← Back home

Privacy Policy

Last updated: 22 September 2026

Draft notice: this is a first draft written to reflect how Kithra actually works today. It has not been reviewed by a solicitor and should not be relied on for real paying customers until it has been. Placeholders in brackets need filling in first.

Who we are

Kithra ([PLACEHOLDER — Companies House number once incorporated], registered office [PLACEHOLDER — registered office address]) is the data controller for the personal data described in this policy. You can contact us at [PLACEHOLDER — e.g. privacy@yourdomain.com].

What we collect

  • Account information: your name, email address, and (optionally) a profile photo and bio.
  • Content you create: posts, comments, likes, connection requests, and direct messages. This is only ever visible to the connections you've mutually confirmed — we don't have a public feed.
  • People you invite: if you add someone by email who isn't on Kithra yet, we store their email address so we can send them one invitation from you and connect you when they join. It's deleted as soon as they join, or if you cancel the invitation, and we never email them again unless you invite them again.
  • Billing information: handled entirely by Stripe, our payment processor. We never see or store your card details — we hold only your subscription status and Stripe's reference IDs for your account.
  • Technical data: standard server logs (IP address, browser type, timestamps) kept briefly for security and debugging, and a session cookie from Clerk, our authentication provider, so you stay signed in.

We do not collect your location, your device contacts, or browsing activity outside this app, and we do not use advertising trackers or cookies of any kind — that's a deliberate product decision, not just a policy one.

Why we collect it, and our legal basis

  • To provide the service (necessary to perform our contract with you) — your account, posts, connections, and messages only exist because you asked us to store them.
  • To process payments (necessary to perform our contract with you) — via Stripe.
  • To keep the service secure (our legitimate interest in preventing abuse and fraud, balanced against your rights).
  • To contact you about your account or billing (necessary to perform our contract with you) — for example, a reminder before your free trial converts to a paid subscription.

Who we share it with

We don't sell your data, and we don't share it with advertisers or data brokers — there aren't any in this product. We do use a small number of specialist processors to run the service, each bound by their own data processing terms:

  • Clerk — authentication and session management.
  • Stripe — payment processing and subscription billing.
  • Resend — sending emails (notifications, trial reminders and invitations).
  • Pusher — delivering messages to your screen in real time.
  • Vercel (including Vercel Blob and Vercel Postgres/Neon) — application hosting, database, and photo storage.

Some of these providers are based in, or process data in, the United States. Where that's the case, we rely on their Standard Contractual Clauses (or equivalent UK-approved transfer mechanisms) to keep your data protected to UK GDPR standards.

How long we keep it

We keep your data for as long as your account is active. If you delete your account, your profile, posts, comments, connections, and messages are permanently deleted — see "Your rights" below for how to do this yourself at any time. Billing records may be kept longer where we're legally required to (e.g. for UK tax purposes).

Your rights

Under UK GDPR and the Data Protection Act 2018, you have the right to:

  • Access the personal data we hold about you
  • Have inaccurate data corrected
  • Have your data erased
  • Receive your data in a portable format
  • Object to or restrict certain processing

You can exercise the access, erasure, and portability rights yourself, any time, from your account settings — no need to email us: use Download my data for a copy of everything we hold about you, or Delete my account to erase it permanently. For anything else, contact [PLACEHOLDER — e.g. privacy@yourdomain.com]. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) if you think we've mishandled your data.

Security

Data is encrypted in transit (TLS) and at rest. Access to production data is restricted, and we monitor for and respond to security issues as a matter of course — this is a company founded by people who work in cybersecurity professionally, and we hold ourselves to that standard.

Children

This service is for people aged 18+ (it's a paid subscription requiring a payment card). We don't knowingly collect data from anyone under 18.

Changes to this policy

If we make material changes, we'll notify you by email or an in-app notice before they take effect.

Contact

Questions about this policy: [PLACEHOLDER — e.g. privacy@yourdomain.com]. General support: [PLACEHOLDER — e.g. support@yourdomain.com].