1. Who we are & the scope of this policy
This Privacy Policy explains how [COMPANY LEGAL NAME] [ENTITY TYPE / REG NO.] (“kott”, “we”, “us”) collects, uses, shares and protects personal information when you use kott — the browser-based real-time dither, glitch and VJ studio at kott.io — and related services (the “Service”). For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR and similar laws, the data controller is [COMPANY LEGAL NAME], [REGISTERED ADDRESS].
This policy applies to personal information we process as a controller. It does not cover third-party sites or services we link to, or the separate processing carried out by our payment providers as sellers of record (see Section 7). Capitalized terms not defined here have the meaning given in our Terms of Service.
2. The short version
We collect the minimum needed to run your account and the studio. Your camera and microphone are processed entirely on your device — those frames never leave your browser and we never store them or build a biometric template. We do not sell your personal information or share it for cross-context behavioral advertising. Payment card numbers are handled by our payment providers, not by us. You can export or delete your data from your Account.
3. Categories of personal information we collect
We collect the following, mapped honestly to what the Service actually stores:
Account & authentication data. Your email address (used for passwordless magic-link sign-in and held in our authentication system), and account timestamps. We do not store account passwords because authentication is passwordless.
Profile data. Optional fields you choose to add: username, display name, avatar image, short bio, and website URL. If you make a public profile or publish presets, your username, display name, avatar, bio and website may be shown publicly.
Settings & preferences. Your studio and account preferences — theme, reduced-motion preference, default export format and resolution, locale/language, and a small bounded set of editor preferences — and your notification preferences (which product, gallery-activity, comment, tips and marketing emails you want; marketing email is off unless you opt in).
Your content — projects, presets and exports. If you save to the cloud, we store your project files (which may embed the images you place on the canvas), project thumbnails, project version history, and your presets (effect settings/parameters, titles and tags). Projects are private by default; presets and projects only become public if you choose to publish them. Content you keep local/in-browser is not sent to us.
Community & sharing data. If you use community features: which presets you like, any reports you submit about content, and share links you create (including a view counter for each link). If you create or join a team, we store the team name, your role, and invite email addresses used to invite members.
Billing & entitlement data. A mapping between your Account and a customer identifier at our payment provider, your subscription/license status, plan, billing period, seat count and license keys. We never receive or store your full payment-card number; card data is handled by the payment provider (Section 7).
Usage & operational data. Usage counters and export logs (for example, number of exports in a period, storage used, export resolution/format and whether an export was watermarked), and internal audit-log entries for sensitive actions (such as account deletion, plan changes and publishing) used for security and integrity. If you join a waitlist, your email and any referral code.
Technical data from your device. Basic technical information such as IP address, browser/device type and request logs handled by our hosting and infrastructure providers to deliver and secure the Service. If and when privacy-respecting product analytics are enabled (see Section 8 and the Cookie Policy), we may collect limited usage events — only with consent where required.
4. Camera & microphone — 100% on-device (read this section)
Your camera and microphone are processed entirely on your device. When you enable webcam, screen or microphone input, the frames and audio are read and processed transiently in your browser’s memory, in real time, to produce the live visual effect — and are then released. The on-device computer-vision models (for segmentation and detection) and the audio analysis run locally in your browser; the model files are served to your browser and executed there.
Never transmitted or stored. Camera, screen and microphone data is never transmitted to our servers and is never stored by us. It does not leave your device. (If you deliberately export a still or recording and then choose to save it to your cloud projects or publish it, that exported file — not the live camera stream — is handled like any other content you choose to save; see Section 3.)
No biometric identifier or template. kott does not create, capture, derive, receive, collect, purchase or retain any faceprint, face-geometry scan, voiceprint or other biometric identifier or biometric information as those terms are used under laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington’s biometric and My Health My Data Act (MHMD) provisions, and comparable laws. The on-device segmentation and detection produce only transient rendering data used to draw the current frame; they do not generate an identity record, are not used to identify or authenticate anyone, and are discarded immediately.
Consent.Your browser requires your explicit permission before any website can access your camera or microphone, and it will prompt you the first time. kott is designed to seek your affirmative in-product consent before first accessing your camera or microphone as well. [PLACEHOLDER — confirm the in-app affirmative-consent screen is implemented and recorded before launch; today the browser’s native permission prompt is the operative gate.] You can decline, and you can revoke access at any time from the studio controls or your browser/operating-system settings.
Retention & destruction. Because processing is transient and in-memory on your device, there is nothing for us to retain: no camera, screen or microphone frames are persisted by us, and each frame is released as soon as it is processed. Our retention period for camera/microphone biometric-adjacent data is therefore none. [PLACEHOLDER — biometric- privacy statement (BIPA / CUBI / MHMD) to be confirmed by attorney; do not add any server-side processing of camera/mic streams without re-reviewing this section.]
