Kifas Privacy Policy
Effective Date: 22 May 2026 | Last Updated: 13 September 2026
This Privacy Policy describes how Kifas Labs Ltd ("Kifas," "we," "us") collects, uses, discloses, and protects personal data in connection with kifas.io and the Services. Capitalized terms not defined here have the meanings in the Terms of Service.
GEOGRAPHIC SCOPE. The Services are not offered to residents of the European Union, the European Economic Area, the United Kingdom, or Switzerland. References below to specific U.S. state laws, the Israeli Privacy Protection Law, and similar regimes apply where the relevant law applies on its terms. Users in jurisdictions not specifically named have equivalent rights to the extent required by mandatory local law.
1. Who We Are; Contact
The controller of personal data described in this Privacy Policy is Kifas Labs Ltd, registered office Shikma 2, Dvira 8533000, Israel, Israeli Company Number 517267134, a private company limited by shares under the Companies Law, 5759-1999. For all privacy questions, requests, and exercise of rights, contact: legal@kifas.io. Where Kifas processes personal data on behalf of an Enterprise or other customer acting as a controller, Kifas acts as a processor and the DPA at kifas.io/dpa governs.
2. Personal Data We Collect
(a) Account and billing data: name, business email, password (hashed), company name and role, billing address, payment method tokens (we do not store full card numbers; payments are processed by Paddle or another disclosed PCI-DSS-certified processor), VAT/tax IDs, and similar.
(b) Usage and technical data: IP address, device and browser identifiers, operating system, timestamps, pages and features used, log files, performance and error data, referrer/UTM data, and, when analytics consent is enabled, Google Analytics 4 measurements and Microsoft Clarity session replay on the public kifas.io website. We do not use Clarity to record customer test targets, and we do not deploy full-keystroke-capture tools on kifas.io.
(c) Customer Content as defined in the Terms (test scripts, browser session content captured by Kifas during your tests, screenshots, video, logs, prompts, AI outputs, Published Workflows).
(d) Communications: emails, support tickets, calls, chat messages.
(e) Cookies, pixels, and similar technologies (see the Cookie Policy at kifas.io/cookies).
(f) Information from third parties: identity providers (e.g., Google, Microsoft, GitHub) if you sign in via SSO; analytics providers; security and fraud-prevention services; publicly available business directories; and Paddle for transaction data and chargeback signals.
Kifas for Jira
Kifas for Jira is an Atlassian Forge app. The app stores no data in Atlassian Forge storage. Every request it sends outside Atlassian goes over TLS to api.kifas.io, which is operated by Kifas. No other remote host receives data from the app.
Kifas reads Jira issues that match the product and development filters configured by the customer. Jira bugs created by Kifas are also retained and read even when they do not match those filters, so Kifas can show their status and verify a fix. For each retained issue, Kifas receives and stores:
- issue key and issue ID;
- summary and description content, including text, formatting, links, inline cards, mentions, and Atlassian account IDs contained in mentions;
- status, status category, issue type, priority, labels, and fix versions;
- assignee and reporter display names and Atlassian account IDs;
- parent issue key and project key;
- issue links, including the link type and linked issue key;
- attachment metadata, including file name, size, content type, and the Atlassian-hosted URL. Kifas does not download attachment contents; and
- created and updated timestamps.
Kifas also receives issue-created, issue-updated, issue-deleted, issue-link-created, and issue-link-deleted events so the mirror stays current. Events for issues outside the configured filters are discarded after the filter check unless the issue is a Jira bug created by Kifas. When a person uses a Kifas app page or panel, including the admin page, project page, or issue panel, Kifas receives that person's Atlassian account ID and the Jira site URL. A short-lived user token is used only for that request to confirm that the person can view the requested Jira content or administer the site. User tokens are never stored.
Kifas stores the Jira site and installation identifiers, encrypted short-lived app credentials, filter and project-mapping configuration, the linking administrator's Atlassian account ID, issue relationships, and Atlassian account IDs attached to human relationship or suggestion decisions. It also stores generated test plans and revisions, the IDs of Jira comments posted by Kifas, test suggestions derived from retained Jira issues, dashboard notifications about Jira plans, suggestions, filed bugs, and verification results, and the Jira issue key, URL, and status category attached to a Kifas failure finding when Kifas files or tracks that bug.
To prevent a retry from posting the same Kifas-authored comment twice, Kifas may read the comments on the target issue and look for its own idempotency marker. Comment bodies are used only during that request and are not mirrored or stored by Kifas.
