Back to Krit

Last updated August 8, 2026

Privacy Policy

Short version: the marketing site sets no cookies and no trackers. The product stores your account and the designs you make in it, asks Google only for your email and basic profile, and never sells any of it.

This policy covers the Krit website at krit.design and the Krit product at app.krit.design. Where the two behave differently, and they do, it says so.

The website

Anonymous usage statistics. We use Vercel Analytics to count page visits and see which pages people read. It is cookieless, it does not follow you to other sites, and it does not build a profile of you. We see aggregate numbers, such as how many people opened the pricing section, not individuals.

Standard server logs. Our host, Vercel, records ordinary request logs including IP address, browser user agent, and the page requested. This is how essentially every web server works, it exists for security and debugging, and it is retained on Vercel's normal schedule rather than ours.

The website sets no cookies of ours, so there is no cookie banner to click. It runs no advertising or social pixels. Fonts are self-hosted at build time, so loading a page makes no request to Google Fonts and leaks no IP address to them. There is no signup form and no newsletter.

Signing in to the product

Krit accounts are handled by Supabase Auth. You can sign in with Google, with GitHub, or with an email address and password.

If you sign in with Google, we request three standard scopes and nothing else: your email address, your basic profile (your name and profile picture), and your Google account identifier. We do not request access to Gmail, Drive, Calendar, Contacts, or any other Google service, and we never see or receive your Google password.

We use that Google data for exactly one purpose: to create your Krit account, identify you when you return, and contact you about your account. We do not use it for advertising, we do not sell or transfer it, and we do not use it to build a profile of you. If Google ever grants us data we do not need, we do not keep it.

Signing in with GitHub works the same way and requests only your email address and basic profile. Signing in with an email address gives us that address and a securely hashed password, which we never store in readable form.

You can disconnect Krit from your Google account at any time from your Google Account permissions page, which revokes our access immediately.

What the product stores

  • Your account: the email, name, and profile picture from whichever sign-in you used.
  • Your work: the projects, canvases, artboards, designs, and version history you create, along with the thumbnails and snapshots we render so the app can show you a preview.
  • Your share links: if you create one, a token that makes that specific project viewable by anyone holding the link.
  • Your subscription status: whether your account is entitled to access, and when that entitlement started or ends.

This lives in our database with Supabase and on servers we operate. Access is restricted to what your account is allowed to see.

Product analytics

Inside the app we use PostHog to understand how the product is used, for example which features get opened and where people get stuck. Unlike the website's analytics, this is associated with your account, because a bug report is not much use if we cannot tell which session it came from. We use it to improve Krit. We do not sell it and we do not use it for advertising.

Payments

Subscriptions are processed by Dodo Payments, which acts as the merchant of record. They collect and handle your payment details under their own privacy policy. Card numbers never reach our servers. What we receive back is your subscription status and the receipt information we need for our own records and tax.

Sharing

A share link makes one project viewable, read only, by anyone who has the URL. It is unlisted rather than secret, so treat it as public. You create these deliberately and you can revoke one at any time.

Keeping and deleting your data

We keep your account and your work for as long as your account exists, because that is the service. If you cancel a subscription, your work is retained so it is still there if you come back.

To delete your account and everything in it, email jaideep@krit.design from the address on the account. We will delete your profile, your projects, your snapshots, and your share tokens, and confirm when it is done. Backups roll off on their own schedule shortly afterwards. Records we are required to keep for tax and accounting, such as invoices, are retained as the law requires.

When you contact us or book a call

If you email jaideep@krit.design, we have your email address and whatever you wrote, in an ordinary inbox, for as long as the conversation is useful. We use it to reply to you and to follow up about work you asked about. We do not add you to a mailing list.

If you book a product audit, that booking runs on Cal.com, which collects your name, email, and the details you enter to schedule the call. Cal.com handles that data under its own privacy policy, and we receive the booking details so we can show up to the call.

Work you share with us in an engagement

If you take a Founder Sprint or send us your product for a teardown, we will see your app, your repository, and whatever else you show us. We treat that as confidential and we do not share it or publish it. We will ask you before using any part of it as a public case study, and no is a complete answer.

Your rights

If you are in the EU, UK, or California, you have rights to access, correct, export, and delete personal data we hold about you, and to object to its processing. We honour these regardless of where you live, because running two standards is how mistakes happen.

To exercise any of them, write to jaideep@krit.design. We will action it and confirm. We do not sell personal information, so there is nothing for you to opt out of on that front.

Processors we rely on

  • Supabase for authentication and the database that holds your account and your work.
  • Vercel for hosting the website and its anonymous analytics.
  • PostHog for product analytics inside the app.
  • Dodo Payments for subscription billing, as merchant of record.
  • Cal.com for call scheduling, only if you book a call.
  • Google Workspace for the email inbox that receives your messages.

Children

Krit is a tool for professional work and is not directed at children under 13. We do not knowingly collect their data. If you believe a child has created an account, tell us and we will remove it.

Changes

If Krit starts collecting something new, this page changes first and the date at the top moves with it. Material changes to how we handle your data will be sent to the email on your account rather than quietly published.

Questions about any of this go to jaideep@krit.design.

Also worth reading:Terms of Service