How we handle privacy
Last updated: August 5, 2026
This policy explains what information Kumiau (“Kumiau,” “we,” “us”) collects when you use kumiau.com and the related isolated content-serving origin, and how we use, share, and protect it. It’s written to match what the product actually does today, not a generic template — see the “How we use your information” section for specifics.
Information we collect
- Account information. When you sign in, Clerk gives us your verified primary email address and basic profile details. If you choose Google or GitHub, we never receive that provider’s password. A connected coding agent never sees or uses your sign-in credentials.
- Content you upload. The prototypes you upload, every published revision of them, and any comments or feedback written by you or the people you’ve shared with.
- Sharing information. Who you’ve invited to a prototype (their email address) and what permission you’ve granted them — view or comment.
- Agent connections. If you connect an MCP-compatible coding agent, we store the connection’s identity (e.g. its client name) and the scopes you approved — not a copy of your sign-in credentials, and not the agent’s own infrastructure credentials.
- Cookies. A sign-in session cookie on
kumiau.com, and a separate session cookie on the isolated content-serving origin that exists purely so a shared prototype can be embedded safely — neither is used for advertising or cross-site tracking. - Optional product analytics. If you choose to allow them, PostHog receives a small set of product events — for example, that a private preview opened or a share completed. We do not send prototype content, filenames, comments, invite email addresses, names, or private URLs. We do not use these events for advertising or cross-site tracking.
Kumiau uses Vercel Web Analytics to measure aggregate traffic — things like which pages get visited and how often. It sets no cookies and creates no persistent visitor identifier, is served first-party from kumiau.com, and is never used for advertising or cross-site tracking. Every page path it receives has identifiers and query strings stripped before it leaves your browser, so it never sees which specific prototype you viewed. If you turn analytics off in your preferences, this measurement stops as well. The optional PostHog product analytics described above are separate and stay off unless you explicitly allow them. We don’t run third-party advertising trackers on Kumiau.
How we use your information
- To authenticate you and keep your account secure.
- To store, serve, and let you and the people you’ve shared with view or comment on your prototypes, according to the permissions you set.
- To send the transactional emails you or your collaborators trigger — an invitation when you share a prototype with someone, or a reminder if you explicitly resend a pending invite. We don’t send marketing email.
- To let a coding agent you’ve explicitly connected read feedback and publish new revisions within the access you’ve approved.
Who we share it with
We use a small set of infrastructure providers to run Kumiau, and don’t sell your personal data or share it with advertisers:
- Neon — our database provider.
- Clerk — account authentication and management.
- Vercel — application hosting and file storage for uploaded prototypes.
- Upstash — a short-lived cache used to enforce access control on prototype views in real time.
- Resend — delivery of the transactional emails described above.
- Google and GitHub — optional sign-in methods.
- PostHog— optional, privacy-safe product analytics when you choose to allow them. Kumiau uses PostHog’s EU-hosted service for this purpose.
Data retention and deletion
Deleting a prototype moves it to Trash, where you can restore it or delete it permanently; permanent deletion removes its content and revokes access immediately. We retain account information for as long as your account exists. You can request deletion of your account data by contacting us at the address below.
Your choices
- Choose how each prototype is shared — a link anyone can open or an invited verified account, and whether they can view it or leave comments — and change that at any time.
- Revoke a share or a connected agent at any time from Connected clients — access is checked on every request, so a revoke takes effect immediately.
- Delete a prototype, or your account, at any time.
- Choose whether to allow optional product analytics below. You can change this decision at any time.
Cookieless aggregate traffic measurement is on — it sets no cookies and creates no persistent identifier, and you can turn it off here. Optional product analytics are not active right now.
Security
We use database-level access controls scoped to your account so your prototypes and shares are only reachable by people you’ve granted access to, encrypt traffic in transit, and never issue a bearer link that keeps working after you revoke access.
Children’s privacy
Kumiau is not directed at children, and we don’t knowingly collect information from anyone under 13.
Changes to this policy
If we make material changes, we’ll update the date at the top of this page.
Contact
Questions about this policy? Reach us at hello@kumiau.com.