Privacy Policy
Last updated: July 6, 2026
Overview
kbdt.dev ("kbdt", "we", "us", or "our") is a keyboard-first task management application. We are committed to protecting your privacy and being transparent about how we handle your information.
kbdt is designed as an offline-first application. Your task data is stored locally on your device by default. This policy describes what information we collect, how we use it, and your choices.
Information We Collect
Account Information
When you sign in, we receive basic profile data from your authentication provider (GitHub): your name, email address, and profile photo. This information is stored in Firebase Realtime Database and used to identify your account, display your profile to collaborators, and manage subscriptions.
Task Data
Your tasks, notes, and outlines are stored locally on your device using IndexedDB. If you enable cloud sync, this data is stored in Cloudflare Durable Objects and associated with your account. We do not read, analyze, or share your task content.
Collaboration Data
When you share a bucket with other users, your tasks in that bucket become visible to all members in real time. Invitations and membership records are stored in Firebase Realtime Database.
API Access
Pro users may generate API tokens to access their tasks programmatically (e.g., via MCP clients). These tokens are stored in Cloudflare D1 and grant access to the same data available in the app. You are responsible for safeguarding your API tokens.
Payment Information
If you subscribe to a paid plan, payment processing is handled entirely by Creem (our payment provider). We do not store your credit card number or payment details. We receive only your subscription status and transaction identifiers.
Usage Analytics
We may collect anonymous, aggregated usage data (e.g., feature usage frequency, error reports) to improve the product. This data cannot be used to identify individual users and contains no task content.
How We Use Your Information
- To provide and maintain the kbdt service
- To sync your data across devices when you opt in
- To authenticate your identity
- To improve and debug the application
- To communicate service updates or changes
We do not sell, rent, or share your personal information with third parties for marketing purposes.
Data Storage & Security
Local data is stored in your browser's IndexedDB and never leaves your device unless you enable sync. Synced data is stored on Cloudflare's global network using Durable Objects with SQLite, with encryption in transit (TLS) and at rest.
We apply reasonable security measures to protect your data, but no method of electronic storage is 100% secure. You are responsible for maintaining the security of your device and account credentials.
Data Retention
We retain your account information and cloud-synced task data for as long as your account is active. If you cancel your Pro subscription, your cloud data remains accessible for 30 days after the billing period ends, after which it may be deleted.
If you request account deletion, we will delete all associated data within 30 days. Local data stored in your browser is not affected by account deletion and remains under your control.
Third-Party Services
We use the following third-party services:
- Firebase(Google) — authentication, user profiles, invitation management, and subscription status
- Cloudflare— task data storage (Durable Objects), relational storage (D1), hosting, and API infrastructure (Workers)
- Creem— subscription billing and payment processing
- GitHub— authentication provider and profile data (avatars, display names)
Each service has its own privacy policy. We encourage you to review them.
Your Rights
You may at any time:
- Export or delete your local data by clearing browser storage
- Request deletion of your cloud-synced data by contacting us
- Revoke authentication access through your GitHub account settings
- Stop using the service entirely — your local data remains yours
Cookies
kbdt uses only essential cookies required for authentication and session management. We do not use tracking cookies or third-party advertising cookies.
Children's Privacy
kbdt is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last updated" date above. Continued use of kbdt after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy, please reach out at hello@kbdt.dev.