Legal
Privacy policy
Written from what the product actually does rather than from a template. If anything here is unclear, ask and we will explain it.
Last updated 21 August 2026
01
Who is responsible
The operator of Kithe (kithe.day) decides what is collected and why, and is the controller of it. Write to [email protected] about anything on this page.
02
What we collect, and why
- Your email address, when you make an account, so we can sign you in and tell you when something changes. It is held by Supabase Auth. We never see your password.
- The addresses you ask us to check, when you check them, and the findings we returned. This is the product.
- Fingerprints of past findings — a check name, a page address and an element selector — so a later scan can tell you what is new rather than repeating itself. Not a second copy of the report.
- The image addresses and alt text on the pages we checked — published markup, already visible to anyone reading the page — so a later scan can tell you when a picture changed and its description did not. Up to four hundred per scan, and used for nothing else.
- A count of scans this month, so a plan’s allowance means something.
- A rate-limit counter derived from your IP address. The address is not stored. It is turned into a short irreversible value first, and that is what the counter is kept against.
We do not use an analytics product, advertising or tracking on this site, and no third-party script runs on any page. See the cookie policy.
We do keep a plain count of how often things happen — how many scans ran today, how many were refused, how many reports were downloaded. It is a name, a date and a number. There is no address in it, no identifier, no page path and no order, so it cannot be tied to you or to anybody else, and no journey through the site can be reconstructed from it even in principle. That is why it needs no cookie and no consent.
03
What we do not collect
- Anything about your visitors. Kithe reads your public pages the way a browser would. It has no access to your analytics, your logs, your customer records or your server, and there is no script of ours on your site through which it could get any.
- Payment details. Payment is not switched on. No card is taken anywhere on this site today.
- Anything behind a login on your site. Kithe fetches what is public and refuses private addresses at the network layer.
04
What the legal basis is
Where the GDPR or the UK GDPR applies: your account and your scans are processed to perform the contract you entered into by signing up. The rate-limit counter is processed under our legitimate interest in keeping a free service available and not becoming a nuisance to other people’s servers — the data is pseudonymous by construction and the interest is hard to serve any other way.
Where PIPEDA applies, the same processing is what a reasonable person would consider appropriate in the circumstances, and creating an account is the consent.
We do not rely on consent for cookies, because the only ones we set are strictly necessary to sign you in.
05
Where it lives, and who else touches it
Data is held in the United States. The companies that process any of it on our behalf are listed, with what each one sees, on the subprocessors page. That page is part of this policy and is kept current.
Nothing is sold. Nothing is shared for advertising. There is no advertising business here to share it with.
06
How long it is kept
- Your account and your scans: until you delete them or close the account.
- Shared scan pages: thirty days, then they stop resolving. A stale result presented as current is the same lie a certificate is.
- The scan cache: thirty minutes. It exists so two people checking the same page in quick succession do not both cost that site a visit.
- The rate-limit counter: it expires with its own window, within a day.
- Aggregate statistics: kept indefinitely, because there is nothing in them to keep — no address, no host, no user, and no way to work backwards to any of those.
07
What you can ask for
A copy of what we hold about you, a correction, deletion, or an export. Email us and we will deal with it. There is no form and no fee.
Deleting your account removes your profile, your sites, your scans, your finding fingerprints and the image records kept alongside them. Aggregate counts your scans contributed to cannot be unpicked, because they were never linked to you in the first place.
If you think we have handled your data badly, tell us first — but you are entitled to complain to a supervisory authority instead, and in Canada that is the Office of the Privacy Commissioner.
08
Automated decisions
Nothing here makes a decision about you. The model reads web pages and drafts wording about those pages; it does not profile people, score them, or decide anything that affects anybody’s rights.
09
Children
Kithe is a tool for people who run websites and is not aimed at children. We do not knowingly hold data about anyone under 16. If you think we do, tell us and it will be deleted.
10
If this changes
The date at the top is the date of the current version. Where a change materially affects account holders, we take reasonable steps to let them know.