Privacy policy.

Effective 10 September 2026. This policy covers the propr.dev website and ProPR Connect, operated by Unchained Development OÜ (Estonian registry code 16785055, Tallinn, Estonia). ProPR agents and execution run on your infrastructure. Data also reaches the external services you use, as described below.

Overview

This website

propr.dev is a static site served through Cloudflare. It requires no account. Fonts and other site assets are served from our own domain. Cloudflare keeps standard server access logs (IP address, requested URL, user agent) for operational and security purposes.

Website analytics

Google Analytics runs after you select “Allow analytics.” It measures page views, site interactions, traffic sources, approximate location, and browser and device details. Google Analytics uses first-party _ga cookies to distinguish visitors and sessions. We use its aggregate reports to understand how people find propr.dev, which content they use, and which routes lead to product documentation, source code, and contact.

Consent is the legal basis for this processing. Selecting “Decline analytics” keeps the Google tag from loading. The “Analytics preferences” control in the footer lets you change your choice. Withdrawing consent removes Google Analytics cookies set through propr.dev and reloads the site without the Google tag. The site saves your choice in browser storage so it can apply that decision on later visits.

Google handles analytics data under its privacy policy and data processing terms. Google may process this data outside the European Economic Area under the transfer safeguards described in those terms.

Contact form and email

When you contact us through the contact form or by email, we receive the details you provide — typically your name, email address, and message. The form is delivered through Formspree, which processes the submission on our behalf under its own privacy policy. We use your details only to reply and to follow up on your request. We do not sell or share this information, and you can ask us to delete it at any time.

Self-hosted ProPR

The ProPR software (Apache 2.0) runs on infrastructure you control. Repository clones, task history, logs, and credentials are stored in your deployment. Prompts and selected context reach the providers you configure; requested MCP results also reach your chat host and, with the optional hosted gateway, Connect. The software does not report usage data to us. Calls to AI providers and GitHub are made with your own credentials, under those providers' terms.

ProPR Connect

ProPR Connect is a hosted service that relays GitHub webhook events to your self-hosted stack. It processes the GitHub account and installation details needed to route deliveries and manage seats. Connect processes full webhook payloads, including any source code included in GitHub issue or review comments. Webhook payloads are cleared after successful delivery; failed deliveries are cached for up to 24 hours for replay. Delivery records and payload-free statistics are separate: statistics including repository name, target GitHub username, event, status, and timing have a 30-day retention window. Subscription payments are processed by Polar, which handles payment data under its own privacy policy; we do not receive your card details.

Optional MCP access

Check MCP availability and operator setup requirements.

Direct MCP connects your chat host to your instance and bypasses Connect. The optional Connect MCP gateway processes tool arguments and results in transit to and from your instance through a managed tunnel. These payloads can contain prompts, source code, repository context, diffs, and artifacts. The gateway processes their contents; it provides no end-to-end encryption through Connect.

Browser OAuth identifies your account and binds app access to an installation, scopes, and repository restrictions, with connected-apps revocation. The gateway forwards MCP requests and results without an intentional application payload store or replay cache. Connect stores OAuth client and pending-consent data, instance registration, grant identity and repository/scope restrictions, token/session hashes, proof-replay records, and encrypted GitHub credentials separately. Revocation clears the grant’s encrypted credential; scheduled cleanup clears expired credentials and removes grant metadata and associated hashes 30 days after expiry or revocation. Registration records follow a separate lifecycle.

The gateway returns generated request IDs and fixed diagnostic errors; scheduled cleanup logs a fixed failure message. These source-level limits do not guarantee zero logging or retention by Cloudflare, operator infrastructure, the chat host, or its model service. Cleanup depends on the configured maintenance job. Webhook payload retention statements apply only to webhooks. Read the public core/Connect contract.

Your chat host and any model service it uses receive the content returned to the conversation under their own policies. ProPR's MCP interface is scoped to text and structured data. Any speech input or output is handled by the host. Enter credentials through browser authentication and setup, outside the conversation.

Your rights and contact

Unchained Development OÜ is based in Estonia, so EU data-protection law (GDPR) applies: you can request access to, correction of, or deletion of personal data we hold about you. Write to sales@propr.dev for any privacy request or question. If this policy changes, the effective date above changes with it.