---
title: "Privacy Policy — Krowk"
canonical_url: "https://krowk.com/privacy-policy"
last_updated: "2026-10-01T21:54:32.045Z"
meta:
  description: "How UAB Primevise collects, uses and protects personal data when you use Krowk, including what an artifact link exposes and how long anything is kept."
  "og:description": "How UAB Primevise collects, uses and protects personal data when you use Krowk, including what an artifact link exposes and how long anything is kept."
  "og:title": "Privacy Policy — Krowk"
---

**Legal**

# **Privacy Policy **

Last updated 29 September 2026. This policy covers krowk.com, app.krowk.com, api.krowk.com and the Krowk CLI, including its coding agent.

## 1. Who we are

Krowk is operated by **UAB Primevise**, a company registered in Lithuania, at Lentvario 18, Vilnius, LT-02300, Lithuania. In this policy “we”, “our” and “us” mean UAB Primevise, and “the Service” means the Krowk website, API, dashboard and CLI.

For everything we do with your own account and usage data, we are the **data controller**. For personal data that happens to be inside the files your agents upload, we are a **data processor** acting on your instructions — see section 4.

Privacy questions, requests and complaints: [privacy@krowk.com](mailto:privacy@krowk.com). We have not appointed a Data Protection Officer, because our processing does not meet the Article 37 GDPR threshold that requires one. Requests go to the address above and are handled by the people who run the Service.

## 2. Read this first: artifact links are public

An artifact page such as `krowk.com/a/art_00000000000000000000demo` is **readable by anyone who has the link, with no account and no password**. That is the entire point of the product — the link has to work when it is pasted into a pull request or a Slack thread. It also means:

- Anything visible in an uploaded screenshot, recording or log is visible to whoever receives the URL, and to anyone they forward it to.
- Links are unguessable but not secret. Once a URL leaves your control — a public pull request, an issue tracker, a browser extension, a crawler that follows links in a page — we cannot pull it back.
- We ask search engines not to index artifact pages with a `noindex` robots directive. That is a request honoured by well-behaved crawlers, not an access control.

Do not upload credentials, personal data you have no basis to share, or anything you would not paste into the channel you are about to paste the link into. Deleting an artifact removes it from our storage and makes the link return `410 Gone`, but it cannot un-see a copy someone already took.

## 3. Personal data we collect

### 3.1 Data you give us

- **Account**: email address and a hashed password. We never store your password itself.
- **Workspace**: workspace name and the roles of the people in it.
- **API keys**: the name you give a key and a hash of the key itself. We cannot recover a key once it is issued — only revoke it.
- **Support**: whatever you put in an email or bug report you send us.

### 3.2 Data your agents send us

- **Artifacts**: the file contents, plus its filename, media type, size and checksum.
- **Run metadata**: whatever the CLI or your CI attaches to a run — typically repository, branch, commit, task and run-log URLs, and the name of the agent. Commit and branch names routinely contain a person's name or email; that is personal data, and it is data you choose to send.

### 3.3 Data we collect automatically

- **Sessions**: for dashboard logins, the IP address and user-agent string of the browser that signed in, so you can spot a session you do not recognise.
- **Usage events**: uploads, bytes stored and which key was last used when — the counters your rate ceiling and invoice are built from.
- **Server and edge logs**: request time, path, response status, IP address and user-agent, kept short-term for security and debugging.
- **Website analytics**: which pages of this site get visited, where the visit came from, coarse browser and device details, and which buttons and links get used — for example that somebody copied the install command, which is how we tell whether the page explains the product. A cookie carries a random identifier so that the same browser coming back next week counts as one person rather than two visits, and the referring site or campaign link that first brought you here is kept against that identifier, so we can tell which of them are worth continuing. Only with your consent — section 9 explains the cookie and how to change your mind.
- **Session replay**: a reconstruction of a visit to this site — pointer movement, clicks, scrolling and the pages as they were laid out — so we can see where the product is being explained badly. Typed input is masked before it leaves your browser, and on an artifact page the artifact itself is masked too: the uploaded text is blanked and the picture or video is replaced with a grey placeholder, so a replay never carries somebody's file. Part of the same consent as analytics, and off entirely if you decline.

### 3.4 The agent, on your machine

The coding agent in the Krowk CLI runs on your machine and does not send us your prompts, your code or its sessions. It sends them to the model providers you connect it to — Anthropic, OpenAI, xAI, OpenRouter or another you configure — under your own account or key, and those providers are responsible for that data under their own policies; we are neither its controller nor its processor. When the agent drives Claude Code or Codex, those tools run as their vendors built them, under their vendors' policies. Your sessions, provider sign-ins and stored keys are kept in files on your machine, in the directory the CLI keeps (`~/.krowk` by default), and never leave it through us. We receive only what you choose to publish, which is covered by sections 2 and 3.2. The CLI has no telemetry; besides the providers you connect, it contacts GitHub to check for updates and models.dev to refresh model prices.