5. Why we process your information (purposes) & legal bases
Where the GDPR or UK GDPR applies, we rely on the following legal bases (Article 6(1)) for each purpose:
To provide the Service and your account — create and authenticate your Account, store your settings, and sync your projects and presets. Legal basis: performance of a contract (Art. 6(1)(b)).
To process payments and manage plans — via our payment providers, and to maintain your subscription/license status. Legal basis: performance of a contract (Art. 6(1)(b)) and, for tax and accounting records, legal obligation (Art. 6(1)(c)).
To operate community and sharing features — display published presets and public profiles, resolve share links, and count views/likes. Legal basis: performance of a contract and our legitimate interests in operating these features (Art. 6(1)(b) and (f)).
To secure the Service and prevent abuse — audit logs, fraud/abuse prevention, enforcing our Terms and Acceptable Use Policy, and moderation. Legal basis: legitimate interests (Art. 6(1)(f)) and legal obligation where applicable.
To communicate with you — service and transactional emails (always), and product/marketing emails only where you have opted in or as otherwise permitted. Legal basis: consent (Art. 6(1)(a)) for marketing, legitimate interests / contract for transactional messages.
To understand and improve the product — limited, privacy-respecting analytics, only when enabled and, where required, only with your consent (Art. 6(1)(a)); otherwise legitimate interests (Art. 6(1)(f)).
Enabling your camera or microphone in the studio does not create any transmission to us, so no separate legal basis is engaged for us in respect of those frames; your interaction with the on-device feature is under your own control and consent.
6. How long we keep your information (retention)
| Data | Retention |
|---|---|
| Account, profile & settings | While your Account is active; deleted after account deletion (subject to backups below) |
| Projects, presets & exports (cloud) | Until you delete them or delete your Account |
| Billing / license records | As required for tax/accounting law after the last transaction [PLACEHOLDER — statutory period] |
| Usage counters & audit / security logs | [RETENTION — LOGS] |
| Camera / microphone frames | None — transient, in-memory on your device only (Section 4) |
| Backups | Residual copies purged on a rolling cycle [RETENTION — BACKUPS] |
When you delete your Account, we delete or de-identify your personal information within a reasonable period, except where we must retain it to comply with law, resolve disputes, or enforce our agreements, and except for residual backup copies that are overwritten on the cycle above.
7. Who we share information with (subprocessors)
We do not sell your personal information. We share it only with service providers (subprocessors) that process it on our behalf under contract, and where required by law or to protect rights and safety. Current and planned subprocessors:
| Provider | Purpose | Status |
|---|---|---|
| Supabase | Authentication, database & file storage | Active |
| Vercel | Application hosting / delivery | Active (deployment) |
| Paddle | Merchant of record — payments & tax (default) | Active |
| Gumroad | Merchant of record — one-time / Founder license | Active (where used) |
| Stripe | Payment processing | When enabled |
| Polar | Merchant of record — payments | When enabled |
| Resend | Transactional / product email | When enabled |
| PostHog | Privacy-respecting product analytics | When enabled (consent-gated) |
| Sentry | Error / crash reporting | When enabled |
The Merchant of Record (Paddle, or Gumroad/Polar/Stripe where used) is the seller of record for your purchase and processes your payment details as an independent controller under its own privacy notice; we receive only limited billing metadata, never your full card number. We may also disclose information to comply with law, respond to lawful requests, or protect the rights, property or safety of kott, our users or the public. If we are involved in a merger, acquisition or asset sale, personal information may be transferred subject to this policy. We maintain a current list of subprocessors and will provide it on request. [PLACEHOLDER — publish/link a maintained subprocessor list and DPA references.]
8. Cookies & similar technologies
We use a small number of cookies and local-storage items — for authentication (essential), for remembering your studio/theme preferences on your device (functional), and to record your consent choices. Any analytics storage is set only where enabled and, where required, only with your consent. See our Cookie Policy for the full list and how to change your choices, and Section 10 for how we honor Global Privacy Control.
9. International data transfers
We and our subprocessors may process personal information in countries other than yours, including the United States and the European Union. Where we transfer personal information from the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, and, where a provider is certified, the EU-U.S. / UK / Swiss Data Privacy Framework (DPF) — together with supplementary measures as needed. You may request a copy of the relevant safeguards at [PRIVACY EMAIL]. [PLACEHOLDER — confirm transfer mechanism per subprocessor and the operating entity’s location: [GOVERNING ENTITY JURISDICTION].]
