Oprex Privacy Policy
How Kinexa Systems collects, uses, and protects your data in Oprex — the ALM/SDLC platform at oprex.id and member.oprex.id.
Data controller: PT Kinetikum Indo Solusi (Kinexa Systems division).
Last updated: 2026-08-04
Short summary
- We store the data you enter into Oprex yourself (projects, issues, requirements, tickets, documents) along with your account identity.
- We do not sell your data and do not use it for advertising.
- Your tenant's data is isolated from other tenants; access follows Group/Project membership.
- You can revoke any AI app's access any time under Settings → Connected Apps.
Data we collect
1. Account data
Oprex logs in via Kinexa SSO. From it we receive your name, email address, and your tenant/entitlements. Oprex never stores your password — authentication happens entirely on the Kinexa side.
2. Content you create
Everything you enter into Oprex: projects, groups, issues/bugs, requirements, specifications, test cases & results, milestones, releases, helpdesk tickets, comments, notes, memories, attachments/files, and tags.
3. Technical & operational data
Request logs (timestamp, endpoint, status code, request id), webhook delivery records, activity trails (who changed what and when), and last-used timestamps for API keys/tokens. This is used for security, auditing, and troubleshooting.
4. Integration credentials
If you connect a Git repository (Forgejo/GitHub/GitLab) or a deploy target, the access token you provide is stored encrypted and used only for that integration.
We neither request nor need payment-card data in Oprex. Subscription billing is handled by the Kinexa system, not by Oprex.
How we use data
- To provide Oprex itself (showing & managing your SDLC data).
- To enforce access control — ensuring only entitled members can see a Group/Project.
- To send notifications you or your team enable (email, webhooks).
- To keep the service secure: detecting abuse, rate limiting, investigating incidents.
- To meet legal obligations where applicable.
We do not use your tenant's content to train AI models.
AI & automated processing
Oprex has AI-assisted features (e.g. issue analysis, and Autopilot which diagnoses critical bugs and drafts a proposed fix). These run only when enabled for your tenant/project.
When an AI feature runs, the relevant excerpt (e.g. an issue's title & description, and where needed the related code) is sent to an AI model provider for processing. Autopilot never merges changes automatically — its output is a proposal that still requires human review.
If you don't want particular data processed by AI, leave the AI features disabled for that project, or contact us.
MCP connectors & OAuth
Oprex can be connected to AI assistants (Claude, ChatGPT, Gemini, and other MCP clients) through our MCP server. Two ways: an API key you create yourself, or OAuth 2.1.
- When you approve an app via OAuth, we store: the app's identity, which of your accounts granted it, the scopes granted, and the access/refresh tokens as hashes (never in plaintext).
- Grants are per-user. Other tenant members can neither see nor revoke your grants.
- A connected app can only reach data you are yourself allowed to access, limited to the granted scopes.
- Revoke any time under Settings → Connected Apps. Revoking immediately kills all of that app's tokens, including older refresh tokens.
Note: once data reaches the AI assistant you chose, that data is also subject to that provider's own privacy policy (e.g. Anthropic, OpenAI, Google).
Sharing with third parties
We share data only with:
- Kinexa SSO — for authenticating your account and checking entitlements.
- AI model providers — only for AI features that are enabled, limited to the excerpt needed.
- Apps you yourself authorized via OAuth or an API key.
- Email delivery services, for notifications you enable.
- Integration targets you configured yourself (Git, webhooks, deploy targets).
- Authorities, where required by applicable law.
We do not sell or rent your data to anyone.
Storage & retention
Data is stored on infrastructure we operate. Tenant content is kept for as long as your account/subscription is active, and remains until you delete it or ask us to.
- OAuth access tokens live 1 hour; refresh tokens 30 days and rotate on every use.
- OAuth authorization codes live 5 minutes and are single-use.
- Revoked tokens are marked revoked and can no longer be used.
After an account closes, we delete or anonymise tenant data within 30 days, except for records we must retain for legal or audit obligations. During that window you can still request a copy of your data.
Security
- All connections use HTTPS/TLS.
- API keys and OAuth tokens are stored as hashes, never in their original form.
- Integration tokens (e.g. Git) are stored encrypted.
- OAuth mandates PKCE (S256); tokens are time-limited and revocable.
- Access is scoped per tenant, and further per Group/Project.
Found a security issue? Report it to support@oprex.id — we appreciate it and will follow up.
Your rights
- View and correct your data directly in the app.
- Request a copy of your tenant's data.
- Request deletion of your data or closure of your account.
- Revoke connected apps and API keys at any time.
For requests you can't perform yourself in the app, contact support@oprex.id.
Children
Oprex is a professional work tool and is not directed at children under 13. We do not knowingly collect data from them.
Changes to this policy
If this policy changes substantially we update the date above and notify you in-app or by email.
Contact
Service operator: PT Kinetikum Indo Solusi — Kinexa Systems division
Email: support@oprex.id
Support: support.oprex.id