### 3.5 What we do not collect

We do not ask for your name, job title, photograph or phone number. We do not store card numbers — payments are handled by our payment processor and we only ever see the billing details it passes back to us. We do not buy personal data from data brokers, we do not sell or rent personal data to anyone, and we do not run advertising or cross-site tracking on the Service.

## 4. When we are a processor, not a controller

The contents of your artifacts are yours. Where they contain personal data — a customer's name in a screenshot of an orders dashboard, say — you are the controller and we process it only to store it, serve it at its link, generate previews and thumbnails, and delete it when it expires or you ask us to. We do not read your artifacts for any other purpose, and we do not use them to train machine-learning models.

If you need a Data Processing Agreement with Standard Contractual Clauses, we will sign one — write to [privacy@krowk.com](mailto:privacy@krowk.com). Until it is signed, the processor terms in our [Terms of Service](https://krowk.com/terms-of-service) apply.

## 5. Why we process it, and on what legal basis

| Purpose | Data | Legal basis (Art. 6 GDPR) |
| --- | --- | --- |
| Run the Service: store artifacts, serve links, unfurl them | Artifacts, run metadata, account | Contract (b) |
| Authenticate you and keep sessions and keys working | Account, sessions, API keys | Contract (b) |
| Meter usage, apply rate ceilings, invoice | Usage events, billing details | Contract (b) |
| Support and service notices | Account, support messages | Contract (b) |
| Security: abuse detection, rate limiting, incident investigation, backups | Logs, sessions, usage events | Legitimate interests (f) |
| Aggregate product analysis (counts and totals, not profiles) | Usage events | Legitimate interests (f) |
| Understanding how the website is used, so we can improve it | Website analytics, session replay | Consent (a) — withdrawable at any time |
| Responding to abuse reports and takedown notices | Artifact and account records, the report itself | Legitimate interests (f), Legal obligation (c) |
| Tax, accounting and statutory record-keeping | Invoices and billing records | Legal obligation (c) |
| Product email to people who asked for it | Email address | Consent (a) — withdrawable at any time |

Where we rely on legitimate interests, we have weighed them against your rights and freedoms and will share that assessment on request.

## 6. How long we keep it

| Data | Retention |
| --- | --- |
| Free-tier artifacts | Link expires 24 hours after upload; the file sits in cold storage for 30 days more so a claimed workspace can recover it, then is deleted |
| Artifacts in a paid workspace | Until you delete them or the workspace closes. After cancellation, links stay live 60 days, then return `410 Gone` and the files are deleted |
| Expiry tombstones (filename, upload time, size) | Retained after the file is gone, so an old thread says what used to be there instead of 404-ing |
| Account, workspace and membership records | Life of the account, then 30 days, then deleted |
| Revoked or expired API keys | 90 days, as an audit trail of what was used when |
| Dashboard sessions | Deleted on sign-out, or 30 days after last use |
| Usage events | 24 months, so a disputed invoice can still be checked |
| Server and edge logs | 30 days, except entries pulled into a security incident |
| Website analytics | 12 months, then deleted. The identifier in it is a random number from a cookie, tied to no name or account |
| Session replay | 30 days, then deleted |
| Encrypted backups | 35 days on a rolling window — a deletion reaches backups as they age out, not instantly |
| Invoices and accounting records | 10 years, as Lithuanian accounting law requires |
| Support correspondence | 24 months after the thread is closed |

## 7. Who we share it with

We use a small number of processors to run the Service. Each one is under a written contract that limits it to acting on our instructions:

- **Cloudflare, Inc.** — website and API hosting, CDN, DDoS protection and edge logs (EU and global edge).
- **Object storage and database hosting** — where artifacts and account records live, in EU regions.
- **Payment processing** — takes your card details directly and returns us an invoice record. We never see the card number.
- **Transactional email** — password resets, receipts and service notices.
- **Error and performance monitoring** — stack traces and request diagnostics, which can incidentally include an IP address or a URL.
- **PostHog** — website analytics and session replay, on their EU-hosted service.

The current named list, with each processor's role and location, is available from [privacy@krowk.com](mailto:privacy@krowk.com) and we will tell you before adding one that materially changes where your data is held.

We also disclose personal data:

- to a court, regulator or law-enforcement body where we are legally required to, having checked that the request is valid and no broader than it has to be;
- to the sender of a valid abuse or copyright notice, to the extent needed to resolve it;
- to our professional advisers, and to an acquirer if the business is sold or merged — in which case we will tell you before your data moves and this policy continues to apply until it is replaced by one no less protective.

