How we protect your data
Encryption, access control, backups, and how to report a security issue.
अंतिम अपडेट 2026-08-06 · v1.0
Encryption
- In transit — every connection to Kiteloom, including the real-time collaboration connection to a board, is encrypted (HTTPS / WSS).
- At rest — your data is encrypted at rest by our database and file storage provider.
- Backups — we run encrypted, off-site backups of account data on a regular schedule.
Authentication and account security
- Passwords are checked against known-breach databases at signup.
- Optional two-factor authentication (TOTP authenticator app, plus one-time backup codes) is available from Settings → Security.
- Sessions are time-bounded — they refresh on activity but expire outright after 90 days, and you can review or revoke individual active sessions from Settings → Security.
Access control
Every board has an explicit visibility level (private, link-shared, or public) and every member has an explicit role (owner, editor, or viewer) — see Sharing & permissions. Permission checks happen on our servers, not just in the app you see: a viewer's write attempt is rejected server-side even if it were somehow sent, and revoking a share link disconnects everyone using it immediately rather than waiting for their session to end.
Abuse prevention
Rate limiting applies across sign-in, board creation, invites, uploads, and the real-time connection itself, to slow down automated abuse without affecting normal use.
Sub-processors
The full list of who processes data on our behalf, and why, is in the "Who we share it with" section of our Privacy Policy.
Reporting a vulnerability
If you believe you've found a security vulnerability in Kiteloom, please report it through our contact page or the machine-readable contact listed in /.well-known/security.txt. We ask that you give us a reasonable opportunity to investigate and address a report before disclosing it publicly. We commit to acknowledging any good-faith report within 5 business days.
Incident notification
If a security incident affects your personal data, we'll notify affected users within 72 hours of confirming the breach, consistent with applicable data protection law.