Privacy Policy
Transparent information about how we handle your data when using the Contiva Groovy IDE
Last updated: 8/13/2026
We absolutely do not store any of your scripts, input data, or personal code on our servers. All processing is ephemeral and data is irrevocably destroyed immediately after processing.
This guarantee covers everything you write and run in the IDE. It's separate from — and doesn't change — the minimal account data described below, which only exists if you choose to create an account for MCP quota (see "Account & Authentication" and "Payment Processing").
Contiva GmbH operates under German data protection laws (DSGVO) and maintains the highest standards of privacy protection for our users.
Your scripts, configurations, and IDE preferences are stored exclusively in your browser local storage:
- LocalData never leaves your device unless you explicitly execute a script
- ControlYou can export, delete, or manage all stored data at any time
- PrivateNo synchronization across devices or to cloud storage
An account is only created if you sign up to buy MCP call quota or connect an AI tool (Claude, Cursor, …) to the MCP server. Using the IDE itself in your browser never requires one.
Your email address and, if you register with a password, a one-way bcrypt hash of it — never the password itself.
We receive your name, email address, and a stable account identifier from the provider you choose — nothing else, and never your password with that provider. If you sign in with more than one provider (or with a password) using the same email, we link them to a single account instead of creating duplicates.
Each AI client you connect (e.g. "Claude Desktop", "Cursor") gets its own credential, shown to you once and stored only as a one-way hash afterwards — we cannot recover it, only revoke it. We keep the client's self-reported name and timestamps for when it was added and last used, so you can see and remove connected devices at any time.
Sent via our own mail relay (smtp.contiva.cloud) to confirm your address or reset a forgotten password — never shared with anyone else.
MCP quota packages are purchased through Stripe. Your card details are entered directly into Stripe's own checkout page and are never seen, transmitted through, or stored by our servers — we're not PCI-DSS certified and don't need to be, because we never handle card data at all.
What we do store, tied to your account: which package you bought, how many MCP calls remain, and when they expire — no payment card numbers, expiry dates, or CVV codes.
Scripts are processed exclusively through our secure Groovy runtime to generate execution results.
Script content and input data are temporarily loaded into memory, processed, and immediately destroyed.
We do not log, store, or retain any script content, input data, or processing results.
After each script execution, all data is permanently removed from our systems with no possibility of recovery.
Technical Security
- • TLS 1.3 encryption for all communications
- • Secure API endpoints with authentication
- • Sandboxed script execution environment
- • Regular security audits and updates
Operational Security
- • No persistent storage of user data
- • Isolated processing environments
- • Automatic data purging after processing
- • German data protection compliance
We collect minimal, anonymized metrics to improve service quality and understand usage patterns:
We use Google Analytics 4 via our own metrics endpoint to ensure your data doesn't go directly to Google:
- • All events are routed through our secure /api/metrics endpoint
- • Anonymous session IDs only (random UUIDs, no personal data)
- • IP addresses are automatically anonymized by GA4
- • No cookies or persistent user tracking
Which development mode users prefer (CPI vs Pure Groovy)
Success/error rates, execution times, and error types (no script content)
Script sizes (byte count only), loading times, and system performance
Which IDE features are used most frequently (e.g., code completion, templates)
Anonymous page navigation patterns (no URLs with personal data)
- • No script content: We never track or store your actual code
- • No personal data: No names, emails, or identifying information
- • Anonymous sessions: Random UUIDs that cannot be linked to you
- • Aggregated only: All data is aggregated and cannot be traced to individuals
- • GDPR compliant: Full compliance with German data protection laws
These metrics help us understand how the IDE is used, identify performance issues, and prioritize feature development while maintaining complete user privacy.
We use a small number of specialized providers rather than building everything ourselves — each only ever receives the minimum needed for its purpose:
- • Stripe — payment processing for quota purchases
- • Google / GitHub / Microsoft — only if you choose to sign in with one of them
- • smtp.contiva.cloud — our own mail relay, sends verification and password-reset emails
Access & Portability
- • Export all your stored scripts
- • Download IDE configurations
- • Request processing information
- • Request a copy of your account data
Deletion & Control
- • Clear all local storage data
- • Revoke any connected MCP device yourself, anytime
- • Request full account deletion (email, linked sign-in methods, devices)
- • Opt-out of analytics collection
For any privacy-related questions, concerns, or data protection requests, please contact our privacy team directly:
Contiva GmbH - Privacy Team
Yokohamastr. 2, 20457 Hamburg, Germany
Geschäftsführer: Robert J. Fels
Email: [email protected]
Subject: Privacy Inquiry - Groovy IDE
Website: https://contiva.com
This privacy policy is reviewed regularly to ensure compliance with current data protection standards. Any material changes will be prominently displayed in the IDE interface.
Continued use of the service after policy updates constitutes acceptance of the revised terms.