Privacy Policy
Kymo ("kymo", "we", "us") is a cookieless web analytics platform. This page explains what data we collect, why, and what happens to it — for three different kinds of people: visitors to a website that has installed kymo's tracker, AI crawlers whose fetches a customer's server reports to us, and account holders who sign up for kymo itself.
1. Visitors to a site using kymo
Kymo is built to work without cookies and without storing anything that identifies a specific person long-term.
- No raw IP address or user-agent string is ever stored. On each page view, we compute a one-way hash (SHA-256) of a daily rotating salt, the visitor's IP, their user-agent, and the site — then discard the originals. This hash changes every day at UTC midnight, so it cannot be used to track a visitor across days or across different sites.
- We do store: the page path viewed, referrer (hostname only), an approximate location (country/city, derived from network-level geolocation, not GPS), device type and browser family, UTM campaign parameters if present, and the timestamp.
- We do not use cookies, local storage, or any other persistent identifier to track visitors. The only client-side storage kymo's tracker ever writes is a same-origin opt-out flag if a site owner chooses to exclude their own visits.
- We do not sell, rent, or share this data with advertisers or data brokers. It is visible only to the site owner who installed the tracker, through their kymo dashboard.
2. AI crawlers
Separately, a customer's own server can report to kymo when an AI crawler (e.g. GPTBot, ClaudeBot, PerplexityBot) fetches one of their pages. This is infrastructure-level traffic, not personal data — we classify the crawler by its user-agent string and record the page it fetched, never anything that identifies a human.
3. Account holders
If you create a kymo account (to view your own site's dashboard), we collect the email address you sign up with, and, if you choose Google or GitHub sign-in, basic profile information those providers share with us (typically name, email, and avatar). Authentication is handled by Supabase Auth — kymo never sees or stores your password in plain text, and for OAuth sign-in we never see your Google/GitHub credentials at all, only a token confirming who you are.
4. Where data is stored and processed
- Supabase (Postgres database + authentication) — stores all analytics events and account data.
- Vercel — hosts the application and processes requests at the edge.
- Stripe (optional) — if a customer wires up conversion tracking, Stripe processes payment events; kymo only stores the resulting purchase amount and the visitor hash it's attributed to, never card details.
- Google / GitHub — only involved if you choose OAuth sign-in, governed by their own privacy policies.
We do not use any advertising or analytics-of-our-own third party beyond what's listed here.
5. Data retention
Analytics events are retained for as long as the site's kymo account is active, so historical trends remain available. Because the visitor hash rotates daily, individual events are not linkable to a person beyond that day even while the row itself persists. Account data is retained until you delete your account.
6. Your rights
You can request access to, correction of, or deletion of your account data at any time by contacting us at nscharan007@gmail.com. If you are a visitor to a site using kymo and have questions about that site's own data practices, please contact that site directly — kymo acts as their data processor, not the data controller for their visitors.
7. Changes to this policy
We'll update the date at the top of this page when this policy changes. Material changes will be communicated to account holders by email.
8. Contact
Questions about this policy: nscharan007@gmail.com
Ekam Shunyam, operating kymo.in