KilnCat does not sell personal information or use it for cross-context behavioral advertising. We use information to provide and secure the studio, process subscriptions, support collaboration, and understand and improve product use. PostHog may process account identifiers, product usage, feedback, diagnostic, operational, replay, and support information for us in the United States, including account email and public handle. PostHog and third-party LLM providers may assist with product analysis, development, and support as described below.
1. Scope and who we are
This Privacy Policy applies to KilnCat websites, accounts, software, creative tools, browser studio, cloud documents, collaboration and multiplayer features, generation and rendering systems, public galleries, APIs, hosted Model Context Protocol (“MCP”) tools, and any related products, features, or support we make available (collectively, the “Service”). Dustin Byrne, doing business as KilnCat in Massachusetts, United States, is responsible for the practices described here.
This Policy does not govern third-party websites, applications, MCP clients, or services that you choose to connect. Their privacy policies apply to their own collection and use. Our Terms of Service govern use of the Service.
2. Information we collect
Account and profile information
We collect your email address, public handle, name and profile image if supplied, account identifiers, authentication and verification status, and account timestamps. Credential signup initially creates a default profile name from the part of your email address before “@.” If you sign in with Google, we receive information Google makes available according to your authorization, such as your email address, name, profile identifier, and sign-in tokens. Passwords are handled through our authentication system and stored only in hashed form; we do not store readable passwords.
Documents, creative content, and collaboration
If you use cloud features, we process document names, graphs, parameters, materials, textures, meshes, geometry, generated assets, revisions, sharing permissions, collaborator activity, room updates, renders, preview images, exports, and related metadata. Private content is stored so we can save, synchronize, recover, share, generate, and render it as you direct. Free or unsaved work may remain only in the current browser tab unless you export it or choose cloud storage.
Public gallery information
When you publish, we store and display the “Published Snapshot” identified in the publication flow. We separately process listing and social metadata such as your public handle, artist notes, publication and revision dates, license records, visibility, and upvote counts, including which signed-in accounts upvote a publication. Only the Published Snapshot is dedicated under CC0; account, identity, listing, operational, and social metadata is not included.
Billing and subscription information
We receive billing and entitlement details from Polar, such as customer and subscription identifiers, product, status, billing period, email, your supplied or default profile name, and transaction or webhook metadata. Polar processes payment-card and other payment credentials; KilnCat does not receive your full card number or security code.
Service, device, and network information
We and our providers collect information generated when you use the Service, including IP address, request time, browser and device type, operating system, referring page, pages and features used, feature-flag assignments and experiment exposures, survey interactions, error and security events, approximate location inferred from IP address, language, screen and viewport size, and cookie or device identifiers. Error reports and server logs may also contain exception messages, stack traces, source locations, release details, service name, severity, request route, timing, trace or session identifiers, and configured log attributes.
MCP, OAuth, and automation information
When you connect an MCP or OAuth client, we process client details, requested and granted scopes, consent, token identifiers, expiry, document handles, request metadata, operations, idempotency or replay-protection records, and resulting status or output. We use this information to authenticate the client, enforce permissions and limits, execute your request, prevent duplicate mutations, and investigate misuse. A third-party client may separately collect prompts, credentials, commands, or results under its own privacy policy.
Feedback, communications, support, and AI assistance
If you contact us, request account recovery, or open a support ticket, we collect your message, email address, name and public handle if available, attachments, ticket status, and related correspondence. A support request may also include the page URL, browser and device details, errors, and diagnostics you choose to provide. Our transactional email provider, Resend, processes recipient addresses and message contents to deliver verification, recovery, security, and service notices. Email sent to our contact address may be converted into a support ticket in PostHog Support.
If you answer a survey or submit product feedback, we collect your response and relevant product context. These responses are voluntary. PostHog may associate a response or support ticket with relevant account, operational, or product context where the applicable choice permits it. Rejecting persistent analytics does not prevent cookieless feedback or support.
We may use PostHog AI or another third-party LLM provider to analyze these records and to help investigate issues, answer support requests, or develop KilnCat. Relevant messages, attachments, and technical context may be submitted to those providers. Their applicable product terms, account settings, and privacy practices govern retention and whether submitted information may be used to improve their services or models. Do not include passwords, access tokens, payment details, or sensitive personal information in surveys or support requests.
Sources
We collect information directly from you, automatically from your browser or device, from collaborators and third-party clients acting under granted permissions, and from providers such as Google and Polar.
