What we collect
We collect only what is needed to sign you in, run the editor on your site, and bill your subscription:
| Data | Why |
|---|---|
| GitHub account identity — your GitHub user ID, username, and avatar, returned when you sign in with GitHub | To authenticate you and authorize commits to your repository |
| Email address — from your GitHub or Google sign-in, or as you provide it | To identify your account, send service and billing notices, and respond to support |
| Sites and repositories you register — the repository name, your site’s origin/URL, and the plan | To know which sites you may edit and to operate the editor against them |
| Editors you invite — the identity (e.g. Google or GitHub) of collaborators you add | To grant them editing access to your site |
| Billing information — handled by Lemon Squeezy; we receive your subscription status and limited records (e.g. plan, last four digits, country), not your full card | To activate, maintain, and account for your subscription |
| Session and technical data — a session token, plus standard logs (IP address, timestamps, error and request data) | To keep you signed in, secure the service, and debug problems |
We do not store your website’s content as a separate database of record. Your pages live in your own GitHub repository; Kiln reads them and writes your edits back as commits.
How we use it
- To provide and operate the service — sign-in, editing, drafts, history, scheduled publishing, and inviting editors.
- To process and account for your subscription (through Lemon Squeezy) and send related notices.
- To secure the service, prevent abuse, and troubleshoot.
- To respond to your support requests and communicate about the service.
- To comply with legal obligations.
We do not sell your personal information, and we do not use it for third-party advertising.
Third parties we share with
We share data only with the providers that make Kiln work, each acting under its own privacy policy:
| Provider | What it handles |
|---|---|
| GitHub | Sign-in (OAuth) and committing your edits to your repository via the Kiln GitHub App. See GitHub’s privacy statement. |
| Cloudflare | Hosting and delivery of the Kiln service and this website, and storage of operational records. See Cloudflare’s privacy policy. |
| Lemon Squeezy | Payments and billing as our merchant of record; it processes your payment details. See Lemon Squeezy’s privacy policy. |
| Optional sign-in for editors who you invite with a Google account. |
We may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights, safety, and security of Kiln and its users.
Cookies and sessions
When you sign in, Kiln stores a session token so you stay signed in across requests; this is strictly necessary to use the service. We do not use third-party advertising or cross-site tracking cookies on the application. This marketing website does not set advertising cookies. Pages you visit on third-party providers (GitHub, Lemon Squeezy) may set their own cookies under their policies.
Data retention
We keep your account and site records for as long as your account is active. If you delete your account or ask us to, we delete or anonymize your personal data within a reasonable period, except where we must keep certain records (for example, billing and tax records held by us or Lemon Squeezy, or data we must retain to comply with law). Operational logs are kept only as long as needed for security and troubleshooting. Your website content is unaffected because it lives in your own GitHub repository.
Your rights and choices
You can:
- Access or correct the personal data we hold about you;
- Delete your account and request deletion of your personal data;
- Revoke our access at any time by uninstalling the Kiln GitHub App or disconnecting a repository;
- Cancel your subscription to stop future billing (see the Refund Policy).
Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to object to or restrict certain processing and the right to lodge a complaint with a supervisory authority. To exercise any of these, contact us at [email protected]. Note that some data, like billing records, may also need to be requested from Lemon Squeezy.
Children
Kiln is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us information, contact us and we will delete it.
International transfers
Our providers may process data in countries other than yours. Where required, we and our providers rely on appropriate safeguards for such transfers.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice.
Contact
Questions or requests about your privacy? Reach us at [email protected].
Kiln