Legal
Privacy Policy
Transparency about the data we collect, why we process it, and the controls available to you.
Last updated: April 13, 2026
Who this policy covers
This policy explains how Khaos Addon ("we", "us") handles personal data for visitors, registered users, and workspace administrators across our websites, APIs, and offline events.
Information we collect
Account details (name, email, authentication tokens), billing records processed by our payment partners, content you upload, device and log data (IP address, browser, approximate location), and product telemetry that helps us diagnose reliability issues.
How we use information
We use data to operate the service, personalize discovery, prevent abuse, fulfill legal obligations, and communicate product changes. Aggregated metrics may inform public roadmap posts without identifying individuals.
Legal bases (EEA & UK)
Where GDPR applies we rely on contract performance, legitimate interests (security, product improvement), consent for optional marketing, and legal requirements where compelled.
Retention
We retain account data while your workspace is active. Backups roll off within 35 days of deletion unless law requires longer storage. Audit logs for security events may be kept up to 18 months.
Your rights
You may access, correct, export, or delete personal data subject to legal exceptions. EEA/UK users may lodge complaints with their supervisory authority. California residents may request disclosure or deletion as described below.
Security
We encrypt data in transit (TLS 1.2+), enforce least-privilege access, run regular penetration tests, and maintain incident response playbooks reviewed quarterly.
International transfers
If data moves outside your region we rely on Standard Contractual Clauses or equivalent safeguards. Contact us for transfer impact assessment summaries.
Children
The service is not directed to children under 16 and we do not knowingly collect their data.
Updates
We will post changes here with a revised "Last updated" date. Material changes trigger in-product notices and, where required, fresh consent.
Contact
Questions about privacy? Email privacy@ or mail our registered address listed in the footer. For EU representatives, request details via the same channel.