10. Your privacy rights
EEA / UK (GDPR & UK GDPR). You have the right to access your personal data; to rectify inaccurate data; to erase data (“right to be forgotten”); to restrict or object to processing (including processing based on legitimate interests, and direct marketing at any time); to data portability; and, where processing is based on consent, to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your supervisory authority [SUPERVISORY AUTHORITY]. We provide in-Account data export and account deletion to help you exercise these rights, and we sign data-processing agreements with our subprocessors.
California (CCPA / CPRA) & other U.S. state laws. If you are a California resident (or a resident of a state with a comparable law, such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others), you have the right to know/access, delete, and correct your personal information, to data portability, and to opt out of the “sale” or “sharing” of personal information and of certain profiling. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We honor the Global Privacy Control (GPC) browser signal as a valid opt-out of sale/sharing. We do not use or disclose sensitive personal information for purposes that require an opt-out right. We will not discriminate against you for exercising your rights. You may designate an authorized agent to make a request on your behalf.
Canada (PIPEDA). If you are in Canada, you may request access to and correction of your personal information and may withdraw consent, subject to legal or contractual limits. You may also complain to the Office of the Privacy Commissioner of Canada.
Brazil (LGPD). If you are in Brazil, you have rights to confirmation of processing, access, correction, anonymization/blocking/deletion, portability, information about sharing, and to withdraw consent, and you may contact the ANPD.
Australia (Privacy Act / APPs). If you are in Australia, you may request access to and correction of your personal information and may complain to us and then to the Office of the Australian Information Commissioner (OAIC).
How to exercise your rights. Use the export and delete tools in your Account settings, or contact us at [PRIVACY EMAIL]. We will verify your identity (usually via your Account email) and respond within the timeframe required by applicable law. These rights are free to exercise, subject to limited exceptions for manifestly unfounded or excessive requests.
11. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or under the higher minimum age that applies to you under Section 3 of our Terms). We use a neutral age gate at sign-up and do not knowingly onboard under-age users. Because camera and microphone processing is on-device and never transmitted to us, our exposure is minimized. If you believe a child has provided us personal information, contact [PRIVACY EMAIL] and we will delete it consistent with the U.S. Children’s Online Privacy Protection Act (COPPA) and other applicable law.
12. Data security
We use technical and organizational measures appropriate to the risk — including encryption in transit, access controls, row-level security on our database, scoped storage buckets (private by default for your projects), and least-privilege service credentials — to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; you are responsible for keeping access to your Account email secure and for backing up important work.
13. Data breach notification
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required by law (for example under the GDPR/UK GDPR or applicable U.S. state breach laws), affected users, within the timeframes the law requires, and describe the nature of the breach and the steps you can take.
14. Changes to this policy
We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, provide additional notice (for example by email or an in-Service notice). Your continued use after a change takes effect constitutes acceptance to the extent permitted by law; where the law requires consent for a change, we will seek it.
15. Kott for macOS (desktop app)
Kott for macOS — the downloadable desktop version of the studio, sold as a $49 one-time lifetime license — is designed to run fully offline after a one-time license activation. It has no account, no telemetry, no analytics, and no crash-report uploading. Any crash diagnostics stay on your Mac and are never uploaded to us. Your camera, screen and microphone are processed on your device exactly as described in Section 4.
The only network requests the app makes. The desktop app makes exactly two kinds of network request, and no others:
(a) One-time license activation. On first launch, the app contacts our activation endpoint once to validate your license key. This request sends only your license key, a random install identifier for that Mac, and the app version — nothing else. It does not send your name, email, files or any usage data. After a successful activation the app works offline and does not phone home again.
(b) Update check. The app checks our public release feed on GitHub releases for a newer version and downloads it if you update. If you are offline, this check fails silently and the app keeps working.
No personal data beyond your purchase email. For the desktop app we do not process any personal data about you beyond the email address used for your purchase, which is held by Paddle (our Merchant of Record, Section 7) and in our license database so we can issue, support, and — where a purchase is refunded or charged back — revoke your license key. The random install identifier described above is not linked to your identity beyond your key. For the full desktop license terms, see the Kott for macOS License Agreement.
16. Contact us
Data controller: [COMPANY LEGAL NAME] [ENTITY TYPE / REG NO.]
[REGISTERED ADDRESS]
Privacy contact: [PRIVACY EMAIL]
Data Protection Officer: [DPO CONTACT]
EU / UK representative (Art. 27 GDPR): [EU/UK REPRESENTATIVE — DETERMINE IF NEEDED]
Related policies: Terms · Cookies · Refunds · Acceptable Use · DMCA · Desktop App License