Legal
Privacy
What we hold, where it is, how long it stays, and how to get it back or removed.
This notice describes how Kinoplate ("we") handles personal data when you use the product. It covers the account you sign up for and the data you put into a workspace.
Kinoplate is currently in private alpha. Where something is not built yet, this page says so rather than describing it as if it were.
What we hold
| Category | What it is | Why |
|---|---|---|
| Account | Email address, name, a password hash, profile picture if you set one | To let you sign in and to identify you to your colleagues |
| Two-factor | An authenticator secret and hashed recovery codes, if you enrol | To verify the second factor at sign-in |
| Sessions | A session token, the browser and approximate location it was created from, and when it was last used | To keep you signed in and to let you end a session you do not recognise |
| Organisation | Its name, its members and their roles, invitations you send | To decide who may reach which workspace |
| Workspace content | Templates, uploaded assets and fonts, folders and tags, rendered files, and the values you sent to produce them | Because it is the thing the product makes and stores for you |
| Usage | Render history with what each one cost, API key metadata, and the ledger behind your credit balance | To meter credits and to let you reconcile a bill |
| Operational logs | Request logs, error reports and timings | To keep the service working and to investigate a fault |
An API key's secret is never held. Only a SHA-256 of it is stored, which is why a lost key is rolled rather than recovered, and why no secret appears in any response, log line or client bundle.
Where it is
Everything above is stored and processed in the European Union: the application, the API and the rendering workers in Germany, the database in Frankfurt, and object storage in Cloudflare's EU jurisdiction. There is no US region.
There is one exception, and we would rather name it than have you find it: the AI features use United States sub-processors. When those features ship, an AI prompt and the specific image being processed go to Anthropic, fal.ai or Higgsfield; your template files and rendered artwork do not. The assistant is handed URLs and small JSON, never image bytes. The sub-processor list names every processor, what it does and where it is.
The waitlist
If you leave your email address on this site, we keep exactly three things: the address, when you left it, and which version of the sentence beside the form you left it under. No name, no IP address, no browser details. It is stored by Cloudflare in a database created in its EU jurisdiction.
We use it for one thing: to write to you once, when your invite is ready. We do not send anything else to it, and we do not share it. The basis is your consent, given by sending the form; write to privacy@kinoplate.com and we delete it, whether before or after that email.
An address that is already on the list gets the same answer as a new one, so the form cannot be used to find out whether somebody signed up.
Sign-in
A session lasts seven days and is refreshed as you use it. You can see every session on your account under Settings and end any of them; changing your password ends all the others.
A password reset link lasts one hour, works once, and ends every other session on the account when it is used. We answer the reset form identically whether or not the address is known here - otherwise the form would tell anyone who has an account.
If you sign in with Google, Google is the identity provider you chose and the exchange carries your email address and name. No workspace content leaves the EU because of it. We link a Google sign-in to an existing password account only when Google asserts the address is verified and the account here has confirmed it too; anything else would be account takeover by sign-up.
Cookies
The application sets one cookie: your session. There is no advertising cookie, no cross-site tracker, and no third-party analytics on this marketing site. Its pages are static files with no session of their own; the waitlist form is the one thing on it that stores anything, as described above.
How long it stays
A waitlist address stays until you ask us to delete it, or until the launch email has gone and the list is no longer needed, whichever is first. Account and workspace data stays until you delete it or close the account. Rendered files stay until they are deleted or a workspace's retention setting purges them; a purged render keeps its row and its cost so your history and your invoices still reconcile, and it is marked as purged rather than looking like one that failed.
Operational logs are kept for a short period for debugging and are not used for anything else.
Your rights
Under the GDPR you can ask for a copy of your personal data, ask for it to be corrected or erased, object to processing, or ask us to restrict it. You can also complain to your local supervisory authority.
Today those requests are made by email and answered by hand. Self-serve export, per-workspace deletion and an audit log are built and not yet released; when they are, they appear in the product and this page says where. We would rather tell you to write to us than point you at a button that does not exist.
Processors
We use a small number of sub-processors to run the service. Each one, what it does and where it is, is on the sub-processor list. The data processing agreement covers the terms on which we process data you put into a workspace.
Contact
Write to privacy@kinoplate.com for anything on this page, including a rights request.