PRIVACY

Privacy Policy

Kenfield is a desktop app for tracking personal learning notes and turning them into weekly syntheses and recommendations. This document explains, in plain and complete terms, what data we collect when you use the app, how we use it, who we share it with, and what rights you have.

1. Who is the data controller

Kenfield is built and operated by Emre Cengiz, acting as an individual. "We" / "us" in this document refers to that person. For any privacy request, question, or complaint, reach out at [email protected].

2. What data we collect

Account data: your email address and password (your password is hashed and salted by our authentication provider, Supabase Auth -- we never see your plaintext password).

Profile data: your display name, profession (chosen during onboarding), and weekly goal -- used to personalize the tone and recommendation pool of your reports.

Your entries ("seeds"): the full text of every learning note you write.

Review/recall data: your FSRS state from Root Test review sessions (stability, difficulty, reps, lapses) -- used to schedule when the next reminder should appear.

Gamification data: your XP, level, streak, and badges -- computed server-side and not client-writable.

Weekly report content: the text of the digest and recommendation reports, stored so you can access them across devices.

Membership and usage data: your membership status and its period end date; and, if you use the Kenfield key, the number of calls, tokens and the cost incurred that month. These numbers exist to enforce the fair-use share and contain no note content.

Device-local settings: some preferences (notification settings, chosen model, quiet hours) live only in your device's local storage and never reach our servers.

3. AI generation: two keys, two different paths

Weekly digest and recommendation reports, per-note branches, Root Test questions and reading articles are generated by a language model, and the similarity embeddings for your entries are produced the same way. This sends the content of your notes to the model. Which key is used is your choice in Settings, and that choice changes the data flow, so both are written out separately below.

If you connected your own key (BYOK): your OpenRouter API key is stored only in your operating system's secure credential store (Keychain on macOS); it is never sent to or seen by our servers. Your note content goes directly from your device to OpenRouter and the model you chose. We do not sit in the middle of that exchange and cannot see its content.

If you use the Kenfield key (the default on the trial and on a membership): the call, including your note content, is forwarded to OpenRouter through our server (a function running on Supabase). So in this flow your note content passes through our infrastructure. We do not store that content: no copy of the request is kept once it has been forwarded, and the only thing that remains on our side is accounting data (call count, token counts and cost). We keep those numbers to enforce the fair-use share and to watch our own spend. On our organisation's OpenRouter account, zero data retention is on, prompt logging is off, and training use is off.

In both cases this use is governed by OpenRouter's and your chosen provider's own privacy policies. We ask for your explicit consent before any data goes to an AI provider, and you can withdraw that consent in Settings at any time; without it, no note content is sent.

4. Who we share your data with

Supabase -- our infrastructure provider, hosting your account, entries, review, and gamification data (database, authentication, server-side functions).

OpenRouter and your chosen model provider -- directly from your device when you use your own key; through our server when you use the Kenfield key. The full distinction is in section 3 above.

Lemon Squeezy -- the merchant of record for the membership bought on the web. They collect and hold your payment and billing details; your card details never reach us. All that comes back to us is your membership status and its period end date.

Apple (App Store) and Google (Google Play) -- if you bought the membership through the store on your phone, the store takes the payment; your card details never reach us. All that comes back to us from the store is the subscription's status, product and period end date. At purchase time the store is given your Kenfield account's identifier (never your email address), so the subscription can be tied to the right account.

Resend -- to email you when your weekly report is ready (only your email address is used for this).

Sentry -- crash/error reporting. Only technical diagnostic data (stack traces, OS/app version) is sent; your note content is never included.

PostHog -- product analytics. Only anonymized/pseudonymous usage data (screen views, feature-usage counts) is collected; your note content is never included.

We never sell your data, and we never share it with ad networks or third-party trackers.

5. How we protect your data

Your OpenRouter API key is stored in your OS's native credential store and is not reachable from the JavaScript layer.

Every table in Supabase is protected by row-level security (RLS): only you can access your own data. "Score" fields like XP, level, streak, and badges are not client-writable; only a server-side trigger can write them.

All data in transit travels over encrypted connections (HTTPS/TLS).

6. How long we keep your data

Your data is kept for as long as your account is active. When you delete your account (Settings → Account), a real server-side deletion runs and your data is permanently removed.

7. Your rights

Access and portability: Settings → "Export your data" lets you download all your notes and data as JSON or CSV, straight to your device.

Deletion: Settings → Account lets you permanently delete your account and all its data.

Correction: you can update your profile details (name, profession, goal) directly in the app.

Objection: contact us at the address above with any question or objection to how we process your data.

If you're in the European Economic Area (EEA): under GDPR, you also have the right to lodge a complaint with your local data protection authority. These rights apply regardless of the governing law stated below, because they follow from where you are, not from our choice of law.

If you're in Turkey: you have the same request rights (access, correction, deletion, objection) under Law No. 6698 on the Protection of Personal Data (KVKK), reachable at the contact address above.

8. Children's privacy

Kenfield is not directed at anyone under 16, and we do not knowingly collect data from them. If we learn that someone under 16 has provided us data, we will delete it on request.

9. Local storage

Kenfield is a desktop app, not a website -- we don't use advertising cookies or cross-site tracking. Some preferences (your chosen model, notification badges, session preference) live only in your device's local storage and never reach any server.

10. Changes to this policy

We may update this policy from time to time. We'll notify you in-app or by email of material changes. The current version always lives on this page.

11. Governing law

This policy is governed by the laws of the Republic of Turkey. This does not limit the GDPR/KVKK rights described in section 7 above in any way.

12. Contact

Questions: [email protected]