Privacy
Last updated: 2026-07-06
What we collect
- Identity: the handle you claim. If you activate email-link sign-in (post-GA, behind operator activation), we also store the email you verify.
- Content: playbooks you create, version history, comparison results, audit log of your actions (create/update/share/revoke/fork/export/trust events).
- Authorization: trust-graph relationships, workspace memberships, share grants you create.
- Operational telemetry: request IP (as a partially-hashed rate-limit key, not stored long-term beyond the limiter window) and user-agent (audit log entries for package export events only).
What we do with it
We use this data exclusively to run the service: render your playbooks, enforce permissions, log auditable actions, scan for sensitive content before share, and rate-limit abusive requests. We do not sell user data, share it with third-party advertisers, or use it to train AI models.
Privacy scanning
When you create or share a playbook, the privacy scanner runs against the content on our own server. It normalizes the text and strips zero-width characters before matching, so common Unicode evasion (zero-width joiners, lookalikes) does not bypass it. The scanner is deterministic, not AI-based — we don't send your content to any third-party AI provider (e.g. OpenAI, Anthropic) unless you have explicitly turned on the optional AI enhancement feature for your account.
Your rights (GDPR / CCPA)
- Access: every playbook you create is exportable as Markdown / JSON / YAML from /playbooks.
- Rectification: edit any playbook via the playbook detail page; each save creates a new version.
- Erasure / right to be forgotten: email
jckeen@keenmediainc.comfrom your verified email or from the address associated with your account. We anonymize your audit-trail references and hard-delete your User row, playbooks, versions, share grants, and trust relationships within 30 days. Workspaces you own require explicit ownership transfer or hand-deletion before User deletion can proceed (FK constraint). - Portability: exports use canonical Markdown / JSON / YAML; no proprietary lock-in.
- Objection / restriction: revoke any share or set any playbook to private at any time.
Analytics
We use Vercel Web Analytics for aggregate page-view counts. It is privacy-focused and cookieless: it sets no cookies and does not build a cross-site profile of you. Before any page view is sent, we strip the query string from the URL, so anything carried in a link — invite codes, sign-in codes, or other tokens — is never transmitted to analytics. We record product funnel events (such as an invite being claimed or a playbook fork) only in our own first-party audit log; those are not shared with any third party.
Cookies
We set one cookie: a secure, http-only session cookie that holds a signed reference to your account and expires within 30 days (enforced on our server). Our analytics is cookieless (see above), and we use no third-party advertising or cross-site tracking cookies.
Data retention
Active playbooks, versions, and audit events are retained for the life of your account or until you delete them. For users who delete their accounts, your identifier is removed from those audit records. Rate-limit buckets are evicted after their window; no long-term IP logging.
Hosting
The application and its database run on reputable cloud infrastructure providers located in the United States. Those providers have their own privacy practices that apply to data in transit and at rest within their infrastructure.
Contact
Privacy concerns, deletion requests, or DPA inquiries: jckeen@keenmediainc.com.