Privacy Policy

How KSTRLWORKS handles your Privacy

Effective Date: December 14, 2025 Updated Date: August 4, 2026


Privacy Highlights

We believe in radical transparency about privacy. Here’s what sets us apart:

  • Minimal data collection - We only collect your email, username, ip and non-identifiable system data for licensing
  • No payment data - Payment processors handle everything; we never see your card details
  • Self-hosted analytics - Fully anonymous, never leaves our servers
  • Your work stays yours - No crash reports, error logs, or project data collected. Nothing is sent unless you run our separate support tool with --send
  • No data selling - Never have, never will
  • No ad trackers - Zero third-party advertising or tracking cookies
  • US-based - All data stored in USA

Questions? We’re humans and we respond: [email protected]


1. Who We Are

KSTRLWORKS provides software for Linux. You purchase and download our software through our website. This policy explains exactly what data we collect, how we use it, and your rights.


2. Information We Collect

We collect minimal data to operate our service:

Account Information

  • Email address - To create your account and send purchase confirmations
  • Username - To identify your account
  • Authentication tokens - Generated by Hanko (our authentication provider) to keep you logged in securely

Desktop Software Technical Data

  • System information - Used solely for compatibility checks and license verification to prevent unauthorized use
  • Update checks - Your application periodically checks our servers for available updates.
  • Ip address - Your ip address is collected during update and downloads to help mitigate abuse of the endpoints.

Support Diagnostics (Optional Tool)

We offer a separate support and diagnostics tool to help resolve support tickets. It is not part of any product, none of our products depend on it, and it never runs unless you run it.

  • Local by default - The tool runs entirely on your machine, shows you the results, and sends nothing anywhere
  • Sending is a deliberate act - Data leaves your machine only when you run the tool with the --send flag and provide the ticket number and email address for your open support ticket
  • You see the full payload first - What we receive is exactly what the tool displays. Run it without --send and you are looking at everything that would be sent
  • One purpose only - We use the diagnostic to debug the issue in your ticket, nothing else, and then delete it (see Data Retention)

Anonymous Website Analytics

  • Self-hosted Umami analytics - Tracks which website features are used (button clicks, page views) without identifying you personally
  • This data never leaves our servers and contains no personal information

Payment Information

  • Handled entirely by Creem and LemonSqueezy - You sign up directly with them during checkout
  • We never receive, process, or store your credit card or payment details
  • All payment data is governed by the payment processor’s privacy policy

What We DON’T Collect

  • Crash reports (stored locally on your device only)
  • Error logs (stored locally on your device only)
  • Your files, projects, or work product
  • Browsing history or activity outside our application
  • Location data
  • Device fingerprints beyond what’s necessary for licensing

3. How We Use Your Data

We use your information only for these purposes:

  • Account Management - To create, secure, and manage your account
  • License Verification - To verify your software license and prevent unauthorized use
  • Software Updates - To deliver software updates and notify you of new versions
  • Service Communication - To send purchase confirmations, license information, and important service updates
  • Service Improvement - To understand hardware compatibility and stability using anonymous, aggregate data.
  • Prevent Abuse - To be able to block certain ip ranges if they abuse our service.
  • Support - To debug the issue in your ticket when you choose to send us a diagnostic report.

We do not use your data for advertising, profiling, or any purpose beyond operating our service.


For users in the European Union, we process your data based on:

  • Contract - To provide you with the software and services you purchased
  • Legitimate Interest - To improve our services through anonymous analytics and prevent license abuse
  • Legal Obligation - To comply with tax and financial regulations
  • Consent - To process a support diagnostic you explicitly send us with the support tool

5. Authentication & Session Management

We use Hanko as our authentication provider, which generates secure JWT (JSON Web Tokens) to keep you logged in. These tokens are:

  • Stored in your browser
  • Used only for authentication purposes
  • Automatically expire after a period of inactivity
  • Not used for tracking or advertising

We do not use traditional tracking cookies. The only data stored in your browser is necessary for you to stay logged in.


