Policy

Privacy, in plain language.

v1.2 · September 2026

This is the long version of the promise on the homepage. Same rules, more detail, still no legalese. If anything here ever stops being true, the version number at the top changes and the changelog says why.

What we collect: nothing by default.

This site runs no analytics today. No cookies. No third-party requests. Open your browser's network tab and check. There is no ad pixel, no data broker, no "partners." Your data isn't inventory here. The only thing this site stores on your device is a single localStorage entry named khaivo-theme: it remembers your light or dark choice and never leaves your browser. The tools that are live keep their own data on your device, and each says so on its page.

One honest caveat: the host that serves these pages (Cloudflare) keeps standard server logs, which can include your IP address and a timestamp. That's ordinary hosting, it isn't ours to sell, and we don't use it for anything. If your connection to this site ever fails, your browser may also send Cloudflare a short error report about that failure. It goes to Cloudflare, never to us.

If analytics ever arrive, you'll read about it here first.

We may eventually want to know how many people visit. If that day comes, the analytics will be self-hosted, cookieless, and aggregate-only: a tool like Plausible or Umami that counts visits without identifying visitors. This page will say so before it happens, with a version bump at the top. No silent changes.

Tools tell you what they send. Most send nothing.

Every tool that can run entirely in your browser does, and its page here carries a plain badge stating exactly what it sends and what it does not. Where a tool has an opt-in exception the badge names it: The Edge Room's badge names its optional AI coach. What you paste stays on your machine unless that badge says otherwise.

Some tools genuinely need a server to work. Those say exactly what is sent, on the tool's own page, before you use it. If a tool's page doesn't mention a server, it doesn't use one.

The newsletter, when it opens: double opt-in, one tap out.

When the newsletter launches, you'll confirm your address before receiving anything (double opt-in), and every email will carry a one-tap unsubscribe that actually works. Your address is never shared or sold. Ever.

Payments, when pro tools ship: Stripe handles them, not us.

Paid tools will use Stripe Checkout. Your card number goes to Stripe and only to Stripe. It never touches Khaivo's servers, and we couldn't read it if we wanted to.

Your rights: email a human, get an answer.

Want to know what we hold about you, or want it deleted? Email hello@khaivo.art and the founder answers, not a ticket queue. Data is deleted on request. Given how little we collect, that conversation will be short. Under GDPR-style laws you can also ask us to correct anything wrong, restrict or object to how the hosting logs are used, or receive whatever we hold in a portable form. Same inbox, same human.

Who is responsible, and on what basis.

Khaivo is run by one person, Quan Vo. Email hello@khaivo.art and you reach him, not a company desk. A postal address lands here once the business details are settled, and the version above bumps that day.

Apart from what you email us, the host logging named above is the only personal data in play, and it exists so these pages get delivered and stay secure. That is legitimate interest, not consent: nothing here asks you for any. The logs are Cloudflare's, kept under Cloudflare's own published retention rules, so we hold no copy to keep or delete. Cloudflare runs a worldwide network, so those logs can be processed outside your home country; Cloudflare publishes a Data Processing Addendum, with the EU standard contractual clauses, for exactly that situation. If you live in the EU or the UK, you can also complain to your national data protection authority. If you email us, we hold that email: your address and what you wrote, in the founder's mailbox, so he can answer you and keep a record of what was agreed. Ask and it is deleted.

Children: nothing here is aimed at them.

This site and its tools are not directed at children under 16, and we don't knowingly collect anything from anyone that age or younger. There is nothing to sign up for, no profile to build, and no way to attach data to a child. If you believe a child's data ended up here anyway, email hello@khaivo.art and it gets deleted.

Changes are versioned, never quiet.

This policy carries a version and a date at the top of this page. Any change bumps the version, and the changelog is public. You should never discover a privacy change by surprise.

Further reading, from people we do not control

Privacy is bigger than this site. Independent, free resources we trust and do not control: Privacy Guides, a community-run catalog of privacy tools and advice, and the EFF's Surveillance Self-Defense, plain-language guides to protecting yourself online. Also worth bookmarking: Data Detox Kit, step-by-step guides to clean up your digital life from a nonprofit, in many languages, and Have I Been Pwned, a free way to check whether your email appeared in known data breaches, no signup. And when you want to understand why any of this matters: Privacy International, an independent nonprofit that has investigated the surveillance industry since 1990 and accepts no corporate or government funding. And when you want the exhaustive map instead of the short list: Awesome Privacy, a community-kept catalog of alternatives where every change is public. And when you would rather check than trust, this site included: Blacklight, a free website privacy inspector from The Markup, a nonprofit newsroom: paste any address and it lists the trackers it finds, no signup. None of them knows you came from here: every link above carries no tracking of any kind.

If you are still asking why any of this matters, the case is written out in plain words on this site: Why privacy matters.

Back to khaivo