Working draft · 26 August 2026
Scope
This draft covers the KairoLock public website, cloud services, and Windows application. It must be reconciled with the final telemetry, crash reporting, retention, vendors, and launch jurisdictions before publication.
Data we expect to process
- Email addresses submitted for launch notifications.
- Account identifiers and verified email through the authentication provider.
- Paddle customer, transaction, and subscription references; KairoLock does not receive raw payment-card data.
- Entitlement status, trial-consumption state, timestamps, and plan features.
- Support messages and the technical details the user chooses to provide.
- Security and service logs needed to prevent abuse and diagnose failures.
Launch notifications
When the pre-launch waitlist is enabled, KairoLock stores the submitted email address and the time it was submitted in Neon Postgres to send launch updates only. Duplicate submissions are treated as successful and do not reveal whether an address is already on the list. KairoLock does not send launch marketing until a suitable email-delivery process is in place. Removal from the waitlist can be requested at any time by writing to support@kairolock.com.
Public website
The website does not require an account or checkout. Any analytics and cookies must remain disabled until their exact purpose, provider, consent requirements, and retention are documented.
Windows activity data
Required decision: document whether any blocked-app, website, schedule, diagnostic, or crash data leaves the device. The public notice cannot be finalized until the Windows implementation and telemetry configuration are audited.
Processors and international transfers
Planned processors include Neon for pre-launch waitlist storage, Supabase for identity and data, Paddle for billing, and the selected hosting and release-delivery providers. Legal review must add entity names, locations, transfer mechanisms, and required regional disclosures.
Retention and deletion
Waitlist removal and data-deletion requests can be sent to support@kairolock.com.
Required decision: define a waitlist retention period before enabling launch emails. Legal review must also define retention periods for accounts, billing references, webhook records, logs, support records, and backups, plus an authenticated deletion process that preserves legally required financial records.
Your rights
Applicable access, correction, deletion, objection, restriction, and portability rights depend on jurisdiction. Requests can be sent to support@kairolock.com; the formal response procedure and statutory timelines must still be inserted before launch.