EU / UK representative (Article 27): Where required under Article 27 of the EU or UK GDPR, our representative's details are available on request at [email protected].

2. The data we collect

You give us:

  • Account data — name, work email, password (stored only as a hash), and your role and team memberships within a workspace.
  • Workspace / company data — company name, description, team size, and settings.
  • Billing data — plan, seat count, and subscription status. Card payments are handled by Stripe; we do not store full card numbers.
  • Communications — messages you send us (support, email) and your email preferences (for example, digest opt-in).
  • Customer Data — documents, files, messages, queries, and other content you or your team submit or connect. We process this as a processor (see the DPA). It may contain personal data about your personnel or third parties; you are responsible for having a lawful basis to provide it.

We collect automatically:

  • Usage and log data — non-content metadata about use of the Service: actions taken, whether a query was answered, feature usage, request identifiers, timestamps, and approximate technical data (browser/device type). We use this metadata for security, debugging, billing/metering, and to improve the Service. The content of your queries and the answers generated is Customer Data: we process it only for the Permitted Purposes described in Section 3, and use it to improve the Service only in aggregated or de-identified form.
  • Cookies — see Section 6.
  • Product analytics — see Section 7.

From third parties you connect:

  • When you connect a source such as Slack, Notion, or Google Drive, we receive content and limited metadata (for example, a Slack user's name and email for attribution) within the scope you authorize. Connector credentials are stored encrypted.

We do not intentionally collect special categories of data (such as health or biometric data), and you should not submit them to the Service unless separately agreed in writing.


3. How we use data

We use personal data to:

  • provide, operate, secure, and maintain the Service, including authentication, tenant isolation, and access control;
  • generate answers and Output from Customer Data in response to your queries;
  • process billing and manage subscriptions;
  • meter usage and enforce plan limits and rate limits;
  • provide support and respond to requests;
  • send service and transactional messages, and (with your opt-in or as permitted) digests;
  • monitor, debug, and improve the Service and develop new features;
  • detect, prevent, and address security incidents, fraud, and abuse;
  • comply with legal obligations and enforce our Terms.

We do not sell personal data. We do not use Customer Data, your queries, or the Output generated for you to train our own generative-AI or machine-learning models. See Section 8 for how AI sub-processors handle this content.

The "monitor, debug, and improve / develop new features" use above applies to account, usage, and log data that we control. We use Customer Data only to provide, secure, support, and debug the Service for you and on your organization's instructions (see the Data Processing Addendum). We do not use Customer Data to improve or develop our products except as aggregated or de-identified data that cannot reasonably be used to identify you or any individual.


4. Legal bases (EU / UK GDPR)

Where the EU or UK GDPR applies, we rely on:

  • Performance of a contract — to provide the Service to you and your organization.
  • Legitimate interests — to secure, debug, and improve the Service, prevent abuse, and run our business, balanced against your rights.
  • Consent — for optional communications, such as the digest; you can withdraw consent at any time.
  • Legal obligation — to comply with applicable law.

For Customer Data, your organization (the controller) is responsible for the legal basis; we process it on its instructions.


5. How we share data

We share personal data with:

  • Processors, sub-processors, and service providers that help us run the Service (hosting, AI inference, email, billing, analytics), under contracts that restrict their use of the data. See our Sub-processor List.
  • Professional advisers (legal, accounting) under confidentiality, where needed.
  • Authorities or third parties where required by law, to protect rights and safety, or to enforce our Terms.
  • A successor in a merger, acquisition, financing, or sale of assets, subject to this policy.

We do not sell personal data and do not share it for cross-context behavioral advertising.


6. Cookies

We set strictly necessary cookies only — for authentication and to keep you signed in and scoped to your active workspace (combra_session, combra_company, and combra_ds, a marker that records that your session cookie has been reissued for our current domain layout). These are required for the Service to function and do not need consent.

We set no analytics or advertising cookies. Our product analytics runs cookieless and stores nothing on your device (Section 7), so there is no analytics cookie to consent to or decline.

You can control cookies through your browser. Blocking strictly necessary cookies will break sign-in.