When AI matching, test planning, failure analysis, or test suggestion features run, relevant ticket summaries and descriptions, linked-work context, test metadata, and failure evidence are sent to the configured model provider. Kifas uses OpenRouter by default and requires routes that deny data collection and provide zero data retention. Depending on the customer's bring-your-own-key settings, processing may instead use OpenRouter, Anthropic, OpenAI, or Amazon Bedrock under the customer's provider agreement. Kifas does not use Jira data to train or fine-tune Kifas or third-party models. Current subprocessors are listed at kifas.io/subprocessors.
Mirrored Jira data is stored in the Kifas database, hosted on Supabase in the United States. Kifas for Jira is not eligible for Atlassian pinned data residency, so app data is stored in the United States regardless of the Jira site's region.
When the site is unlinked from Kifas or the app is uninstalled from Jira, access stops immediately and app credentials are deleted. Retained Jira data and data derived from it are permanently purged within 30 days. Kifas reports stored Atlassian account IDs through Atlassian's personal data reporting API in each reporting cycle (seven days by default) and erases stored personal data for accounts Atlassian reports as closed.
Kifas for Jira does not retain worklogs, issues outside the configured filters other than Jira bugs created by Kifas, Atlassian user email addresses, user-directory data, passwords, or user API tokens. Jira may deliver an event or Kifas may fetch an issue before applying the configured filter; unmatched issue data is discarded after that check. Kifas may create Jira bug issues and add or update Jira comments when a customer uses the related Kifas workflow features.
Jira supplies a short-lived app token to Kifas with events and the hourly heartbeat. App tokens expire within four hours, are encrypted at rest using AWS KMS envelope encryption, and are replaced when a newer token arrives. Tokens are never written to logs, URLs, or source code.
For questions about Kifas for Jira, contact support@kifas.io. Report security concerns to security@kifas.io.
Biometric data. Kifas does not knowingly collect biometric identifiers as defined by the Illinois Biometric Information Privacy Act (740 ILCS 14/), the Texas Capture or Use of Biometric Identifier Act (Bus. & Com. Code § 503.001), the Washington Biometric Identifiers Act, or similar laws.
3. How We Use Personal Data
We use personal data to: (i) provide, operate, secure, and maintain the Services; (ii) authenticate users and prevent fraud and abuse; (iii) bill, invoice, and collect payment (including through merchant-of-record arrangements with Paddle); (iv) communicate with you about service, security, billing, support, product updates, and, where permitted by law, marketing (you may opt out of marketing at any time); (v) enforce our Terms and policies, defend legal claims, and comply with law; and (vi) compute aggregate and de-identified analytics to understand and improve the Services. Kifas does not currently use Customer Content to train or fine-tune AI models. This applies to every plan and includes data received through Kifas for Jira.
4. AI Training
Kifas does not currently use Customer Content to train or fine-tune AI models. Kifas uses third-party AI model providers to perform inference when an AI-enabled feature runs, but requires the routes used by Kifas to deny training on Customer Content. Current providers are listed on the Subprocessors page.
Aggregate and de-identified analytics that cannot reasonably identify you or another individual may be used to operate, secure, debug, and improve the Services.
When Kifas uses de-identified data, Kifas maintains technical safeguards and business processes designed to prevent it from being linked to an individual or household. Kifas will not attempt to reidentify that data except to test those safeguards where permitted by law, and will contractually require any recipient to follow the same restrictions.
5. Disclosure of Personal Data
We disclose personal data to: (a) subprocessors (hosting, payment processing including Paddle, email and notification providers, customer-support tools, analytics, security/fraud-prevention, error-reporting; current list at kifas.io/subprocessors); (b) professional advisors (lawyers, accountants, auditors) under confidentiality; (c) authorities when legally required (court orders, subpoenas, government requests, national-security demands, where lawful); (d) business transfers (merger, acquisition, financing, sale, restructuring, bankruptcy); and (e) with your consent or at your direction. We do not sell personal data for monetary or other valuable consideration as those terms are defined under the California Consumer Privacy Act, and we do not "share" personal data for cross-context behavioral advertising. If we ever begin to do so, we will update this Privacy Policy and provide the "Do Not Sell or Share My Personal Information" mechanism required by Cal. Civ. Code § 1798.135.
Important note on B2B and employment data under CCPA/CPRA: The temporary CCPA exemptions for business-contact information and employment-related personal information under AB 1355 expired on January 1, 2023, and business-to-business and employment data have been fully in CCPA/CPRA scope since that date. We treat business-contact data of California residents as fully covered personal information.
6. International Data Transfers
Kifas is established in Israel; our hosting is provided primarily through Amazon Web Services in the United States. Personal data is transferred between Israel and the United States in the ordinary course of providing the Services. Because we do not offer the Services to residents of the EU/EEA, UK, or Switzerland, we do not implement Standard Contractual Clauses or rely on the EU-U.S. Data Privacy Framework. Customers in other jurisdictions consent to the international transfer of their personal data to the United States and Israel by using the Services.