3. PostHog and related product tools
We use PostHog, Inc. for product analytics and improvement, feature delivery and testing, diagnostics and reliability, feedback and research, customer support, and related data and AI tools. Depending on our configuration, these functions may use analytics, heatmaps, feature flags, experiments, surveys, error tracking, logs, profiles, data warehouse or pipeline tools, AI-assisted analysis, session replay, and Support. We may enable, disable, or replace individual tools as the Service evolves. If that materially changes the categories of information, purposes, recipient categories, or legally required choices described here, we will update this Policy and obtain a new choice where required. Our PostHog project uses United States hosting.
Information and product uses
PostHog may receive and combine:
- account and contact identifiers, including email address, public handle, account identifier, and device or session identifiers;
- technical and network information, such as IP address, approximate location, browser, device, operating system, language, URL or page path, referrer, and screen dimensions;
- usage and interaction information, including pages, clicks, navigation, editor, render or export events, timings, feature use, flag or experiment assignments, survey interactions and responses, and account or subscription state;
- diagnostic information, including errors, exceptions, stack traces, release and service information, logs, routes, traces, messages, and configured attributes; and
- support, feedback, profile, operational, and business records that we choose to connect for the purposes described above, together with insights, segments, cohorts, and other information derived from those records.
We may use email address and public handle to associate activity with an account, provide support, and understand use across sessions. We do not use PostHog for advertising profiles or cross-context behavioral advertising.
Session replay
If enabled and separately allowed through Privacy choices, session replay can capture page content rendered in your browser, DOM changes, clicks, pointer movement, scrolling, navigation, timestamps, and screen or viewport dimensions. KilnCat configures replay to mask inputs and block canvas elements, including the graph and texture canvases. Other visible interface text and interactions may still be captured, and masking may not remove every value. Do not place passwords, payment details, access tokens, share secrets, or sensitive personal information in document names, node labels, feedback, surveys, support messages, or other free-form fields.
AI and LLM provider use
PostHog AI, its subprocessors, and other third-party LLM providers may process relevant analytics, prompts or responses, survey feedback, errors, logs, warehouse results, support messages, attachments, and technical context to help us operate, analyze, troubleshoot, support, secure, and develop KilnCat. This can include a bug description or technical excerpt supplied by a user. We decide what context to submit, but the provider processes submitted information under its applicable product terms, account settings, and privacy practices, which may permit retention or use to improve its services or models.
PostHog’s role
PostHog processes the information described above for us under its data-processing terms and may use infrastructure and AI subprocessors. Learn more in PostHog’s Privacy Policy, Data Processing Agreement, and subprocessor list.
4. Cookies and browser storage
KilnCat uses essential cookies and browser storage to keep the Service working and remember your privacy choice. Persistent storage used for PostHog analytics and replay is nonessential and is not created or accessed until you consent. If you reject it, PostHog instead receives the limited cookieless events described below, without setting or reading a PostHog analytics cookie, local storage identifier, or replay session. Although a consented PostHog cookie is normally written on the KilnCat domain, the associated information is sent to PostHog as our service provider. Browser settings may let you clear or block these technologies, but blocking essential storage can prevent sign-in, recovery, support, or editor features from working.
| Category | Purpose and examples | Typical duration |
|---|---|---|
| Essential authentication | Secure session cookies and OAuth state used to sign you in, prevent forgery, and maintain account security. | Session or the configured account-session period. |
| Studio and recovery storage | Local or session storage for editor layout, document pointers, recovery copies, template handoff, and preferences. | Session only or until replaced, cleared, or no longer needed. |
| Privacy choice | Essential local storage records the policy version, purpose-level choices, decision time, and choice source so we can honor and demonstrate your choice. | Up to six months, then we ask again; sooner if purposes change. |
| Cookieless PostHog measurement | Before you choose and after you reject persistent analytics, PostHog receives pageviews and limited product usage events, plus feedback you deliberately submit. It uses server-side privacy-preserving hash mode and does not use a PostHog browser identifier or session replay. After a choice, the essential KilnCat decision record remains in local storage. | No PostHog analytics browser storage; each request is processed when sent. |
| Optional persistent PostHog analytics and replay |
After consent, a ph_…_posthog cookie and local storage may hold
distinct, device, and session identifiers and configured properties. Named
analytics and separately allowed replay use this consented context.
|
Up to six months unless cleared, withdrawn, or refreshed sooner. |
| PostHog Support | When you request support, local storage may remember the widget session, ticket, widget state, name, and email needed to continue the conversation. | Until cleared or no longer needed for the support conversation. |
We do not use advertising cookies. Other providers may use essential cookies on their own domains when you visit Google sign-in, Polar checkout, or a connected third-party service. Support storage used to answer a ticket is separate from optional analytics consent and is created only when you request support.
