Legal

Privacy policy

Draft · text last changed 2026-09-23
Draft — not yet in forceThis text has been prepared but not yet reviewed and adopted. It is published so the shape of our terms is visible, not as a binding agreement. Until it is adopted, nothing on this page creates obligations for you or for mkdir beyond what applicable law provides. Questions: support@mkdirhq.com.

1. What this covers

This policy covers the personal data mkdir processes when you use Kriyo, as the operator of the service. For the leads and contacts inside your workspace, you decide why they are processed and we process them on your behalf; a data processing agreement for that relationship is not yet published, and this page will link to it when it is.

2. What we collect about you

  • At sign-up: your email address, a hash of your password (never the password), your company name, and the IP address the sign-up came from, which is kept to limit abuse of sign-up.
  • The workspace you create and everything you put in it: leads, mailboxes and their credentials, messages, files, knowledge base, settings.
  • An activity log of actions taken in the workspace: what was done, by whom, when.
  • A verification token sent to your email, which expires.
  • Session data needed to keep you signed in.

3. What we use it for

  • To run the service: send the messages you approve, sync replies, check DNS and warm-up, compute the figures on your screens.
  • To draft replies. The content of an inbound reply and the relevant parts of your knowledge base are sent to a model provider to produce a draft. The draft is not sent to anyone until a person in your workspace approves it.
  • To verify your email, throttle abusive sign-ups and keep the account secure.
  • To bill you, once a plan is agreed. Payment card details are handled by a payment processor and never stored by us.

4. Where it is kept

Each workspace’s data is held in a separate database. Account records (your login, the plan catalogue, billing state) are held in a shared administrative database. The region in which data is hosted will be stated here before this policy is adopted.

Secrets you store (mailbox passwords, integration keys) are write-only once saved: they can be replaced but not read back through the interface, except that a workspace owner may read the credentials of mailboxes provisioned for that workspace.

5. Who else sees it

We share data with providers only as needed to run the service, by role:

  • Mail infrastructure providers, to provision domains and mailboxes you order and to deliver the messages you approve.
  • Data providers, when you search for or reveal a contact.
  • A model provider, to draft replies as described above.
  • A payment processor, when billing is enabled.
  • Hosting providers for the application and its databases.

A list of these providers by name will be published here before this policy is adopted. We do not sell personal data.

6. How long

Workspace data is kept while the workspace exists. When a workspace is closed, its database is deleted after a retention period that will be stated here before this policy is adopted. Sign-up throttle records are short-lived. The activity log is kept with the workspace.

7. Your rights

You can export your leads and results from the workspace, correct your account details, and ask us to delete your workspace. Where the law gives you rights of access, rectification, erasure, restriction, portability or objection, you can exercise them by writing to the address on the contact page. We will say honestly what we can and cannot do and how long it will take.

8. Cookies

The application uses cookies needed to keep you signed in and to protect forms against cross-site requests. Your theme choice is stored in your browser. There are no advertising or cross-site tracking cookies on this site.

9. Changes

The date at the top changes when this policy does. Material changes will be notified in the workspace. The controller’s legal identity and contact address will be stated here before this policy is adopted.