7. Data Retention
We retain personal data for as long as necessary to provide the Services, comply with legal obligations (e.g., tax, accounting, anti-money-laundering), resolve disputes, and enforce our agreements. By default: (a) Account data is retained while your Account is active and for up to ninety (90) days after closure; (b) billing records are retained for seven (7) years (consistent with U.S. and Israeli tax-record retention obligations); (c) Customer Content for Free Trial Accounts is deleted within fourteen (14) days after trial expiration; (d) Customer Content for paid Accounts is retained while the Account is active and deleted within thirty (30) days after termination; (e) Published Workflows are removed within ninety (90) days of Account termination per Section 12 of the Terms; and (f) Enterprise retention is governed by the Order Form / MSA. Aggregate data and data that has ceased to be personal data through the de-identification safeguards in Section 4 may be retained indefinitely.
8. Your Rights
Depending on your jurisdiction, you may have rights including: access, correction, deletion, restriction, objection, portability, withdrawal of consent, opting out of automated decision-making, opting out of sale or sharing of personal information, and limiting use of sensitive personal information. To exercise rights, email legal@kifas.io with proof of identity. We will respond within the time required by applicable law (typically 30-45 days). We will not discriminate against you for exercising your rights.
For California residents (CCPA/CPRA): rights to know, access, delete, correct, opt out of sale/sharing, and limit use of sensitive personal information; the categories of personal information collected, sources, purposes, and recipients are described above; business-contact and employment data of California residents are in full scope (the AB 1355 exemption having expired on January 1, 2023).
For residents of other U.S. states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, Iowa, New Jersey, Tennessee, Montana, etc.): equivalent rights apply. The Texas Data Privacy and Security Act took effect July 1, 2024.
For Israeli residents: rights under the Privacy Protection Law, 5741-1981, as amended by Amendment No. 13, 5784-2024 (passed by the Knesset on 5 August 2024 and entered into force on 14 August 2025), apply, including the expanded rights of access, correction, and deletion, and the expanded transparency obligations under Section 11 of the PPL. Complaints may be filed with the Privacy Protection Authority (Israeli Privacy Protection Authority, רשות הגנת הפרטיות).
For Canadian residents: rights under PIPEDA and Quebec's Law 25 (where applicable) apply.
For Australian residents: rights under the Privacy Act 1988 (Cth) apply.
For residents elsewhere: equivalent rights apply to the extent required by mandatory local law.
9. Automated Decision-Making
Kifas may use automated systems (including AI-based systems) to detect fraud, abuse, suspicious access patterns, AUP violations, and similar security-relevant signals, and to suspend or terminate Accounts based on such detection. You may request human review of any such automated decision by emailing legal@kifas.io. We do not use solely-automated decision-making with legal or similarly significant effects for individual users in employment, credit, housing, insurance, or similar regulated contexts.
10. Security
We implement administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent), role-based access controls with multi-factor authentication for administrative access, secure software development, vulnerability and patch management, logging, monitoring, periodic risk assessments and penetration tests, and a documented incident-response plan. No system is impervious; you are responsible for safeguarding your credentials and endpoints. We comply with the Israeli Privacy Protection Regulations (Data Security), 5777-2017.
11. Data Breach Notification
If we become aware of a security incident that compromises personal data, we will notify affected parties as required by applicable law, including: (a) Israeli Privacy Protection Regulations (Data Security), 5777-2017, Regulation 11(d)(1): immediate notice to the Privacy Protection Authority of a "Severe Security Incident" (אירוע אבטחה חמור) and a follow-up report on the steps taken; under Amendment 13 the PPA's authority to direct notice to affected data subjects has been expanded; (b) U.S. state breach-notice laws (e.g., Cal. Civ. Code § 1798.82, N.Y. Gen. Bus. Law § 899-aa, Tex. Bus. & Com. Code § 521.053, and analogous statutes in all U.S. states) according to their statutory timing.
12. Children
The Services are not directed to and are not intended for anyone under eighteen (18) years of age. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact legal@kifas.io and we will delete it.
13. Cookies
See the Kifas Cookie Policy at kifas.io/cookies.
14. Changes
We will notify you of material changes by email and in-app notice at least thirty (30) days in advance (or immediately for legal or security reasons), as described in the Terms.
15. Privacy Contact
All privacy inquiries and data-subject requests should be sent to legal@kifas.io. As of the Effective Date, Kifas has assessed its scale and processing activities and has determined that it does not meet the statutory criteria for a mandatory Privacy Protection Officer (PPO) appointment under Section 17B1 of the Israeli Privacy Protection Law (e.g., we are not a public body, data broker with more than 10,000 records, large-scale systematic monitor, or a bank, insurer, hospital, or HMO processing Information of Special Sensitivity at scale). We will reassess this position as our scale and processing change.