Legal
Privacy Policy
Effective date: 1 July 2026 · KYN Technology Pte Ltd · Contact: privacy@kyn.com.sg
1. Data We Collect
- Account data: your Google account email and profile name, used for sign-in and workspace membership.
- Client business information: brand name, domain, business description, ideal customer profile, goals and tone — provided during onboarding and used to steer monitoring and generation.
- Tracked URLs and site data: the pages you track, their fetched content, technical scan results, and citation-check results from AI engines.
- Competitor data: the competitor names/domains you configure and per-engine mention data collected about them.
- CMS credentials: credentials for publishing destinations you connect (WordPress, Webflow, Shopify, Ghost) — stored encrypted (AES-256-GCM), write-only after saving, and never exposed in logs, error messages, or client-side responses.
2. Your API Keys
LLM provider API keys you supply are stored encrypted (AES-256-GCM) and are write-only after saving — the dashboard shows only the last four characters and a validity status. Keys are decrypted server-side solely to perform the work you have configured (probing, analysis, generation) and are never shared with other clients, never used for our own purposes, and never included in logs or error output.
3. How We Use Data
Data is used to operate the Service for your workspace: running scheduled checks, generating and publishing content, applying and verifying fixes, computing reports, and sending the notifications you enable. We do not sell personal data. Access within the Service is scoped per workspace via row-level security.
4. Third-Party Subprocessors
The Service relies on the following categories of subprocessors:
- Supabase — database, authentication, and storage (region: Singapore (ap-southeast-1)).
- Vercel — application hosting and content delivery.
- Stripe — subscription billing (we never store card details).
- AI providers — Anthropic, OpenAI, Google, and Perplexity APIs, invoked with your own API keys for probing and generation; prompt text and page content are transmitted to them as part of that work.
- Resend — alert and report emails.
The current detailed list is available on request at privacy@kyn.com.sg.
5. Data Retention
Workspace data (checks, logs, reports, articles) is retained for the life of your subscription plus 90 days after cancellation, after which it is deleted or irreversibly anonymised. Encrypted credentials are deleted within 30 days of account closure or immediately on your request.
6. Your Rights
Subject to applicable law (Singapore's Personal Data Protection Act (PDPA) and, where applicable, the EU GDPR), you may request access to, correction of, export of, or deletion of your personal data by contacting privacy@kyn.com.sg. We respond within 30 days.
7. Contact
KYN Technology Pte Ltd · Singapore · privacy@kyn.com.sg