Legal

Privacy

Last updated 2026-05-25

What we collect

Only what KFC needs to run: your email and name (from sign-in), the rooms you create, the contributions you submit, and short request logs (IP, user agent, timestamp) for security. No tracking pixels, no third-party analytics, no advertising IDs.

What we share

Nothing with advertisers. Nothing sold. Contributions are visible only to the other members of the room you submitted to, after you submit. The contents of a room are sent to Anthropic to generate the synthesis. Account email may be sent to our auth provider for sign-in flows.

Where it lives

Application data is stored in Neon Postgres (EU-West-2, London). Authentication state is stored as HTTP-only cookies. Logs are retained 30 days.

Your rights

You can request a copy of your data, ask for corrections, or have your account deleted by contacting us. Account deletion removes your user record, all rooms you created, all contributions you made, and all replies. Cascades are immediate.

Cookies

One first-party HTTP-only session cookie for authentication. No tracking cookies, no consent banner needed under GDPR strictly-necessary exemption.

Children

KFC is not directed at children under 16 and we do not knowingly collect data from them.

Changes

We will update this page when our practices change. Material changes will be announced via the email on your account.