Legal
Privacy Policy
Last updated 4 August 2026. This policy covers krowk.com, app.krowk.com, api.krowk.com and the Krowk CLI.
1. Who we are
Krowk is operated by UAB Primevise, a company registered in Lithuania, at Lentvario 18, Vilnius, LT-02300, Lithuania. In this policy “we”, “our” and “us” mean UAB Primevise, and “the Service” means the Krowk website, API, dashboard and CLI.
For everything we do with your own account and usage data, we are the data controller. For personal data that happens to be inside the files your agents upload, we are a data processor acting on your instructions — see section 4.
Privacy questions, requests and complaints: [email protected]. We have not appointed a Data Protection Officer, because our processing does not meet the Article 37 GDPR threshold that requires one. Requests go to the address above and are handled by the people who run the Service.
2. Read this first: artifact links are public
An artifact page such as krowk.com/a/9f3c2e1 is readable by anyone who has the link, with no account and no password. That is the entire point of the product — the link has to work when it is pasted into a pull request or a Slack thread. It also means:
- Anything visible in an uploaded screenshot, recording or log is visible to whoever receives the URL, and to anyone they forward it to.
- Links are unguessable but not secret. Once a URL leaves your control — a public pull request, an issue tracker, a browser extension, a crawler that follows links in a page — we cannot pull it back.
- We ask search engines not to index artifact pages with a
noindexrobots directive. That is a request honoured by well-behaved crawlers, not an access control.
Do not upload credentials, personal data you have no basis to share, or anything you would not paste into the channel you are about to paste the link into. Deleting an artifact removes it from our storage and makes the link return 410 Gone, but it cannot un-see a copy someone already took.
3. Personal data we collect
3.1 Data you give us
- Account: email address and a hashed password. We never store your password itself.
- Workspace: workspace name and the roles of the people in it.
- API keys: the name you give a key and a hash of the key itself. We cannot recover a key once it is issued — only revoke it.
- Support: whatever you put in an email or bug report you send us.
3.2 Data your agents send us
- Artifacts: the file contents, plus its filename, media type, size and checksum.
- Run metadata: whatever the CLI or your CI attaches to a run — typically repository, branch, commit, task and run-log URLs, and the name of the agent. Commit and branch names routinely contain a person's name or email; that is personal data, and it is data you choose to send.
3.3 Data we collect automatically
- Sessions: for dashboard logins, the IP address and user-agent string of the browser that signed in, so you can spot a session you do not recognise.
- Usage events: uploads, bytes stored, transcoding minutes and which key was last used when — the counters your quota and invoice are built from.
- Server and edge logs: request time, path, response status, IP address and user-agent, kept short-term for security and debugging.
3.4 What we do not collect
We do not ask for your name, job title, photograph or phone number. We do not store card numbers — payments are handled by our payment processor and we only ever see the billing details it passes back to us. We do not buy personal data from data brokers, we do not sell or rent personal data to anyone, and we do not run advertising or cross-site tracking on the Service.
4. When we are a processor, not a controller
The contents of your artifacts are yours. Where they contain personal data — a customer's name in a screenshot of an orders dashboard, say — you are the controller and we process it only to store it, serve it at its link, generate previews and thumbnails, and delete it when it expires or you ask us to. We do not read your artifacts for any other purpose, and we do not use them to train machine-learning models.
If you need a Data Processing Agreement with Standard Contractual Clauses, we will sign one — write to [email protected]. Until it is signed, the processor terms in our Terms of Service apply.
5. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Run the Service: store artifacts, serve links, unfurl them | Artifacts, run metadata, account | Contract (b) |
| Authenticate you and keep sessions and keys working | Account, sessions, API keys | Contract (b) |
| Meter usage, apply quotas and spend caps, invoice | Usage events, billing details | Contract (b) |
| Support and service notices | Account, support messages | Contract (b) |
| Security: abuse detection, rate limiting, incident investigation, backups | Logs, sessions, usage events | Legitimate interests (f) |
| Aggregate product analysis (counts and totals, not profiles) | Usage events | Legitimate interests (f) |
| Responding to abuse reports and takedown notices | Artifact and account records, the report itself | Legitimate interests (f), Legal obligation (c) |
| Tax, accounting and statutory record-keeping | Invoices and billing records | Legal obligation (c) |
| Product email to people who asked for it | Email address | Consent (a) — withdrawable at any time |
Where we rely on legitimate interests, we have weighed them against your rights and freedoms and will share that assessment on request.