7. Product analytics

We use PostHog to record feature usage and error paths so we can operate and improve the Service. PostHog receives product-usage metadata only, never the content of your documents, queries, or answers. We run PostHog on PostHog Cloud US, so this analytics data is hosted in the United States. Where PostHog processes personal data of individuals in the EEA or UK, PostHog states that it participates in the EU-US Data Privacy Framework (with the UK Extension where applicable), and the parties additionally rely on Standard Contractual Clauses (with the UK Addendum or IDTA where required). Our PostHog integration runs cookieless (no analytics cookies or device storage), with autocapture and session recording disabled, and we do not permit PostHog to use our analytics data to train its AI models. PostHog publishes its own privacy and sub-processor information at posthog.com.

Our public marketing website at combra.ai uses Umami, a cookieless, self-hosted analytics tool that does not set cookies or track you across sites; it collects only aggregate, anonymous visit statistics and needs no consent banner.

We do not use Google Analytics, advertising pixels, or cross-site tracking.


8. How AI processing works

Combra answers questions and extracts knowledge using retrieval and large language models. To do this, relevant Customer Data (such as document text and your queries) is sent to our AI sub-processors to produce embeddings, rank results, and generate answers:

  • Generation (answers, classification, fact extraction, and reading page images): runs on Google's Gemini API, called directly. When Gemini is unavailable, the same request falls back to Anthropic's Claude API, also called directly, so the Service keeps answering. We contract with both providers for business use of their APIs and do not permit either to use Customer Data to train its models; each provider's API terms govern data submitted to it.
  • Embeddings and reranking: provided by Jina AI. Every chunk of every document you ingest is sent to Jina to be embedded, as is every query you ask. Jina's published terms reserve a right to use customer data in anonymized form to improve its own AI, and we tell you so rather than claim a protection we do not hold.
  • Voice input: when you speak to the Service instead of typing, the audio is transcribed by Deepgram.
  • Web search: when nothing in your workspace grounds a question, the Service can answer from the public web instead. A short search query rewritten from your question is sent to a search backend — our own self-hosted instance where one is configured, otherwise DuckDuckGo — and the Service fetches the public pages it cites. Document text is never sent to a search engine.

If you bring your own key. A workspace can supply its own Google or Anthropic API key for answer generation. The same two vendors then receive the same content, but the call runs under your account and your agreement with that provider, so their terms with you govern it. Embeddings, reranking, and fact extraction continue to run on our own keys.

We do not make decisions about individuals that produce legal or similarly significant effects based solely on automated processing. You remain responsible for reviewing AI Output before relying on it (see the Terms).


9. International transfers

We are based in the United States and use sub-processors in the US and the EU. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, primarily the 2021 EU Standard Contractual Clauses (with the UK Addendum / IDTA for UK transfers), and, for sub-processors that are certified, the EU-US Data Privacy Framework and its UK Extension as an additional basis. You can request information about these safeguards at [email protected].


10. Retention

  • Customer Data is retained while your account is active. We do not age it out: nothing in an active workspace is deleted on a timer. After termination you have 30 days to export it; we delete or de-identify it from active systems within 60 days of termination, and backups are purged on the normal cycle within 90 days, except where law requires longer. For Personal Data within Customer Data, the DPA controls.
  • Deleting a document happens in two steps. Archiving takes it out of search and answers at once but keeps the file and everything derived from it, so you can restore it. Permanent deletion removes the database row, the chunks and extracted facts that cascade from it, and the stored file itself. Archived items are kept until someone permanently deletes them; nothing promotes an archive to a deletion automatically.
  • Questions and answers are recorded and kept for the life of the workspace. Deleting a document does not retract an answer that already quoted it, and the Service has no self-service control for removing a past question or answer. Erasure requests go through Section 12.
  • When a person leaves a workspace, we remove their membership and revoke every share link they created. Their personal space and its contents are not deleted and stop being reachable by anyone through the Service. Removing or handing over that content is a Section 12 request.
  • Account and billing data is retained for the life of the account and then for up to 7 years as needed for legal, tax, accounting, and dispute purposes.
  • Logs and usage data are retained for up to 18 months for security, debugging, and product analysis, then deleted or aggregated.
  • Product-analytics data is retained per our analytics configuration, generally no longer than 12 months in identifiable form.
  • Authentication tokens are short-lived: sessions expire (24-hour maximum) and can be revoked; access tokens have enforced maximum lifetimes.
  • Residual copies in routine backups are deleted on the normal backup cycle (no later than 90 days).