5. How we use information
We use information to:
- provide, generate, render, save, synchronize, share, export, and support the Service;
- create and secure accounts and deliver verification or recovery messages;
- process subscriptions, maintain entitlements, and prevent billing fraud;
- enable collaboration, public links, publication, gallery voting, and MCP or API access according to your instructions;
- understand feature use, operate flags and experiments, collect voluntary feedback, replay and troubleshoot sessions, fix errors, analyze logs and business data, and improve usability and performance;
- detect abuse, enforce limits and permissions, protect users, and maintain the integrity and availability of the Service;
- respond to support, privacy, legal, and rights requests, including summarizing, classifying, and drafting support responses;
- comply with law, resolve disputes, and enforce our agreements; and
- send service communications and, only where permitted, product communications you can opt out of.
KilnCat does not currently train its own models on private content. Private content may be processed by third-party LLM providers for the operational, support, and development purposes described above, and those providers may handle it under their own terms and settings. Limited cookieless pageviews and named product events run before a choice and after rejection unless GPC or DNT blocks PostHog. Persistent analytics and session replay run only while the corresponding Privacy choice is active. Voluntary survey responses and support needed to answer your request are processed to respond to your action, perform our agreement with you, or for our legitimate interest in improving the Service and support. Server-side logs, security records, and necessary business-data connections are processed to operate and secure the Service. Depending on where you live, other legal bases may include legitimate interests and compliance with legal obligations.
6. How we disclose information
We disclose information only as described below:
- Service providers. Providers support hosting, networking, databases, object storage, rendering, authentication, email delivery, analytics, feature delivery and experiments, surveys, error tracking, logs, business-data analysis, session replay, customer support, security, and other operations. PostHog processes the product, reliability, feedback, warehouse, replay, and support information described above. PostHog's LLM subprocessors or another third-party LLM provider may receive records needed for the AI-assisted tasks described above. Their handling, retention, and possible model-improvement use depend on the applicable product terms and account settings disclosed above.
- Payments. Polar receives checkout, customer, payment, tax, and subscription information to process purchases and provide its customer portal.
- Connected services. Google and third-party OAuth or MCP clients receive information when you choose to connect them or authorize access.
- Other users and the public. Collaborators, share-link recipients, and gallery visitors receive information according to the permissions and publication choices you make.
- Legal and safety. We may disclose information when reasonably necessary to comply with law or legal process, protect rights and safety, investigate fraud or abuse, or enforce agreements.
- Business transfers. Information may be disclosed during a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the Service, subject to appropriate confidentiality protections where practicable.
- At your direction. We disclose information when you ask us to or provide consent.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising and do not use targeted advertising networks.
7. Public and shared content
The Published Snapshot defined in our Terms is public and dedicated under CC0, which is intended to be irrevocable; a privacy deletion cannot withdraw that dedication or retrieve copies controlled by others. Your public handle and associated listing, revision, license, visibility, and upvote metadata may also be public and indexed, but are not part of the CC0 dedication.
Private share links and collaboration invitations expose content to recipients you choose. A person may forward a bearer-style share link. Revoke links and access you no longer want active. Do not publish or share personal information or confidential material unless you have the right and intention to disclose it.
8. Retention
We retain information for as long as reasonably necessary for the purposes described above, including to provide the Service, maintain security and backups, resolve disputes, enforce agreements, and meet legal obligations. Retention varies by category:
- Account profiles and private cloud documents are generally kept while your account is active. We process verified closure and privacy requests within the periods required by applicable law. We remove, restrict, or deidentify account data that is not still needed for billing, fraud prevention, dispute resolution, security, publication integrity, or legal compliance.
- Deleting a document removes it from the active workspace but does not immediately erase its database record, revision history, collaboration updates, or recovery copies. Those records may be restricted while deletion is processed, and residual copies may remain in backups until overwritten under our backup cycle unless a legal or security hold applies.
- Account closure automatically unpublishes public listings. Records needed to preserve publication integrity, CC0 history, moderation, or legal compliance may remain, and copies held by others are outside our control.
- Billing, transaction, tax, entitlement, and fraud-prevention records are retained for applicable legal, accounting, and dispute periods.
