Skip to main content

Privacy

Privacy Policy

Version 2026-09-01, effective September 1, 2026. Current production behavior, pending owner/legal review.

Status of this policy

Version 2026-09-01. Effective date: September 1, 2026.

This policy describes the current Kiriyar production implementation at a user-facing level. Owner and professional legal review are still required before monetization, advertising, or broader legal-policy finalization.

Kiriyar does not currently claim compliance certification, legal review, a legal entity, a business address, or a specific legal jurisdiction in this policy.

Information Kiriyar processes

The current Kiriyar tool catalog is designed for anonymous browser-local use.

For authenticated account flows, where available or accessed, Kiriyar processes account information needed to run authentication and account features, including email address, display name, email-verification status, password credential records managed by Better Auth, authentication sessions, and verification or password-reset records.

For authenticated account flows, Kiriyar stores password credential records or password hashes for authentication. Kiriyar does not intentionally store plaintext passwords.

If account creation is available, creating an account requires agreeing to the Privacy Policy and Terms of Service shown at sign-up. Kiriyar records the acceptance date and Terms version on the account record. Kiriyar does not currently store a separate Privacy Policy acceptance version, consent-history table, or log of prior versions.

Kiriyar has dormant usage and entitlement foundations for future server-backed tools. Current browser-local tools are not metered and do not create usage records through normal tool use.

Kiriyar may store optional product preferences for authenticated users who complete or skip onboarding or later edit preferences. These preferences are limited to product-relevant tool interests and workflow priorities.

Kiriyar stores selected security audit events for account and recovery actions. These records use pseudonymous internal references and safe metadata rather than passwords, tokens, raw session values, or form payloads.

Kiriyar stores shared-state rate-limit counters for sensitive server actions. These counters use keyed pseudonymous digests and do not store raw email addresses, raw user IDs, raw reset tokens, raw IP addresses, passwords, or session tokens.

Kiriyar emits limited server-side operational logs for production troubleshooting. These logs use allowlisted safe summaries and must not include passwords, raw email addresses, raw IP addresses, cookies, tokens, reset or verification URLs, database URLs, or tool input.

Browser-local tool behavior

The current Kiriyar tool catalog is designed to process tool input, selected files, and generated tool output locally in the user's browser.

Kiriyar does not intentionally upload current browser-local tool input, selected files, or generated output to Kiriyar servers as part of tool processing.

Kiriyar does not use optional product preferences for advertising, demographic profiling, or sharing with transactional email providers.

Clipboard and download actions occur only after explicit user action in the browser.

Authentication, cookies, and storage

Where authenticated account sessions are used, Kiriyar uses Better Auth for email/password authentication and session management.

Better Auth manages authentication cookies for authenticated account sessions. Kiriyar server routes validate sessions server-side; cookie presence alone is not authorization.

Kiriyar stores the `kiriyar-theme` browser preference in localStorage when a user chooses Light or Dark display mode.

The dormant `kiriyar_guest` quota cookie is not issued by normal browsing or by the current browser-local tools. It is reserved for a future anonymous metered server-action flow if such a feature is separately approved.

Production data is stored in PostgreSQL hosted on Railway. Local development databases and production databases are separate environments.

Account deletion

Where authenticated account access is available, self-service account deletion is available for authenticated email/password users after current-password confirmation, an exact confirmation phrase, and an explicit acknowledgement.

When authenticated account deletion succeeds, it removes the live Kiriyar user record, credential account, active sessions, authenticated-user usage records, and authenticated-user entitlement overrides through the current server-authorized flow.

Pseudonymous security audit records, rate-limit counters, operational logs, provider records, and future backup artifacts may remain where reasonably necessary for security, abuse or fraud prevention, reliability, recovery, or applicable legal/compliance obligations.

Kiriyar does not promise immediate deletion from every provider, log, backup, or security system. Exact retention periods remain unresolved owner/legal and provider-policy work.

Backups and retention limits

Railway managed PostgreSQL backups and point-in-time recovery are not currently active for Kiriyar, and no Railway-managed recovery point currently exists.

If the owner later creates retained logical backups or activates managed backups, those backups may contain historical copies of account data until they expire under the applicable backup policy.

Kiriyar does not currently promise immediate deletion from retained backup artifacts, and backup erasure or deletion replay is not implemented yet.

Restored backup data should be used only for owner-approved recovery or restore testing in restricted environments, not for public traffic unless recovery has been approved.

Current interim recovery planning depends on owner-controlled logical backups stored privately outside Git and restored to isolated databases before any production recovery decision.

Kiriyar does not currently specify exact retention periods for security audit events, rate-limit counters, operational logs, transactional email provider records, or future backup artifacts.

External integrations

Railway hosts the Kiriyar application runtime and PostgreSQL database. Railway may process hosting, deployment, database, network, and operational log metadata as part of providing the service.

Transactional email delivery is implemented through Resend for password reset and verification messages when the required owner-controlled environment configuration is present.

When transactional email is active, the provider may process recipient addresses, message contents, action links, and delivery metadata for password-reset and verification delivery. Provider retention depends on the provider configuration and policy.

Public support and legal contact receiving is configured through Porkbun email forwarding for support@kiriyar.com and legal@kiriyar.com. This is separate from Kiriyar's Resend transactional authentication email.

Kiriyar does not send marketing email, newsletters, or bulk email in this phase.

Paid subscriptions, checkout, payment providers, third-party advertising, active analytics/tracking, external logging providers, and network/IP-based application rate limiting are not active.

No card numbers, bank information, payment-provider credentials, ad-provider identifiers, analytics pixels, tracking beacons, session-replay scripts, or marketing email payloads are part of the current runtime.

Security practices

Kiriyar separates server secrets from public browser configuration and intentionally exposes only public app URL configuration to client code.

Security headers, same-origin defaults, server-side session validation, generic health responses, and safe error handling are part of the current foundation.

Users should avoid entering sensitive real-world secrets into browser-local tools unless they are comfortable processing that content in their own browser environment.

Policy updates and contact

Kiriyar may provide notice of policy changes and may require explicit consent or re-acceptance where a future change or applicable requirement makes that necessary. No universal re-consent system is implemented in this phase.

For privacy, legal, or data-related inquiries, contact legal@kiriyar.com. For general account, technical, product, or support inquiries, contact support@kiriyar.com.