Last updated: September 8, 2026
Kemkit is built to require as little of your data as possible. This policy explains what we do and don't collect, and how the few things we do touch are handled.
Kemkit's core tools work without an account, and we never keep your uploaded images on our servers. The one exception is when you choose to send slices to your own Klaviyo account, which necessarily uploads them to Klaviyo — see below. Some parts of Kemkit do involve personal data, and this section says exactly which. Specifically:
If you sign up for a paid plan, Polar — our payment processor — will collect billing information (name, email, payment method) directly. We don't see or store your full payment details; Polar handles that as the merchant of record.
If you create an account, we collect your email address and a password, which is stored only as a secure hash. Supabase handles this for us. We use it to sign you in and to connect you to a plan.
We count the emails you upload. Kemkit has a monthly allowance measured in emails, so we keep a count of how many you have uploaded in your current allowance period, along with a short-lived identifier per email so that working on the same one again is not counted twice. If you subscribe, that period follows your billing cycle; on a free account it runs from your sign-up day each month; signed out, it is a rolling 30 days from your first use. Signed in, that count is stored against your account. Signed out, it is counted against your network (IP) address instead, and that record expires automatically within 40 days. We apply a short-term rate limit using the same identifier. IP addresses count as personal data in some places, which is why we spell this out — we use them for counting and abuse prevention, nothing else.
If you subscribe, we store which plan you are on and a reference to your Polar subscription, so paid features unlock. We never see or store your card details.
We may use anonymous, aggregate usage analytics (like page views or feature usage counts) to understand how Kemkit is used and improve it. This doesn't identify you personally.
Kemkit's core tools don't currently use tracking cookies. If we add advertising (planned, to support the free tier) or more detailed analytics in the future, this policy will be updated to describe what's used, and — where required by your location — we'll ask for consent first.
Using Kemkit means some of your activity touches these third parties:
| Service | What it's used for | What it sees |
|---|---|---|
| Google (Gemini) | Copy Extractor reads your uploaded image | The image you upload, for a single request |
| Anthropic (Claude) | Copy Extractor fallback when Gemini is unavailable | The image you upload, for a single request |
| Supabase | Accounts, sign-in, plan and usage records, and your encrypted Klaviyo token | Your email address, hashed password, plan, extraction count, and your encrypted Klaviyo connection |
| Upstash | Rate limiting, and monthly counts for signed-out visitors | Your IP address, held no longer than 40 days |
| Shopify | Link Finder scans store pages | The store URL you provide; this is a request to a public store page, same as visiting it in a browser |
| Polar | Payment processing (paid plans) | Your billing information, if you subscribe |
| Klaviyo | Connecting a Klaviyo account, and sending slices to it | Only if you connect one: your account name, plus any images, copy and links you choose to send to your own Klaviyo account |
| Vercel | Hosting | Standard web server logs (IP address, request metadata) |
| Google Workspace | Our own business email (hello@kemkit.com) | Not applicable to your data — this is how we receive your emails to us |
Each of these has its own privacy policy governing how they handle data.
We don't retain your uploaded images or extracted text after processing — Slicer never sends them anywhere, and Copy Extractor's server-side call discards the image immediately after returning the extracted text to your browser. Extracted copy exists only in your browser session unless you copy or save it yourself.
The exception is a Klaviyo connection, if you create one. We keep the encrypted token until you disconnect it in Kemkit or revoke it in Klaviyo, at which point the stored record is deleted. Images you have already sent to Klaviyo live in your own Klaviyo account and are yours to manage there.
Depending on where you're located, you may have rights to access, correct, export, or delete personal data we hold about you, or to object to certain processing. We still collect little by design — but if you have an account we hold your email address, your plan, your email count, and — only if you created one — your encrypted Klaviyo connection, and if you have used Kemkit while signed out we hold a short-lived count against your IP address. To see, correct, or delete any of it, email hello@kemkit.com and we'll action it.
Kemkit isn't directed at children, and we don't knowingly collect information from anyone under 13 (or the relevant minimum age in your location).
We take reasonable measures to protect the limited data we handle, including using secure connections (HTTPS) and relying on reputable third-party providers (Vercel, Supabase, Upstash, Polar, and our AI providers). Your Klaviyo token is encrypted before it is stored, so a copy of our database alone would not grant access to your Klaviyo account. No system is 100% secure, and we can't guarantee absolute security.
We'll update the "Last updated" date above whenever this policy changes. Material changes (like adding accounts, ads, or new data collection) will be called out clearly, not buried in a routine update.
Questions about this policy or your data? Reach us at hello@kemkit.com.