Privacy Policy

Last updated 6 August 2026

Persona Kit is a tool for managing separate online identities, which means you deliberately put identity-shaped information into it. This policy explains exactly what we store, where it lives, who else can see it, and how to get it back or delete it.

Who we are

Persona Kit is operated by Techtegrity (“Persona Kit”, “we”, “us”). We provide a hosted service at persona-kit.com for creating and managing distinct online personas, including per-persona email inboxes, profile images, and browsing profiles. We are the data controller for the information described in this policy.

For any privacy question or request, contact [email protected]. Include a postal mailing address in replies when required for a rights request under applicable privacy law.

What we collect

Account information

When you create an account we store your name, email address, and whether that address has been verified. If you sign in with a password, we store a hash of it — never the password itself. If you sign in with Google or GitHub, we store the access and refresh tokens that provider issues us, along with the account identifier and granted scopes.

Session and device information

Each active sign-in creates a session record containing a session token, your IP address, and your browser’s user-agent string. We use these to keep you signed in, to show you your active sessions, and to investigate suspicious activity.

Billing information

Paid subscriptions are processed by Stripe. We never see or store your card number. Stripe returns a customer identifier, which we store against your organization so we can look up your subscription and show your plan. Your name, billing address, and payment details live with Stripe under their privacy policy.

Usage information

For subscribers on a metered plan we report a count of your active personas to Stripe so the per-persona portion of your bill can be calculated. This is a number, not a list — the contents of your personas are never sent to Stripe.

Persona data

This is the part worth reading closely, because personas are where the sensitive material is. Everything below is content you create or that arrives in a persona inbox you created. We store it so the product can function.

  • Identity fields — persona name, username, gender, date of birth, phone number, street address, city, state, postal code, country, and the last four digits of a social security number where you choose to record one.
  • Environment fields — the IP address, location, browser, operating system, language, and timezone associated with a persona.
  • Browser fingerprint — user agent, screen resolution, colour depth, platform, installed plugin and font lists, canvas, WebGL and audio-context signatures, hardware concurrency, device memory, and touch support.
  • Browsing history and cookies — URLs and page titles visited in a persona’s browsing sessions, and the cookies captured during them, including cookie values.
  • Email — for personas with an inbox, the full contents of messages received: sender address and name, subject, and the message body in both text and HTML.
  • Images — persona profile photos you upload, and photos generated on your behalf by our AI image feature.
  • Proxy credentials — if you configure an outbound proxy, its host, port, and username in plain form, and its password encrypted with AES-256-GCM (see Security).

Persona data is stored so that we can operate the service, and our staff can technically access it — see Security for an honest description of what that means. Do not store information in a persona that you could not tolerate being read by a systems administrator or disclosed under legal compulsion.

Why we process it

Under the GDPR, we rely on the following legal bases. If you are outside the EU/UK, these still describe our actual reasons.

  • Performance of a contract — operating your account, storing and displaying your personas, receiving and showing persona email, generating images you request, and billing you for a paid plan.
  • Legitimate interests — keeping the service secure and available, preventing abuse, diagnosing faults, and communicating about service changes. We balance these against your interests and use the least data that achieves the purpose.
  • Legal obligation — retaining billing and tax records, and responding to lawful requests.
  • Consent — where we ask for it explicitly, such as optional product emails. You can withdraw consent at any time.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use your persona content to train machine learning models.

Who we share it with

We use the following sub-processors. Each receives only what its function requires, and each is bound by its own contractual and privacy obligations to us.

ProcessorPurposeWhat it receives
VercelApplication hosting and deliveryRequests to the site, including IP address and user agent; server logs
Techtegrity managed PostgreSQLPrimary databaseAll account and persona data described above
Amazon Web Services (S3)Image storagePersona profile images
StripePayments and subscription managementYour email address, payment details you enter with them, and a count of active personas for metered billing
PostmarkSending and receiving emailOutbound account email (verification codes, digests) and inbound persona email in transit
OpenAIAI persona image generationThe prompt describing the persona whose image you asked us to generate
SteelRemote browser sessionsPersona browsing profile and session traffic while a session is running
Google, GitHubOptional single sign-onOnly what you authorise at sign-in, if you use these providers

We may also disclose information where legally required — in response to a valid subpoena, court order, or other lawful demand — or to establish, exercise, or defend legal claims. If we are ever party to a merger or acquisition, your information may transfer as part of that transaction, and we will say so before it takes effect.

How long we keep it

  • Account data — for as long as your account exists, and up to 30 days after deletion in backups.
  • Personas and their contents — until you delete them, or until you delete your account.
  • Persona email — on the Free plan, inbound messages are automatically removed after 7 days. On Pro, messages are kept until you delete them. In both cases the persona and its address survive; only the messages age out.
  • Sessions — until they expire or you sign out.
  • Billing records — as long as required for tax and accounting purposes, typically seven years, held by us and by Stripe.

Security

We would rather describe this accurately than impressively.

What we do:

  • All traffic to and from the service is encrypted in transit using TLS.
  • Account passwords are stored as salted hashes, never in a recoverable form.
  • Proxy passwords are encrypted at the application layer with AES-256-GCM before being written to the database.
  • Data at rest is protected by disk-level encryption on our database and object storage infrastructure.
  • Access to production systems is limited to personnel who need it to operate the service.

What we do not do, so that there is no confusion:

  • Persona content is not end-to-end encrypted, and is not encrypted client-side before it reaches us.
  • We do not operate a zero-knowledge architecture. Persona fields, email contents, and images are readable by our systems and, where necessary, by our staff.
  • Encryption keys are held server-side by us. They are not derived from your password, and we can decrypt what we encrypt.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any relevant supervisory authority as required by law.

Your rights

Depending on where you live, you may have the right to access a copy of your personal information, correct it, delete it, restrict or object to its processing, port it to another service, and withdraw consent. Residents of Virginia have these rights under the Virginia Consumer Data Protection Act; residents of California under the CCPA/CPRA; residents of the EEA and UK under the GDPR.

Persona-level deletion is self-service. You can edit or delete any persona from your dashboard, and deleting one removes its identity fields, email messages, images, cookies, and browsing history.

Account-level export and erasure are handled by hand. We have not yet built self-service export or account deletion — email [email protected] and we will carry out the request and confirm when it is done, within the period the applicable law requires: 45 days under the VCDPA and CCPA, one month under the GDPR.

We will not discriminate against you for exercising these rights. If you believe we have handled your information improperly you may appeal our decision by replying to our response, and you may lodge a complaint with your supervisory authority — in Virginia, the Office of the Attorney General.

International transfers

We operate from the United States and our infrastructure is located there. If you access the service from outside the US, your information will be transferred to and processed in the US. Where we transfer personal data out of the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses with our sub-processors.

Children

Persona Kit is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has given us information, contact [email protected] and we will delete it.

Changes

We may update this policy as the product changes. When we make a material change we will update the date at the top of this page and, for changes that meaningfully affect your rights, notify account holders by email before the change takes effect. Continuing to use the service after a change means you accept the updated policy.

Contact

Questions, requests, or complaints: [email protected]. Persona Kit offers 3 personas at no cost, and you do not need a paid account to exercise any right described here.