Privacy Policy
Effective: July 17, 2026
1. Who we are
Kilden is operated by Freshwork S.p.A. ("Kilden", "we", "us"), based in Chile. This policy explains what personal data we handle and how. Kilden plays two distinct roles:
- Controller — for data about visitors to our websites and holders of Kilden accounts. Sections 2–4 cover this.
- Processor — for the data our customers send to the platform about their own users ("End-User Data"). We process it on the customer's instructions; the customer is the controller. Sections 5–6 cover this.
2. When you visit our websites
Apart from Google Ads and the Meta Pixel (both described at
the end of this section), kilden.io
(docs included) and the panel use no other third-party analytics, advertising or
tracking services. For our own product analytics we use our own Kilden
SDK on our websites and in the panel — the same first-party product we offer
customers, sending data only to our own platform. It collects page views, product usage
events and the identifiers
listed below, and in the panel it may also record sessions with Kilden session replay (text
you type is masked by default and passwords are always masked). You can stop all of this at
any time by running kilden.optOut() in your browser's developer console: it
sets the kilden_opt_out cookie and halts all capture on that browser,
including session replay. Our web server logs (IP address, user agent, requested URL) are
kept for up to 30 days for security and troubleshooting.
Functional cookies:
| Cookie | Purpose | Duration |
|---|---|---|
landing_locale | Remembers your language choice on kilden.io | 1 year |
kilden_root_session | Keeps you signed in to the panel | Session |
XSRF-TOKEN | Protects forms against cross-site request forgery | Session |
remember_* | "Remember me" sign-in, if you choose it | Long-lived |
appearance, sidebar_state | UI preferences (theme, sidebar) | Up to 1 year |
Analytics cookies, set by our own Kilden SDK for the kilden.io domain and its
subdomains:
| Cookie | Purpose | Duration |
|---|---|---|
kilden_anon_id | Random anonymous identifier generated in your browser | 1 year |
kilden_distinct_id | Your account identifier, once you sign in | 1 year |
kilden_session | Groups events into a browsing session | 1 year |
kilden_first_touch | How you first arrived (landing page, referrer, UTM parameters) | 1 year |
kilden_opt_out | Remembers that you opted out of analytics and replay | 1 year |
Google Ads
Because we advertise Kilden on Google, kilden.io and the panel load the
Google Ads tag (gtag.js). We use it to measure which sign-ups
came from our ads (conversion tracking) and to build remarketing
audiences of people who visited our sites. When you create an account, we also use
enhanced conversions: your email address is hashed (SHA-256) in your browser
and sent to Google so it can match the sign-up to an ad click even when cookies are
unavailable. We never send Google your raw email or password. Google acts as an independent
controller for the advertising data it receives; see
Google's advertising policies.
The Google Ads tag sets these cookies on the kilden.io domain and its subdomains:
| Cookie | Purpose | Duration |
|---|---|---|
_gcl_au | Stores ad-click information for conversion measurement | 90 days |
_gcl_aw | Remembers the Google Ads click that brought you here | 90 days |
You can manage or turn off personalized advertising in your Google Ad Center.
Meta Pixel
Because we also advertise Kilden on Instagram and Facebook, kilden.io and the panel load the
Meta Pixel (fbevents.js, served by Meta Platforms Ireland). We
use it to measure which sign-ups came from our ads (conversion tracking) and
to build remarketing and lookalike audiences of people who visited our sites.
When you are signed in we use Meta advanced matching: your email address is
hashed (SHA-256) in your browser and sent to Meta so it can match the visit to an ad even when
cookies are unavailable. We never send Meta your raw email or password. Meta acts as an
independent controller for the advertising data it receives; see
Meta's privacy policy.
The Meta Pixel sets these cookies on the kilden.io domain and its subdomains:
| Cookie | Purpose | Duration |
|---|---|---|
_fbp | Identifies your browser for ad conversion and remarketing | 90 days |
_fbc | Remembers the Meta ad click that brought you here | 90 days |
You can manage or turn off personalized advertising in your Meta ad settings. Google Ads and the Meta Pixel are the only cases where we share data with a third party for advertising; every other subprocessor is listed in Section 7.
3. When you create an account
As the controller of panel accounts, we collect:
- Registration data: name, email address, password (stored hashed), optional company name and workspace name.
- OAuth sign-in (optional): if you sign in with GitHub or Google we receive your name, email and provider account ID. We never receive your password from them.
- Security data: email verification status, two-factor authentication secrets and recovery codes (if enabled), session records including IP address and user agent.
- Communications: emails we exchange with you, and transactional emails we send (verification, password reset, workspace invitations).
4. How we use account data
- to provide, secure and operate the Service (performance of contract);
- to notify you about security issues and material changes to the Service (legitimate interest);
- to understand how our websites and the panel are used and to improve them, through the first-party analytics and session replay described in Section 2 (legitimate interest — you can opt out at any time as described there);
- to comply with legal obligations.