## 8. Where it is processed

Artifacts and account records are stored in the European Union. Some processors are US-based or serve traffic from a global edge network, so limited data — chiefly logs, diagnostics and cached responses — is processed outside the EEA. For those transfers we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one covers the recipient, and on encryption in transit and at rest. A copy of the safeguards for any given transfer is available on request.

## 9. Cookies and local storage

We run no advertising cookies and no cross-site tracking. One analytics cookie is set, and only if you agree to it — that is what the banner on your first visit is asking. What we set:

- **`krowk_consent`** — records whether you accepted or declined analytics, so we stop asking. Strictly necessary; it is the only way to honour a "no". Kept for a year, scoped to krowk.com and its subdomains so a choice made here also applies on app.krowk.com.
- **PostHog analytics cookie** ( `ph_…_posthog`) — a random identifier, so that a second visit from the same browser counts as the same person rather than a new one. Set only after you accept. It holds no name, no email and no account, and it is never read by anyone but us. Kept for a year.
- **Session cookie** (app.krowk.com only) — keeps you signed in. Strictly necessary; there is no dashboard without it.
- **CSRF token** — protects dashboard forms against cross-site request forgery. Strictly necessary.
- **`theme` in localStorage** — remembers whether you chose light or dark. It never leaves your browser. Clearing site data resets it.

Nothing is loaded from a third-party analytics domain: the events go to a path on this site, which passes them to PostHog's EU service. If you decline, no analytics cookie is written, no session replay is recorded, and nothing further is sent — we do not fall back to counting you another way. To change your mind later, clear this site's cookies and the banner will ask again. Our CDN may also keep short-lived edge logs, described in section 3.3; those are not cookies and do not depend on your choice.

Declining costs you nothing. Every part of the site, and every artifact link, works exactly the same either way.

## 10. Security

Everything is served over TLS, artifacts are encrypted at rest, passwords are hashed with a slow algorithm, and API keys are stored only as digests. Uploads go straight from your client to object storage through a presigned URL that is scoped to one object and expires in minutes — the bytes never pass through our application servers. Access to production is limited to the people who need it, requires multi-factor authentication, and is logged. We keep encrypted, restore-tested backups.

No system is perfectly secure. If a breach is likely to result in a risk to your rights and freedoms, we will notify the Lithuanian State Data Protection Inspectorate within 72 hours of becoming aware of it and tell affected users without undue delay, with what happened, what data was involved, and what to do about it. To report a vulnerability, write to [security@krowk.com](mailto:security@krowk.com); we will not pursue good-faith research that respects other people's data.

## 11. Automated decision-making

Rate ceilings are applied automatically, and hitting one pauses uploads on a key or an address for a stated number of seconds. These are threshold rules on counters, not profiling, and they have no legal effect on you beyond pausing the Service — but if one trips wrongly, email us and a person will look at it. We do not otherwise make decisions about you by automated means, and we do not profile you.

## 12. Your rights

Under the GDPR you can ask us to give you a copy of your personal data (access) or a portable machine-readable export; correct it if it is wrong (rectification); delete it (erasure); pause our use of it (restriction); stop processing based on legitimate interests (objection); and withdraw any consent you have given, at any time, without affecting what was lawful before you withdrew it.

Write to [privacy@krowk.com](mailto:privacy@krowk.com). We answer within one month and may extend that by two months for a complex request, telling you why. It is free unless a request is manifestly unfounded or excessive. We may ask for enough information to confirm who you are — so that we do not hand your data to someone else.

Two limits worth stating plainly. If the data is inside an artifact uploaded by a customer's workspace, we are the processor and will refer you to that customer, or act on their instruction. And a deletion reaches live systems immediately but rolls out of encrypted backups as they age out, within 35 days.

## 13. Children

The Service is for developers and is not directed at children. You must be at least 16 to use it. We do not knowingly collect personal data from children under 16; if we learn that we have, we delete it. Tell us at [privacy@krowk.com](mailto:privacy@krowk.com) if you believe a child has given us data.

## 14. Complaints

If we have not resolved something, you can complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, Vilnius, LT-10312 — [vdai.lrv.lt](https://vdai.lrv.lt) — or to the supervisory authority where you live or work. The full list is at [edpb.europa.eu](https://edpb.europa.eu/about-edpb/about-edpb/members_en). We would rather hear from you first.

## 15. Changes to this policy

We update this policy when the Service changes. The date at the top always says when. For a change that materially affects your rights or how we use your data, we will email account holders at least 30 days before it takes effect, and where the change needs your consent, we will ask for it rather than assume it.

## 16. Contact

UAB Primevise  
 Lentvario 18  
 Vilnius, LT-02300  
 Lithuania

Privacy: [privacy@krowk.com](mailto:privacy@krowk.com)  
 Security: [security@krowk.com](mailto:security@krowk.com)  
 Everything else: [support@krowk.com](mailto:support@krowk.com)