Privacy Policy
KindyHero("we", "our", "us") respects your privacy. This policy explains what we collect, how we use it, and the choices you have. It applies to our web application and the free KindyHero Chrome extension.
What we collect
- Account information. Email, name, and profile image you provide at sign-up (or that your Google account provides on OAuth sign-in).
- Authentication token. After you sign in, we issue a short-lived session token. The KindyHero Chrome extension caches this token locally (in
chrome.storage.local) so you stay signed in across browser sessions without logging in twice. The token lives on your device and is sent to our API only to authenticate your requests. - Submitted content. The content you submit for processing, the generated output, and any scores calculated for it. The extension only reads the input field of a supported site at the moment you trigger an action - nothing is transmitted before you explicitly do so.
- Usage metadata. Per-account daily action counts (used to enforce plan limits), timestamps, the tool the request came from, and your plan tier.
- Billing. Handled by Stripe on our web app. The Chrome extension never sees payment data. We do not see or store your card details.
- Login activity. When you sign in or sign out, we record the timestamp, IP address, browser user-agent, and approximate country. This helps you detect unauthorised access to your account and lets us understand product engagement in aggregate. We do not sell or share this data.
How we use it
Your content is sent to a third-party AI provider to generate the result. We store your input and its output so you can access your history. We use aggregate usage numbers to improve the product.
We do not sell, rent, or share your data with third parties for advertising or profiling.
Content moderation
Before any submission is sent to our AI provider, we run it through a lightweight filter that rejects content falling into the categories listed in our Terms of Service (drugs, adult content, personal messaging and dating, spam and phishing, hate speech, excessive profanity) and submissions that are too short or vague to process meaningfully. Rejected submissions are never transmitted to the AI provider, never appear in your history, and do not count against your daily limit.
We do, however, keep an internal audit record of rejected submissions - the original text, the rejection category, timestamp, IP address, browser user-agent, and the tool it was submitted from. This is used solely to identify accounts that repeatedly attempt disallowed content so we can enforce our Terms of Service. These records are not shared with third parties.
Chrome Extension
The KindyHero Chrome extension is the client that adds KindyHero to supported sites. Because browser extensions warrant an explicit data disclosure, here is exactly what it does and does not handle.
Data the extension sends to our servers:
- The text from the input field of a supported site - but only when you trigger an action. No background reading, no keystroke logging.
- Your cached session token, attached as an Authorization header so our API knows which account is making the request.
Data the extension stores locally on your device (via chrome.storage.local, not transmitted anywhere):
- Your cached session token.
- Your theme preference (light or dark).
- Your button customisation (position, shape, colour) and enabled-site toggles.
- Your popup vs side-panel preference.
Data the extension does not collect:
- Web history. Content scripts only run on the sites listed in the extension manifest, and only to add KindyHero. We do not track which pages you visit, page titles, or visit timestamps.
- Location. We do not access GPS, device location, or derive geolocation from your IP beyond the approximate country recorded in the login activity log above.
- Personal communications. We do not read your emails, texts, DMs, or any chat conversation content. Content you submit through KindyHerois treated as website content you explicitly submit, not interpersonal messages.
- Financial information. The extension never handles card numbers, transactions, or credit data. All billing runs through Stripe on our web app.
- Health information. Never collected.
- Keystrokes, clicks, or mouse movement on the sites it runs on. The extension only reads the contents of the input field at the moment you trigger an action.
We do not sell or transfer user data to third parties outside of approved use cases (Stripe for payments, our AI provider for the processing itself, a managed PostgreSQL database for data storage, and Resend for transactional email). We do not use your data for advertising, profiling, creditworthiness scoring, or any purpose unrelated to the single purpose of processing the content you choose to submit.
Your data, your control
- You can delete any item from the History page.
- You can export your saved items from the Library page.
- You can delete your account from Settings. This removes all stored content, history, and account data.
What we keep after you delete your account
To prevent abuse - specifically people deleting an account purely to reset a usage allowance or to claim a second free trial - we keep a small fraud-prevention record when an account is deleted. That record contains a one-way salted hash of the email address, a count of the usage already spent and the date it belonged to, and, where a payment card was on file, the card fingerprint your payment processor returns. It does not contain your email address, your name, or any of your content, and the hash cannot be reversed to recover the address.
If an IP address was recorded alongside it, that IP is deleted automatically after the retention period configured for this site (90 days by default). The remaining fields are retained for as long as the anti-abuse measure is in force. We rely on our legitimate interest in preventing fraud and service abuse as the lawful basis for keeping it. If you would like this record removed, contact us and we will delete it.
Security
Data is stored in a managed PostgreSQL database with row-level security so only you can read your own records. Traffic is encrypted with TLS. Authentication uses short-lived session tokens.
AI provider API keys
If you add your own AI provider API key (Anthropic, OpenAI, Google, or xAI) via Settings › AI Providers, here is exactly how we handle it:
- Encrypted at rest. Your API key is encrypted with AES-256 before being written to our database. The plaintext key is never stored. We hold only the encrypted ciphertext plus the last four characters of the key so you can identify which key you saved.
- Used only for your requests. The key is decrypted in memory only at the moment your request is processed, and only to call the AI provider on your behalf. It is never logged, never exposed in API responses, and never used for any other account.
- Never shared or sold.Your key is not shared with third parties beyond the provider it belongs to (e.g. your Anthropic key is sent only to Anthropic's API endpoint during your request).
- You control deletion.You can remove your API key at any time from Settings › AI Providers. Deletion permanently removes the encrypted ciphertext from our database.
Cookies
We use essential cookies for authentication and your preferences (such as theme). Optional analytics and marketing cookies are only set after you accept them in our cookie banner, and no non-essential cookie loads before you consent. You can change or withdraw your choice at any time from our Cookie Policy page, and we honour the Global Privacy Control (GPC) browser signal. That page also lists every cookie, its purpose, and its duration.
Sub-processors
We share data with a small set of vetted sub-processors that help us run the service (hosting, database, payments, transactional email, error monitoring, and AI processing). The current list, including each vendor's purpose and data location, is published on our Security page. We do not sell your personal information.
Data Processing Agreement
Business customers can request a GDPR Art. 28 Data Processing Agreement. See how to request a DPA.
Your California privacy rights (CCPA / CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act, as amended by the CPRA.
Categories of personal information we collect. Identifiers (name, email, account ID); commercial information (subscription plan and billing handled by Stripe); internet and network activity (login activity: timestamp, IP address, user-agent, approximate country; usage metadata); and the content you submit for processing. We collect these to provide and secure the service, as described above. We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not knowingly collect data from children.
We do not sell your personal information,and we do not "share" it for cross-context behavioural advertising. Analytics and marketing cookies run only with your consent. You can opt out at any time using the Do Not Sell or Share My Personal Information control on our Cookie Policy page, and we treat a Global Privacy Control signal as a valid opt-out.
Your rights. You have the right to know what personal information we hold and how we use it, the right to delete it, the right to correct it, and the right to opt out of any sale or sharing. You can exercise the rights to know and delete directly: download a copy of your data or permanently delete your account from Settings. You may also email us (see Contact below) and we will respond within the timeframes the law requires.
Non-discrimination. We will never deny you service, charge a different price, or provide a different quality of service because you exercised any of these privacy rights.
Changes to this policy
If we make material changes, we will update the date above and, for signed-in users, show a notice on your next visit.
Contact
Questions? Email support@kindyhero.com or see our Terms of Service.