Privacy Policy

Last updated: May 12, 2026

Kynoras ("we", "us", or "our") operates kynoras.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully.

1. Information We Collect

1.1 Account Information

When you create an account, we collect your name, email address, and password (stored as a cryptographic hash). If you sign in via Google or GitHub OAuth, we receive your name, email, and profile picture from those providers.

1.2 Business Data

As part of the Service, you may provide information about your clients, projects, proposals, contracts, and invoices. This data is stored securely and is used solely to provide you with the Service.

1.3 Usage Data

We collect information about how you interact with the Service, including pages visited, features used, and actions taken. This helps us improve the product and understand usage patterns. We use Google Analytics 4 for this purpose.

1.4 Payment Information

Payment processing is handled entirely by Stripe. We do not store your credit card details. We receive confirmation of payment status and a Stripe customer ID, but never your raw card data.

1.5 Communications

If you contact our support team or sign up for updates, we store the communication and your contact details to respond to your inquiry and improve our Service.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process transactions and send related information including purchase confirmations and invoices
  • Send transactional emails (proposal notifications, invoice reminders, welcome messages) via Resend
  • Respond to comments and questions and provide customer support
  • Monitor and analyze usage patterns to improve the Service
  • Detect, prevent, and address technical issues and fraud
  • Comply with applicable laws and regulations

3. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

  • Session cookies: Required for authentication. We store a secure, HTTP-only JWT session token.
  • Analytics cookies: Google Analytics 4 uses cookies to measure how users interact with our website. You can opt out via your browser settings or the Google Analytics opt-out browser add-on.
  • Advertising cookies: If Google AdSense is active on this site, Google may place cookies to serve relevant advertisements. You can manage ad personalization at google.com/settings/ads.

4. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information with:

  • Service providers: Stripe (payments), Resend (email), Google Analytics (analytics), Cloudflare (infrastructure). These providers are bound by their own privacy policies.
  • Legal requirements: If required by law, court order, or governmental authority.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal purposes.

6. Data Security

We implement industry-standard security measures including HTTPS encryption, HTTP-only cookies, bcrypt password hashing, and encrypted database connections. However, no method of transmission over the Internet is 100% secure.

7. Your Rights (GDPR/CCPA)

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your personal data
  • Portability: Request your data in a machine-readable format
  • Objection: Object to processing of your personal data

To exercise these rights, contact us at [email protected].

8. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us.

9. Third-Party Links

The Service may contain links to third-party websites. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us: