Public pre-release policy
Privacy notice
This notice separates website identity data from local mission content and from data sent to a model provider the user chooses.
1. Data covered by this notice
This notice covers data processed through the Kratyx website and, where stated, the Kratyx desktop product. It does not replace the privacy terms of Google, Apple, Supabase, a model provider, an operating system, or another service a user chooses.
2. Website account data
When sign-in is configured, Kratyx receives account identifiers and identity information necessary for authentication, such as an email address and the provider used. Provider profile data may include a display name or avatar when the provider supplies it.
Authentication is provided through the Kratyx Supabase project. Required first-party cookies maintain the website session. No advertising or behavioural analytics service is currently declared on this website.
3. Local mission data
Kratyx is designed around a local-first policy for mission content. Mission descriptions, plans, activity, and local files remain on the device unless the user explicitly selects and accepts a cloud provider or another external execution path.
4. Model providers and external services
Content sent to a cloud model provider leaves the device and is then governed by that provider's data use, retention, security, and availability terms. Users should not include secrets or personal data unless they are authorised to process it and have reviewed the selected provider.
5. Data currently not collected by the website
- No payment-card or billing details.
- No public API usage records.
- No enabled marketing mailing-list submission.
- No declared third-party advertising cookies.
6. Security and retention
Kratyx uses authentication and operational controls intended to limit access, but no service can promise absolute security. Exact retention periods for production account and support data must be approved and published before public release.
7. Your choices
Users can sign out, avoid configuring a cloud model provider, and avoid placing sensitive content in a mission. A verified process for account access, correction, export, and deletion requests must be operational before public launch.
8. Contact and changes
The verified privacy contact is still a launch gate; see support. Material changes will be dated on this page before they apply.