Privacy Policy
Effective Date: August 2026 • GDPR & CCPA Compliant
Your privacy and intellectual property are foundational to KAWDING. This policy details how we isolate your developer secrets, encrypt project records with PostgreSQL Row Level Security, and guarantee zero cross-site advertising trackers.
API keys, database passwords, and Hostinger FTP secrets are encrypted with Supabase RLS and never logged to plain-text server files.
Cloud storage enforces strict PostgreSQL Row Level Security locked exclusively to your authenticated user identity.
We never sell user data, utilize third-party ad networks, or run cross-site behavioral tracking cookies.
1Information We Collect & Why
We believe in strict data minimization. We collect only the data required to authenticate and deliver your in-browser development environment: (a) Account Identifiers: your registered email address and authenticated user ID via Supabase Auth; (b) Workspace Artifacts: project files, code tabs, and AI chat turns saved directly to your cloud PostgreSQL record; and (c) Ephemeral Telemetry: standard server request headers for rate limiting and bot defense.
2How AI Prompts & Project Context Are Handled
When requesting code generation or assistance, your instructions and relevant code snippets are securely transmitted over HTTPS to your active AI provider (e.g., Google Gemini, DeepSeek, Xiaomi MiMo, OpenAI, or OpenRouter). KAWDING does not retain or train proprietary base AI foundation models on your private intellectual property.
3Database Credentials & Remote MySQL Protection
When connecting to Hostinger Remote MySQL (such as srv361.hstgr.io or srv1191.hstgr.io) or cPanel databases, your connection parameters are handled over encrypted channels. Credentials stored in project settings are isolated per user. You maintain complete control to test, alter, or remove database parameters at any moment.
4100% Cloud Architecture & Zero Browser Leakage
KAWDING is engineered with a pure Direct-to-Supabase Cloud architecture. Project state, file edits, and snapshots are persisted into secure PostgreSQL tables (builder_user_projects, builder_user_settings) protected by Row Level Security policies. When you log out, active session tokens are invalidated.
6Your Privacy Rights (GDPR, CCPA & Global Laws)
Regardless of your geographic location, you retain full rights over your data: (a) Right to Access: inspect all projects and account settings at any time; (b) Right to Portability: download all workspace code as clean standard ZIP archives with zero proprietary lock-in; (c) Right to Erasure: permanently delete projects and account records with one click; and (d) Right to Rectification: update billing and profile preferences instantly.
7Data Retention & Deletion
Active workspace projects are preserved in your cloud database until you explicitly choose to delete them. When a project is removed from the Projects manager, its records, source code, and associated action logs are permanently purged from PostgreSQL.
8Security Infrastructure & Encryption
All data in transit is encrypted using modern TLS 1.3 cryptographic protocols. Live queries utilize parameterized PDO statements to prevent SQL injection vulnerabilities, and password authentications use industry-standard Bcrypt hashing.
9Contact the Data Protection Team
If you have questions, feedback, or requests regarding this Privacy Policy or your personal developer information, contact our privacy officers at support@lushai.dev.
Need data erasure or privacy details?
Contact our Data Protection Officer for account erasure requests or enterprise security reviews.