Who we are
Persona Kit is operated by Techtegrity (“Persona Kit”, “we”, “us”). We provide a hosted service at persona-kit.com for creating and managing distinct online personas, including per-persona email inboxes, profile images, and browsing profiles. We are the data controller for the information described in this policy.
For any privacy question or request, contact [email protected]. Include a postal mailing address in replies when required for a rights request under applicable privacy law.
What we collect
Account information
When you create an account we store your name, email address, and whether that address has been verified. If you sign in with a password, we store a hash of it — never the password itself. If you sign in with Google or GitHub, we store the access and refresh tokens that provider issues us, along with the account identifier and granted scopes.
Session and device information
Each active sign-in creates a session record containing a session token, your IP address, and your browser’s user-agent string. We use these to keep you signed in, to show you your active sessions, and to investigate suspicious activity.
Billing information
Paid subscriptions are processed by Stripe. We never see or store your card number. Stripe returns a customer identifier, which we store against your organization so we can look up your subscription and show your plan. Your name, billing address, and payment details live with Stripe under their privacy policy.
Usage information
For subscribers on a metered plan we report a count of your active personas to Stripe so the per-persona portion of your bill can be calculated. This is a number, not a list — the contents of your personas are never sent to Stripe.
Persona data
This is the part worth reading closely, because personas are where the sensitive material is. Everything below is content you create or that arrives in a persona inbox you created. We store it so the product can function.
- Identity fields — persona name, username, gender, date of birth, phone number, street address, city, state, postal code, country, and the last four digits of a social security number where you choose to record one.
- Environment fields — the IP address, location, browser, operating system, language, and timezone associated with a persona.
- Browser fingerprint — user agent, screen resolution, colour depth, platform, installed plugin and font lists, canvas, WebGL and audio-context signatures, hardware concurrency, device memory, and touch support.
- Browsing history and cookies — URLs and page titles visited in a persona’s browsing sessions, and the cookies captured during them, including cookie values.
- Email — for personas with an inbox, the full contents of messages received: sender address and name, subject, and the message body in both text and HTML.
- Images — persona profile photos you upload, and photos generated on your behalf by our AI image feature.
- Proxy credentials — if you configure an outbound proxy, its host, port, and username in plain form, and its password encrypted with AES-256-GCM (see Security).
Persona data is stored so that we can operate the service, and our staff can technically access it — see Security for an honest description of what that means. Do not store information in a persona that you could not tolerate being read by a systems administrator or disclosed under legal compulsion.
Why we process it
Under the GDPR, we rely on the following legal bases. If you are outside the EU/UK, these still describe our actual reasons.
- Performance of a contract — operating your account, storing and displaying your personas, receiving and showing persona email, generating images you request, and billing you for a paid plan.
- Legitimate interests — keeping the service secure and available, preventing abuse, diagnosing faults, and communicating about service changes. We balance these against your interests and use the least data that achieves the purpose.
- Legal obligation — retaining billing and tax records, and responding to lawful requests.
- Consent — where we ask for it explicitly, such as optional product emails. You can withdraw consent at any time.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use your persona content to train machine learning models.
Who we share it with
We use the following sub-processors. Each receives only what its function requires, and each is bound by its own contractual and privacy obligations to us.
| Processor | Purpose | What it receives |
|---|---|---|
| Vercel | Application hosting and delivery | Requests to the site, including IP address and user agent; server logs |
| Techtegrity managed PostgreSQL | Primary database | All account and persona data described above |
| Amazon Web Services (S3) | Image storage | Persona profile images |
| Stripe | Payments and subscription management | Your email address, payment details you enter with them, and a count of active personas for metered billing |
| Postmark | Sending and receiving email | Outbound account email (verification codes, digests) and inbound persona email in transit |
| OpenAI | AI persona image generation | The prompt describing the persona whose image you asked us to generate |
| Steel | Remote browser sessions | Persona browsing profile and session traffic while a session is running |
| Google, GitHub | Optional single sign-on | Only what you authorise at sign-in, if you use these providers |
We may also disclose information where legally required — in response to a valid subpoena, court order, or other lawful demand — or to establish, exercise, or defend legal claims. If we are ever party to a merger or acquisition, your information may transfer as part of that transaction, and we will say so before it takes effect.
How long we keep it
- Account data — for as long as your account exists, and up to 30 days after deletion in backups.
- Personas and their contents — until you delete them, or until you delete your account.
- Persona email — on the Free plan, inbound messages are automatically removed after 7 days. On Pro, messages are kept until you delete them. In both cases the persona and its address survive; only the messages age out.
- Sessions — until they expire or you sign out.
- Billing records — as long as required for tax and accounting purposes, typically seven years, held by us and by Stripe.
Security
We would rather describe this accurately than impressively.
What we do:
- All traffic to and from the service is encrypted in transit using TLS.
- Account passwords are stored as salted hashes, never in a recoverable form.
- Proxy passwords are encrypted at the application layer with AES-256-GCM before being written to the database.
- Data at rest is protected by disk-level encryption on our database and object storage infrastructure.
- Access to production systems is limited to personnel who need it to operate the service.
What we do not do, so that there is no confusion:
- Persona content is not end-to-end encrypted, and is not encrypted client-side before it reaches us.
- We do not operate a zero-knowledge architecture. Persona fields, email contents, and images are readable by our systems and, where necessary, by our staff.
- Encryption keys are held server-side by us. They are not derived from your password, and we can decrypt what we encrypt.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any relevant supervisory authority as required by law.
Your rights
Depending on where you live, you may have the right to access a copy of your personal information, correct it, delete it, restrict or object to its processing, port it to another service, and withdraw consent. Residents of Virginia have these rights under the Virginia Consumer Data Protection Act; residents of California under the CCPA/CPRA; residents of the EEA and UK under the GDPR.
Persona-level deletion is self-service. You can edit or delete any persona from your dashboard, and deleting one removes its identity fields, email messages, images, cookies, and browsing history.
Account-level export and erasure are handled by hand. We have not yet built self-service export or account deletion — email [email protected] and we will carry out the request and confirm when it is done, within the period the applicable law requires: 45 days under the VCDPA and CCPA, one month under the GDPR.
We will not discriminate against you for exercising these rights. If you believe we have handled your information improperly you may appeal our decision by replying to our response, and you may lodge a complaint with your supervisory authority — in Virginia, the Office of the Attorney General.
International transfers
We operate from the United States and our infrastructure is located there. If you access the service from outside the US, your information will be transferred to and processed in the US. Where we transfer personal data out of the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses with our sub-processors.
Children
Persona Kit is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has given us information, contact [email protected] and we will delete it.
Changes
We may update this policy as the product changes. When we make a material change we will update the date at the top of this page and, for changes that meaningfully affect your rights, notify account holders by email before the change takes effect. Continuing to use the service after a change means you accept the updated policy.
Contact
Questions, requests, or complaints: [email protected]. Persona Kit offers 3 personas at no cost, and you do not need a paid account to exercise any right described here.