본문으로 건너뛰기

Exactly what we collect

A plain-language table of every category of data Kiteloom collects, why, and for how long. This is the detail behind our Privacy Policy.

⚠️ Pre-release notice. Kiteloom is in pre-release. This page reflects exactly what the product collects today; see our Privacy Policy for the rights you have over it.

최종 업데이트 2026-08-06 · v1.0

What we collect

DataCollectedPurposeLegal basisRetention
Email addressAt signupAccount identity, transactional emailContractLife of account + 30 days
Password hashAt signupAuthenticationContractLife of account
Display nameAt signup / editShowing you to collaboratorsContractLife of account
Google profile (ID, email, name, avatar)If you use Google sign-inAuthenticationContractLife of account
2FA secret + backup code hashesIf you enable two-factor authenticationAccount securityContractUntil you disable 2FA
Session records (device, IP address, last seen)On sign-inSecurity, session managementLegitimate interest30-day rolling window, capped at 90 days from creation
Board content (shapes, text, images)As you create itProviding the productContractLife of board + 30-day trash window
Board metadata (name, timestamps, members)As you create itProviding the productContractLife of board + 30-day trash window
Version historyAutomatically, plus on manual checkpointLetting you restore earlier versionsContract7 days on the free plan; unlimited on paid plans
Uploaded imagesWhen you upload one to a boardProviding the productContractLife of board + 30-day trash window
Audit log (auth and admin actions, IP, user agent)AutomaticallySecurity, fraud prevention, complianceLegal obligation / legitimate interest400 days
Rate-limit countersAutomaticallyAbuse preventionLegitimate interestUnder 24 hours (rolling token-bucket windows)
Subscription and payment statusOn purchaseBillingContractLife of account; billing records kept per applicable tax law
Card detailsNever — Paddle handles payment. We never see or store card data.
Error reports (Sentry)When the app errorsFixing bugsLegitimate interestPer Sentry's plan retention policy
Product analytics (PostHog)Only with your consent, once analytics shipsImproving the productConsentPer PostHog's plan retention policy
CookiesSee the cookie table belowSee the cookie table belowConsent / strictly necessarySee the cookie table below

Cookies

A cookie is a small file a website stores in your browser. Here's every cookie Kiteloom sets, first-party or otherwise:

NameCategoryPurposeExpiryParty
better-auth.session_tokenStrictly necessaryKeeps you signed in30 days, refreshed on activity, capped at 90 days from sign-inFirst-party
ph_<project_key>_posthogAnalyticsProduct usage analytics — only set once you accept analytics cookies12 monthsThird-party

Strictly-necessary cookies can't be switched off — they're what keeps you signed in. Analytics cookies are opt-in only, through the cookie banner, and no analytics cookie is set unless you accept it there. You can change your choice at any time from the "Cookie settings" link in our footer.