Privacy Policy
This policy explains what data Kirelta ("we") collects when you use kirelta.com and api.kirelta.com, and how we handle it.
1. What we collect
| Data | Purpose |
|---|---|
| Name, email, hashed password | Account creation & login |
| API keys (hashed) | Authenticating your API requests |
| Model data you send us (rows/features) | Computing drift & calibration signals |
| Usage metrics (requests, latency) | Billing, reliability, abuse prevention |
2. How we use it
Solely to operate the Service: authenticate you, compute the statistics you request, bill usage-based plans, and respond to support requests. We do not sell your data.
3. Storage & security
Data is stored in a managed PostgreSQL database. Passwords are salted and hashed (PBKDF2); API keys and email verification tokens are stored as SHA-256 hashes, never in plain text. All traffic uses HTTPS. Access to production systems is restricted to the operator.
4. Third parties
- Hosting: Railway (application & database), Cloudflare (DNS, static site).
- Email: Resend (transactional email — verification, password reset), when enabled.
- Billing: Paddle, as merchant of record for paid plans, when enabled.
Each processes only the minimum data needed for their function and is bound by their own privacy terms.
5. Retention
We retain account and usage data while your account is active, and for a reasonable period after closure for legal/accounting purposes. You can request deletion at any time.
6. Your rights
You may request access to, correction of, or deletion of your personal data by emailing . We will respond within a reasonable timeframe.
7. Cookies
The dashboard uses browser local storage to keep you signed in; we do not use third-party advertising cookies.
8. Changes
We may update this policy; material changes will be notified by email or in-app.