6. How long we keep it
| Data | Retention |
|---|---|
| Free-tier artifacts | Link expires 48 hours after upload; the file sits in cold storage for 30 days more so a claimed workspace can recover it, then is deleted |
| Artifacts in a paid workspace | Until you delete them or the workspace closes. After cancellation, links stay live 60 days, then return 410 Gone and the files are deleted |
| Expiry tombstones (filename, upload time, size) | Retained after the file is gone, so an old thread says what used to be there instead of 404-ing |
| Account, workspace and membership records | Life of the account, then 30 days, then deleted |
| Revoked or expired API keys | 90 days, as an audit trail of what was used when |
| Dashboard sessions | Deleted on sign-out, or 30 days after last use |
| Usage events | 24 months, so a disputed invoice can still be checked |
| Server and edge logs | 30 days, except entries pulled into a security incident |
| Encrypted backups | 35 days on a rolling window — a deletion reaches backups as they age out, not instantly |
| Invoices and accounting records | 10 years, as Lithuanian accounting law requires |
| Support correspondence | 24 months after the thread is closed |
7. Who we share it with
We use a small number of processors to run the Service. Each one is under a written contract that limits it to acting on our instructions:
- Cloudflare, Inc. — website and API hosting, CDN, DDoS protection and edge logs (EU and global edge).
- Object storage and database hosting — where artifacts and account records live, in EU regions.
- Payment processing — takes your card details directly and returns us an invoice record. We never see the card number.
- Transactional email — password resets, receipts and service notices.
- Error and performance monitoring — stack traces and request diagnostics, which can incidentally include an IP address or a URL.
The current named list, with each processor's role and location, is available from [email protected] and we will tell you before adding one that materially changes where your data is held.
We also disclose personal data:
- to a court, regulator or law-enforcement body where we are legally required to, having checked that the request is valid and no broader than it has to be;
- to the sender of a valid abuse or copyright notice, to the extent needed to resolve it;
- to our professional advisers, and to an acquirer if the business is sold or merged — in which case we will tell you before your data moves and this policy continues to apply until it is replaced by one no less protective.
8. Where it is processed
Artifacts and account records are stored in the European Union. Some processors are US-based or serve traffic from a global edge network, so limited data — chiefly logs, diagnostics and cached responses — is processed outside the EEA. For those transfers we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one covers the recipient, and on encryption in transit and at rest. A copy of the safeguards for any given transfer is available on request.
9. Cookies and local storage
We run no advertising, analytics or cross-site tracking cookies, so there is no consent banner to click through. What we do set:
- Session cookie (app.krowk.com only) — keeps you signed in. Strictly necessary; there is no dashboard without it.
- CSRF token — protects dashboard forms against cross-site request forgery. Strictly necessary.
themein localStorage — remembers whether you chose light or dark. It never leaves your browser. Clearing site data resets it.
Public artifact pages and this website set no cookies at all. Our CDN may keep short-lived edge logs, described in section 3.3.
10. Security
Everything is served over TLS, artifacts are encrypted at rest, passwords are hashed with a slow algorithm, and API keys are stored only as digests. Uploads go straight from your client to object storage through a presigned URL that is scoped to one object and expires in minutes — the bytes never pass through our application servers. Access to production is limited to the people who need it, requires multi-factor authentication, and is logged. We keep encrypted, restore-tested backups.
No system is perfectly secure. If a breach is likely to result in a risk to your rights and freedoms, we will notify the Lithuanian State Data Protection Inspectorate within 72 hours of becoming aware of it and tell affected users without undue delay, with what happened, what data was involved, and what to do about it. To report a vulnerability, write to [email protected]; we will not pursue good-faith research that respects other people's data.
11. Automated decision-making
Quotas, rate limits and spend caps are applied automatically, and hitting one can suspend uploads on a key or a workspace. These are threshold rules on counters, not profiling, and they have no legal effect on you beyond pausing the Service — but if one trips wrongly, email us and a person will look at it. We do not otherwise make decisions about you by automated means, and we do not profile you.
12. Your rights
Under the GDPR you can ask us to give you a copy of your personal data (access) or a portable machine-readable export; correct it if it is wrong (rectification); delete it (erasure); pause our use of it (restriction); stop processing based on legitimate interests (objection); and withdraw any consent you have given, at any time, without affecting what was lawful before you withdrew it.
Write to [email protected]. We answer within one month and may extend that by two months for a complex request, telling you why. It is free unless a request is manifestly unfounded or excessive. We may ask for enough information to confirm who you are — so that we do not hand your data to someone else.
Two limits worth stating plainly. If the data is inside an artifact uploaded by a customer's workspace, we are the processor and will refer you to that customer, or act on their instruction. And a deletion reaches live systems immediately but rolls out of encrypted backups as they age out, within 35 days.
13. Children
The Service is for developers and is not directed at children. You must be at least 16 to use it. We do not knowingly collect personal data from children under 16; if we learn that we have, we delete it. Tell us at [email protected] if you believe a child has given us data.
14. Complaints
If we have not resolved something, you can complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, Vilnius, LT-10312 — vdai.lrv.lt — or to the supervisory authority where you live or work. The full list is at edpb.europa.eu. We would rather hear from you first.
15. Changes to this policy
We update this policy when the Service changes. The date at the top always says when. For a change that materially affects your rights or how we use your data, we will email account holders at least 30 days before it takes effect, and where the change needs your consent, we will ask for it rather than assume it.
16. Contact
UAB Primevise
Lentvario 18
Vilnius, LT-02300
Lithuania
Privacy: [email protected]
Security: [email protected]
Everything else: [email protected]