Draft — to be reviewed by a lawyer before launch.
Privacy Policy
Kitgrow is built so that what you record stays with you. This policy explains the little we do collect, why, and what you can do about it. [Business or personal name] (“we”) is the controller of this data.
1. What stays on your computer
The apps you build and everything you record in them are stored in a file on your computer, along with automatic local backups. If you use your own Anthropic API key, it is stored encrypted on your computer and your AI requests go directly from your computer to Anthropic. We cannot see any of this.
2. What we collect
| Data | Why | How long |
|---|---|---|
| Email address and sign-in records | To create your account and sign you in | Until you delete your account |
| AI usage: request type, model, token counts, cost, success, time | To apply plan limits, bill fairly and prevent abuse | Until you delete your account |
| AI results waiting for your app to pick them up | To deliver the result of a request | Deleted when your app receives them, or after 2 days |
| Subscription status (plan, renewal date, Paddle customer and subscription IDs) | To give you the features you paid for | While you are subscribed, then as required by tax law |
We do not store the text of your AI requests. We do not use analytics or advertising trackers in the app. We do not sell your data.
3. What is sent when you use the AI
When you ask the AI to build or change something, the app sends what is needed to answer: your request, the structure of the feature (names and types of its fields), and — only when you ask it to enter or change records — a short excerpt (up to 200 characters) of the relevant records, at most 100 per feature. When you import a CSV file, it sends column names, simple statistics and up to 3 short example values per column, not the whole file. This goes through our server to Anthropic, which processes it to produce the answer under its commercial terms and does not use it to train its models.
4. Service providers
| Provider | What for | Location |
|---|---|---|
| Supabase | Accounts, usage records, running AI requests | [Region] |
| Anthropic | Answering AI requests | United States |
| Paddle | Payments and subscriptions (Merchant of Record) | United Kingdom and others |
| Cloudflare | Website and app update downloads | Global |
| [Email provider] | Sending sign-in emails | [Location] |
Paddle collects your payment details directly under its own privacy policy; we never see your card. When the app checks for updates, the update server sees your IP address and app version, as any download does.
5. Your rights
You can access, correct, export or delete your data and object to its processing. You can delete your account at any time from the app’s settings (Settings → Account → Delete account) or by emailing privacy@kitgrow.app; we delete your account data within 30 days, except records we must keep by law (such as tax records). Your local records are not affected — delete the app’s data folder to remove them.
6. Security
Connections are encrypted. Access to account data is limited to what each part of the service needs, and your own API key is encrypted with your operating system’s secure storage.
7. Children
The online services are not intended for children under 14.
8. Changes
We will announce material changes in the app or by email before they take effect.
9. Contact
[Business or personal name] · privacy@kitgrow.app