Privacy notice

What this website collects, and what the Kolap service is built to process once you have access.

Draft, pending legal review. This document is a working draft written from what the product does. It is not final and may change before general availability.

Who is responsible

Mazacode LTDA, CNPJ 45.655.559/0001-98, Florianópolis/SC, Brazil, operates Kolap and this website.

This website

This website sets no cookies, runs no analytics or advertising tags, has no forms and loads its fonts and images from its own server. The only way to reach us from it is a link that opens a WhatsApp conversation, and that conversation is then governed by WhatsApp's own terms and privacy policy.

The site is served through Cloudflare. The Cloudflare account that hosts it injects Cloudflare Web Analytics at the edge, which measures page views without cookies, and we do not control that beacon.

The Kolap service, in early access

Kolap is not publicly available. Access is arranged in a conversation, and this section describes how the service is built to behave.

  • Account data: name, e-mail address, plan, API keys (stored as a hash with the last four characters) and notification preferences.
  • Workflow data: the graph and node settings, prompts, published versions, trigger payloads, stored webhook deliveries, run logs and failure diagnoses. Payloads can contain personal data that you send, and you decide what to send.
  • Connector credentials: tokens you store in the secrets vault are encrypted with AES-256-GCM. The product shows only the name, type and last four characters.
  • Billing data: if you hold a paid plan, a card payment processor handles payment, and Kolap keeps the plan and the processor's reference rather than the card number.

Why we process it

To authenticate you, run your workflows, deliver webhooks and notifications, keep connector credentials safe, help you debug failed runs and bill a paid plan.

Retention and your controls

  • For each workflow you can set a retention period from 1 to 365 days. Older runs are pruned once a day.
  • For each workflow you can list payload fields to redact from stored logs. Credential headers on incoming webhooks are masked before a delivery is stored.
  • Deleting an account deletes its data, apart from records we must keep for tax or security reasons.

Who else receives data

  • The AI providers Anthropic and OpenAI receive the text of a prompt when you use the AI Prompt node, the workflow generator or the failure diagnosis.
  • Each service connector sends your data to the service it connects to, as you configure it.
  • A transactional mail provider sends verification, alert and similar messages.
  • A card payment processor handles payments for paid plans.
  • Hosting, database and queue providers run the infrastructure. They are not final while the service is in early access.

Your rights

Under Brazil's data protection law (LGPD) you can ask to confirm that we process your data, and to access, correct, export or delete it. To reach us about this document, message the founder on WhatsApp. This website has no contact form and no e-mail address.

Changes

When the service opens to the public this notice will be finalised after legal review, and the date above will change.

Last updated 6 October 2026. Kolap is a product of Mazacode LTDA, CNPJ 45.655.559/0001-98, Florianópolis/SC, Brazil.