11. Security

We protect personal data with measures including tenant isolation via database row-level security, role- and team-based access controls, encryption in transit (TLS), authenticated encryption at rest for the credentials we hold on your behalf (connector OAuth tokens and any model-provider API key you supply), short-lived revocable sessions, rate limiting and login lockout, signed-and-replay-protected integration webhooks, and PII-minimizing error logging. Annex II of the DPA contains the full description.

If a breach affects your personal data, we will notify you and the relevant authorities as required by applicable law, including US state data-breach-notification laws and, where it applies, the GDPR.


12. Your rights

Depending on where you live, you may have rights to:

  • access a copy of your personal data;
  • rectify inaccurate data;
  • erase data ("right to be forgotten");
  • restrict or object to processing;
  • port data to another provider;
  • withdraw consent where processing is based on consent;
  • not be discriminated against for exercising privacy rights.

To exercise these rights, contact [email protected]. We will verify your request and respond within the time required by law. If you are an individual whose data appears within a customer's Customer Data, please contact that customer (the controller); we will assist them as their processor.

United States

We honor privacy rights across the United States. We do not sell or share personal information — not for money, and not for cross-context behavioral or targeted advertising — and we do not use sensitive personal information for any purpose beyond providing the Service. Wherever you live in the US, you can ask us to access, correct, or delete your personal information, and you may use an authorized agent. Contact [email protected]; we will not discriminate against you for exercising these rights. If we deny a request, you may appeal by replying to our decision or emailing [email protected] with "Privacy appeal."

  • California (CCPA/CPRA). In the preceding 12 months we have collected the following categories of personal information for the business purposes in Section 3, retaining each only as long as described in Section 10:

    • Identifiers (name, email, account identifiers) — to operate accounts and provide the Service.
    • Commercial information (plan, billing, subscription status) — to bill and manage subscriptions.
    • Internet/network activity (usage and log data) — for security, debugging, and analytics.
    • Other information you submit (the contents of Customer Data, which may contain personal information) — processed as a service provider on your organization's behalf.

    We collect these from you, your Authorized Users, your connected sources, and automatically through your use of the Service. We disclose them only to the sub-processors and recipients in Section 5, for business purposes. We do not "sell" or "share" personal information as defined by the CCPA, and we do not use or disclose sensitive personal information beyond permitted purposes. California residents have the rights to know/access, delete, correct, and opt out of sale/sharing — there is nothing to opt out of, as we do not sell or share.

  • Other US states. Where another US state's comprehensive privacy law applies to you (for example, Virginia, Colorado, Connecticut, Texas, Utah, or Oregon), you may have rights such as to access, correct, or delete your personal information and to opt out of its sale, targeted advertising, or certain profiling. Some of these laws apply only to data about individuals acting in a personal (not commercial) capacity. In any case there is nothing to opt out of — we do not sell data, share it for cross-context advertising, or run such profiling.

EU / EEA

You may lodge a complaint with your local data-protection supervisory authority.

UK

Under the Data (Use and Access) Act 2025, you may complain to us directly first. Email [email protected] with "Data protection complaint" in the subject. We will acknowledge your complaint within 30 days, investigate it, and respond with the outcome without undue delay. If you are not satisfied, you may escalate to the UK Information Commissioner's Office (ICO) at ico.org.uk.


13. Children

The Service is for business use and is not directed to children. We do not knowingly collect personal data from children through account registration or use of the Service.

  • For data we control (such as account data): if we learn we have collected personal data from a child under 18, we will delete it.
  • For Customer Data (which we process on a customer's behalf as a processor): we do not control its contents. If a child's personal data appears within a customer's Customer Data, the customer is the controller; please contact that customer, and we will assist them in addressing the request as their processor.

14. Changes

We may update this policy. If changes are material, we will give notice (by email or in-product) before they take effect. The "Last updated" date shows the current version.


15. Contact

Questions or requests: [email protected] Fabrique-Futur LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States

© 2026 Fabrique-Futur LLC[email protected] · combra.ai