6. Data Sharing & Third Parties

We do not sell or share your personal data. Period.

The only third parties that interact with your data are:

Hanko (Authentication)

  • Purpose: Secure login and authentication
  • Data Shared: Email, username, authentication tokens
  • Privacy Policy: Hanko’s privacy policy

Payment Processors (Creem & LemonSqueezy)

Self-Hosted Analytics (Umami)

  • Purpose: Understand website usage patterns
  • Data Collected: Anonymous page views, button clicks, navigation patterns
  • Hosting: Self-hosted on servers in USA
  • Personal Data: None - completely anonymized and never shared with any third party

7. Data Location & International Transfers

  • All data is stored on servers in USA
  • We do not transfer your personal data to other countries
  • For EU users: Your data is protected under Standard Contractual Clauses for transatlantic data transfers as required by GDPR

8. Data Retention

We keep your data only as long as necessary:

Data TypeRetention Period
Active accountsRetained while your account is active
Deleted accountsPermanently deleted within 90 days of deletion request
Anonymous analyticsRetained indefinitely (contains no personal information)
Support diagnosticsDeleted from our servers and working machines within 30 days after your ticket is resolved
Ip addressRetained indefinitely (as an abuse filter only)
Payment recordsMaintained by payment processors per their policies and legal requirements
Authentication tokensExpire automatically based on session length

9. Data Security

We take security seriously:

  • Encryption in transit: All data transmission uses TLS 1.2 encryption or higher
  • Encryption at rest: User account data is encrypted using AES-256 encryption
  • Access controls: Strict internal access controls limit who can access data
  • Regular updates: Our systems are regularly updated with security patches
  • Minimal collection: The best security is not collecting data in the first place

Security Incidents

In the unlikely event of a data breach affecting your personal information, we will notify you within 72 hours as required by GDPR and applicable laws.


10. Your Privacy Rights

Rights for All Users

You have the right to:

  • Access - Request a copy of your personal data (email and username)
  • Correction - Request correction of inaccurate data (can be done in your profile)
  • Deletion - Request deletion of your account and data (can trigger deletion in your profile)
  • Object - Object to how we process your data
  • Portability - Download your data in a machine-readable format
  • Withdraw consent - Stop receiving optional communications

Additional Rights for EU Residents (GDPR)

  • Right to restrict processing of your data
  • Right to lodge a complaint with your local data protection authority
  • Right to be informed of the safeguards for international data transfers

Additional Rights for California Residents (CCPA)

  • Right to know what categories of personal information we collect
  • Right to know if we sell your personal information (we don’t)
  • Right to opt-out of any future sale (we never sell data)
  • Right to non-discrimination for exercising your privacy rights

How to Exercise Your Rights

Email us: [email protected]

Response time:

  • GDPR requests: Within 30 days
  • CCPA requests: Within 45 days (may extend another 45 days if needed)

We’ll verify your identity before fulfilling requests to protect your data from unauthorized access.


11. Children’s Privacy

Our services are not intended for anyone under 16 years old (or 13 in the United States under COPPA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately at [email protected] and we will delete it.


12. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects. All account and license decisions are reviewable by humans.


13. Policy Updates

We may update this privacy policy from time to time to reflect:

  • Changes in our data practices
  • New legal requirements
  • Service improvements

When we make changes:

  • We’ll update the “Last Updated” date at the top
  • For material changes, we’ll notify you via email
  • Continued use of our services after changes means you accept the updated policy

You can always find the current version at /policies/privacy-policy


14. Contact Us

We’re humans and we respond to every privacy inquiry.

For privacy questions, requests, or concerns:
Email: [email protected]
Please include “Privacy Question” in the subject line

For data subject access requests (GDPR/CCPA):
Email: [email protected]
Please include “Privacy Request” in the subject line


15. Transparency Commitment

We believe privacy policies should be honest, clear, and actually helpful. If anything in this policy is confusing, or if you have suggestions for how we can be more transparent, please let us know. We’re always trying to do better.


Thank you for trusting us with the minimal data we need to serve you.