Trust & Privacy
What we store
This is the complete picture of what a Kymo event row contains. Nothing here identifies a person across a day or a site.
A human event
| Field | Type | Required | Description |
|---|
A bot event
AI-crawler and search-crawler hits are stored with the crawler's classification instead of a visitor:
| Field | Type | Required | Description |
|---|
Never stored
- Raw IP addresses.
- Raw user-agent strings from human visitors. (AI crawler user-agents are kept on the crawler's own event row, so a classification can be audited and corrected. A crawler is not a person.)
- Full referrer URLs with their query strings.
- Cookies — on your site or on Kymo.
- Any cross-day or cross-site identifier. The first-touch key
beat.jswrites on your own domain holds a traffic source and a timestamp, and no identifier of any kind — see First-touch attribution. - Names, emails, or form field contents. (A goal name or revenue you pass with
window.kymois stored as you send it — so do not put personal data there.)
See Privacy model for how identity works without any of the above.
Data attribution
Kymo identifies the network a crawler request came from using a local IP-to-ASN database. The lookup happens in memory and the address is discarded immediately; it is never stored, as stated above.
That database is built from three sources, each licensed under a Creative Commons Attribution 4.0 International License:
- IP Geolocation by DB-IP
- IP-to-AS data by Route Views
- Address allocation statistics by the NRO