Privacy Policy
Last updated: August 2, 2026
This Privacy Policy explains how Kairne(“we,” “us,” or “our”) collects, uses, and shares information when you use our website, dashboard, public profiles, and related services (collectively, the “Service”). By using the Service, you agree to the practices described here.
1. Who is responsible for your data
The operator of Kairne is the data controller for personal information processed through the Service. Contact us at support@kairne.dev for privacy questions or requests.
2. Information we collect
Account and authentication data
When you register or sign in with GitHub, we collect:
- Name, email address, and profile image from your GitHub account
- Email verification status (where required for billing or security)
- Session identifiers, IP address, and browser user-agent
- OAuth provider data (GitHub account ID, access and refresh tokens, granted scopes)
Profile and portfolio data
When you build your portfolio, we store information you provide or sync, including:
- Username, bio, tagline, availability status, and location
- Website, LinkedIn, X (Twitter), and public contact email links
- GitHub username and synced repository metadata
- Project case studies, updates, resume sections (experience, education, skills), and visibility preferences
- Username change history
- Resume PDF upload metadata and file storage references
Billing data
If you subscribe to Pro, Stripe processes payment information. We receive and store subscription identifiers, plan, status, billing interval, and Stripe customer ID. We do not store full payment card numbers.
Public profile visitor analytics (Pro feature)
When a Pro user's public profile is viewed, we collect first-party engagement events to power recruiter analytics for that profile owner. For each event we may record:
- Event type (for example, profile view, project click, resume download)
- Page path, tab, project identifier, or link type
- Approximate country and region (from hosting headers or IP geolocation)
- Referring website hostname
- Device category (desktop, mobile, or tablet) derived from user-agent
- A daily pseudonymous visitor identifier created by hashing your IP address, user-agent, profile owner ID, and a rotating daily salt
We do not store raw visitor IP addresses in analytics records. Profile owners do not receive visitor IP addresses in their analytics dashboard. We skip analytics for known bots, prefetch requests, and when the profile owner views their own profile.
Technical and security data
We automatically process certain technical information, including:
- Server and application logs
- Rate-limiting and abuse-prevention signals (IP address, fingerprint data)
- Webhook and background job processing records
3. How we use information
We use collected information to:
- Provide, maintain, and secure the Service
- Authenticate users and manage sessions
- Sync GitHub repositories and display public profiles
- Generate and serve resume PDFs
- Process subscriptions and enforce plan limits
- Send transactional emails (for example, account deletion confirmation)
- Provide Pro recruiter analytics to profile owners
- Detect fraud, abuse, and security incidents
- Improve reliability and develop new features
- Comply with legal obligations
We do not sell personal information. We do not use third-party advertising or cross-site tracking pixels on the Service.
4. Public information
Content you publish on your public profile — including your display name, bio, projects, updates, resume details, and links you add — is visible to anyone on the internet and may be indexed by search engines. Choose carefully what you publish and what contact information you expose.
Your account email address is not displayed publicly unless you set the same address as your public contact email.
5. Third-party service providers
We use trusted providers to operate the Service. They process data on our behalf under contractual safeguards:
- Supabase / PostgreSQL — primary database hosting
- Supabase Storage — private storage for uploaded resume PDFs
- Stripe — subscription billing and payment processing
- Resend — transactional email delivery
- GitHub — OAuth sign-in and repository synchronization
- Vercel — application hosting
- Upstash Redis — rate limiting and authentication session caching
- Arcjet — bot detection, email validation, and auth route protection
- Inngest — scheduled background jobs (for example, analytics retention)
When you use embedded content on your profile (such as Loom videos) or when visitors load GitHub contribution data in the browser, those third parties may collect information under their own policies.
6. Cookies and similar technologies
We use cookies and similar storage for authentication, security, and basic functionality. See our Cookie Policy for details.
7. Data retention
- Account and profile data is kept while your account is active and as needed to provide the Service.
- When you delete your account (Settings → Security), we delete or anonymize personal data associated with your account, cancel any active Pro subscription, and remove uploaded resume files from our storage, subject to limited backup and legal retention exceptions.
- Pro recruiter analytics events are retained for up to 90 days, then deleted by automated retention jobs.
- Former usernames may remain reserved and redirect for a limited period after a username change.
- Session and security logs are retained for a limited operational period unless longer retention is required for security or legal reasons.
8. Security
We use administrative, technical, and organizational measures designed to protect personal information, including encrypted connections (HTTPS), access controls, and rate limiting. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
9. Your choices and rights
Depending on where you live, you may have rights to:
- Access, correct, or delete personal information we hold about you
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Port data you provided to us
- Lodge a complaint with a supervisory authority
You can update much of your profile data in Settings. You can revoke active sessions and disconnect linked OAuth accounts in the Security section. You can permanently delete your account from Settings → Security; GitHub sign-in accounts must confirm deletion via a link we email to you. To exercise other rights, contact support@kairne.dev. We may need to verify your identity before fulfilling a request.
10. International transfers
We and our service providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards for cross-border transfers.
11. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may be communicated by email or in-product notice where appropriate.
13. Contact
Privacy questions or requests: support@kairne.dev
Service terms: Terms of Service