- PostHog analytics, profiles, experiments, feedback, diagnostics, warehouse data, logs, and replay are retained according to our account configuration and for as long as reasonably needed to understand product use, test and improve features, investigate problems, provide support, and operate the Service. High-volume records such as replay and logs may use shorter periods than account, event, or support records.
- Support messages, attachments, and AI-assisted work may be retained while needed to respond, investigate recurring issues, improve the Service, maintain business records, or address security, legal, or dispute matters. Copies submitted to a third-party LLM provider are also subject to that provider's terms and account settings.
- OAuth tokens expire according to their stated lifetime. Revoked and expired-token records, request logs, and security records are kept only as long as reasonably needed for their operational or legal purpose.
When deletion is due, information may remain temporarily in restricted backups or with providers according to their retention systems. We may retain information where needed for legal, security, fraud-prevention, accounting, publication-integrity, or dispute purposes, and may retain deidentified or aggregated information that cannot reasonably be linked to you.
9. Your choices and tracking signals
Account and content controls
You can update available account details, change sharing permissions, revoke public links, unpublish gallery listings, and cancel subscriptions through available controls. Hosted MCP access expires after one hour and cannot refresh in the background. To request earlier client revocation or account deletion, contact us by email. Unpublishing does not revoke the CC0 dedication.
Analytics, client diagnostics, and session replay
KilnCat counts pageviews and named product events without analytics cookies before you choose. The first banner offers equally direct Accept all, Reject all, and Customize controls. These events cover general feature use and feedback you deliberately submit. Reject all continues these events in PostHog cookieless mode without a PostHog browser identifier or replay. Accepting persistent analytics permits PostHog cookies or local storage and lets us associate signed-in activity with an internal account identifier. Session replay remains a separate choice. We limit automatic collection to the product usage needed for the purposes described in this Policy. We store the policy version, choices, decision time, and choice source for up to six months, then ask again. A material purpose change also requires a new choice.
You can reopen Privacy choices from public-page footers and the studio status bar; other product surfaces link to this page. Withdrawal tells the attached PostHog client to leave persistent capture, stops replay, removes known PostHog analytics browser persistence, and continues only the disclosed cookieless events. It applies prospectively and does not make earlier lawful processing unlawful. Email [email protected] with a privacy request concerning PostHog data already stored on our behalf.
When a recognized Global Privacy Control (GPC) or browser Do Not Track (DNT) signal is present, PostHog does not start, including cookieless events, even if an earlier browser choice allowed it. Blocking PostHog scripts has the same practical effect. Essential authentication, server logging, security, consent, support, and document-storage activity remains available when persistent analytics is rejected.
You cannot opt out of transactional messages necessary for account security, billing, collaboration, or material Service changes. Any marketing email will include an unsubscribe method where required.
10. Privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to access, know about, correct, delete, or receive a portable copy of personal information; restrict or object to certain processing; withdraw consent; opt out of sale, sharing, or targeted advertising; and appeal a denied request. KilnCat does not sell personal information or use it for targeted advertising.
To make a request, email [email protected] from the address associated with your account and describe the request. We may ask for information needed to verify your identity and authority. Authorized agents may submit requests where law permits, but we may still verify the user and the agent’s authority. We will not discriminate against you for exercising applicable privacy rights.
If we deny an appealable request, you may reply to appeal and explain why you believe the decision should change. You may also contact the privacy or consumer-protection authority where you live.
11. Security
We use administrative, technical, and physical safeguards designed to protect information, including access controls, encrypted transport, secure cookies, restricted private services, private object storage, and credential separation. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Protect your credentials and share links, use a unique password, and contact us promptly if you suspect compromise.
12. United States processing
KilnCat is operated from the United States. Information may be processed in the United States and other locations where our providers operate. Those locations may have privacy laws different from the laws where you live. Where required, we rely on contractual safeguards, consent, or other approved transfer mechanisms.
13. Children
The Service is for adults and is not directed to children or anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided information to KilnCat, contact us so we can investigate and delete it as appropriate.
14. Changes to this Policy
We may update this Policy as the Service, our practices, or legal requirements change. We will update it when our practices materially change the information categories, purposes, recipient categories, retention criteria, or choices described here. We will post the updated version and revise the date above. If a change is material, we will provide additional notice through the Service, email, or another appropriate channel before it takes effect when required. Prior versions may be requested by contacting us.
15. Contact
Contact us with privacy questions, requests, complaints, or support needs. Email may be converted into a PostHog Support ticket, and relevant content may be submitted to a third-party LLM provider under its applicable terms and settings as described above. Please do not include passwords, access tokens, payment details, or other secrets in email.