NovaHavenTech
  • Home
  • Products
  • About
  • Contact
Try Costara
NovaHavenTech
  • Home
  • Products
  • About
  • Contact
Try Costara →
  1. NovaHaven Tech
  2. /
  3. Products
  4. /
  5. Costara
Costara
OverviewFeaturesPricingCompareDocsSoonChangelogSoonTermsPrivacyRefund Policy

Costara

  • Overview
  • Features
  • Pricing
  • Documentation
  • Changelog

Compare

  • vs LangSmith
  • vs Langfuse
  • vs Datadog
  • All comparisons
  • Alternatives

Company

  • About
  • Contact
  • GitHub

Legal

  • Privacy Policy
  • Terms of Service
NovaHavenTech· © 2026 NovaHaven Tech. All rights reserved.
GitHub

Last updated: March 22, 2026

Costara Privacy Policy

Last updated: March 2026

This Privacy Policy explains how NovaHaven Tech collects, uses, and protects information in connection with the Costara service.


1. Who We Are

Costara is operated by NovaHaven Tech, a proprietorship owned by Mythili Ramalingam, registered as a Micro Enterprise under India's MSME Act (Udyam Registration: UDYAM-TN-03-0308964), based in Coimbatore, Tamil Nadu, India.

For privacy enquiries: support@novahaven.tech


2. What Costara Captures

SDK Usage Data

When you instrument your application with the Costara Python SDK, we receive metadata only:

  • LLM provider name (e.g. openai, anthropic)
  • Model name (e.g. gpt-4o, claude-3-5-sonnet)
  • Token counts (prompt tokens, completion tokens)
  • Estimated cost in your configured currency
  • Request latency in milliseconds
  • Feature tag (a string you supply, e.g. customer-support-chat)
  • Environment label (e.g. production, staging)
  • Timestamp

We never collect prompt text, completion text, or any message content. This is a structural constraint of the SDK — the SDK does not have access to prompt or completion content by design, not by a policy setting or configuration toggle. There is no flag to enable content capture. Your users' data stays in your infrastructure.

This privacy-by-architecture approach is a deliberate product decision. Monitoring tools have no business touching your users' conversations. So we built Costara in a way that makes it architecturally impossible for us to do so.

Account Data

When you create a Costara account:

  • Email address
  • Name (optional)
  • Password (stored as a bcrypt hash via Supabase Auth — we never see your plaintext password)

Payment Data

Payments are processed by Razorpay. We receive payment confirmation and plan status from Razorpay. We do not store card numbers, UPI IDs, or bank account details. Razorpay handles all payment instrument data on their PCI-compliant infrastructure.

Dashboard Usage Data

We collect basic usage data about how you interact with the Costara web dashboard — page views, feature interactions, and session information. This data is used solely to understand how the product is being used and to improve it. It is never used for advertising.


3. How We Use Your Data

  • To operate the Service — display your cost dashboards, calculate aggregates, send budget alerts
  • To improve the Service — aggregate, anonymized usage patterns help us prioritize features
  • To communicate with you — billing notifications, product updates (you can unsubscribe from non-billing emails at any time)
  • For security — detecting abuse, rate limiting, fraud prevention

We do not sell your data. We do not use your SDK event data for advertising or any purpose unrelated to operating the Service.


4. Data Retention

| Data type | Retention | |---|---| | SDK events | Per your plan: 7 days (Free), 90 days (Pro), 1 year (Team) | | Account data | Until account deletion + 30-day grace period | | Server logs | 30 days | | Billing records | 7 years (legal requirement) |

You may request deletion of your account and all associated event data at any time. See Section 8 for instructions.


5. Third-Party Services

Costara uses the following sub-processors:

  • Supabase — database and authentication. AWS us-east-1 region. All event data is isolated per organization using row-level security enforced at the database layer.
  • Railway — API server hosting. US region.
  • Vercel — dashboard frontend hosting. Global edge.
  • Razorpay — payment processing and subscription management. Handles all billing instrument data.
  • Resend — transactional email delivery for budget alerts and billing notifications.

All sub-processors are contractually bound to process data only for the purposes of providing the Service.


6. Your Rights

You may request to: access your data, correct inaccurate data, export your event data (CSV), or delete your account and all associated data.

To exercise any of these rights, email support@novahaven.tech with the subject line "Costara Privacy Request". We will respond within 5 business days.

If you are in the European Economic Area, you also have rights under the GDPR, including the right to lodge a complaint with a supervisory authority.


7. Security

We use industry-standard practices to protect your data: encryption in transit (TLS), row-level security in our database, and API key authentication for SDK access. We keep dependencies updated and review access controls regularly.

If you discover a security vulnerability, please contact us at support@novahaven.tech before disclosing it publicly. We take security reports seriously and will respond promptly.


8. Changes to This Policy

We may update this Privacy Policy from time to time. If we make significant changes, we will notify you by email at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Continued use of the Service after changes take effect constitutes acceptance of the updated policy.


9. Contact

NovaHaven Tech Coimbatore, Tamil Nadu, India Proprietor: Mythili Ramalingam support@novahaven.tech