We do not sell personal data, we do not run ads, and we do not use your account data or your Customer Data to train machine-learning models.
5. Data we process on behalf of customers
Customers instrument their own websites and apps with the Kilden SDK or APIs. What is collected is decided and configured by the customer — Kilden stores and processes it on their behalf. Depending on the customer's configuration, End-User Data can include:
- Events and context: page URLs, referrer, device type, screen size, UTM parameters, and custom events and properties the customer defines.
- Approximate location: derived from the visitor's IP address (country, region, city, time zone) against a local geolocation database — no external geolocation service is called. The IP is processed transiently, only to derive that location, and is discarded after processing (held at most in short-lived ingestion buffers, ≤3 days); it is never written to our databases. Customers can turn this off per project. Location is derived using the IP Geolocation by DB-IP database (CC BY 4.0).
- Identifiers: a random anonymous ID generated in the browser, the user ID the customer assigns (which may be pseudonymous or not), and a session ID.
- Profile traits the customer sets, which may include name, email or plan.
- Session recordings (if the customer enables replay): reconstructions of the page and interactions. Text typed into inputs is masked by default and passwords are always masked; customers can additionally exclude or mask any element.
- Messaging data (if the customer runs campaigns): recipient email address, message content, delivery/open/click/bounce events, and suppression lists.
- Feature flag evaluations: which flags were evaluated for which identifier.
If you are an end user of a site or app that uses Kilden, the operator of that site is the controller of this data. Please direct access, correction or deletion requests to them; we support our customers in fulfilling such requests, and forward any we receive directly.
6. The Kilden SDK in your browser
On customers' sites, the SDK stores identifiers in the browser (keys prefixed
kilden_, such as kilden_anon_id and kilden_session) using
localStorage together with a first-party cookie set on the site's registrable domain with a
one-year lifetime, so the identity is shared across that site's subdomains; where cookies
are unavailable the SDK falls back to localStorage or memory only. The SDK exposes an
opt-out API that stops all capture and transmission, including session replay; whether and how
it is offered to you is controlled by the site operator.
7. Sharing and subprocessors
We share personal data only with providers that help us run the Service:
| Provider | Purpose |
|---|---|
| Resend | Email delivery (transactional email and customer campaigns) |
| Polar | Payment processing and subscription billing — receives your name, email, workspace name, plan and metered usage totals if you subscribe to a paid plan |
| DigitalOcean | Cloud infrastructure (compute, managed databases) |
| S3-compatible object storage | Storage of session replay recordings |
| GitHub / Google | OAuth sign-in, only if you choose it |
| Google Ads | Advertising conversion measurement and remarketing on our own sites — receives ad-click identifiers and, on sign-up, a hashed (SHA-256) version of your email (enhanced conversions). See Section 2 |
| Meta Platforms (Meta Pixel) | Advertising conversion measurement and remarketing/lookalike audiences on our own sites — receives ad-click identifiers and, when you are signed in, a hashed (SHA-256) version of your email (advanced matching). See Section 2 |
We may also disclose data when required by law, and in connection with a merger or acquisition (in which case this policy continues to apply to data collected before the change).
8. International transfers
We are based in Chile and our infrastructure and subprocessors may be located in the United States or the European Union. Where data protection law requires it, we rely on appropriate safeguards such as standard contractual clauses with our providers.
9. Retention
| Data | Retention |
|---|---|
| Account data | While your account is active; deleted within 60 days of account deletion |
| Our own analytics data (Section 2) | Session recordings of our sites: same as session recordings below. Analytics events and identifiers: no more than 24 months |
| Web server logs | Up to 30 days |
| Events (End-User Data) | Automatically deleted after the project's retention window — 6 months on Free, 24 months on paid plans by default (a shorter or longer window can be arranged on request) — or sooner if the customer deletes them |
| Profiles (End-User Data) | While the customer's project is active, or until the customer deletes them |
| Session recordings | 30 days in the primary store, then deleted automatically; backup copies expire within a further 15 days |
| Pipeline buffers (message queues) | 3–14 days |
| Email suppression lists | Kept while needed to honor unsubscribe and bounce suppression |
10. Security
Data is encrypted in transit (TLS). Passwords are stored hashed. Server-side write keys are separate from public browser keys, and customer identity assertions can be cryptographically verified. Access to production systems is restricted. No system is perfectly secure; if a breach affects your personal data we will notify you as required by law.
11. Your rights
Depending on where you live (including under the GDPR and Chilean data protection law), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, and to withdraw consent. To exercise these rights, email [email protected] — we respond within 30 days. You may also lodge a complaint with your local supervisory authority. For End-User Data, contact the site operator (see Section 5).
12. Children
The Service is not directed to children under 16 and we do not knowingly collect their personal data for our own purposes.
13. Changes to this policy
We may update this policy. For material changes we will notify account holders by email or in the panel before they take effect. The effective date at the top always reflects the current version.
14. Contact
Freshwork S.p.A. — [email protected]