Privacy Policy
Krytr (“we”, “us”, “our”) operates the Krytr platform at krytr.com (the “Service”). This page explains what data we collect, how we use it, and the choices you have.
1. Information we collect
- Account data — email, name, and authentication ID from your sign-in provider (Clerk).
- Brand data — handles, palettes, voice settings, and other content you create.
- Render data — topics, generated scripts, generated assets, and resulting videos.
- Social connection tokens — when you connect Instagram or YouTube, we store OAuth access tokens encrypted in our database. We never see your social-platform password.
- Usage data — credit balances, renders count, plan, and basic analytics needed to operate the Service.
- Billing data — handled by Stripe. We store a Stripe customer ID; we do not store card numbers.
2. How we use it
- To deliver the Service: fetch content sources, generate scripts and assets, render videos, and publish them to the social accounts you connect.
- To bill you for usage and manage subscriptions.
- To send transactional emails (account, billing, render-complete notifications).
- To improve Krytr — aggregated, de-identified usage data only.
3. Social-platform data (Meta + Google)
When you connect Instagram or YouTube, we request only the scopes needed to publish content on your behalf and read basic profile info to display in our UI. Specifically:
- Instagram (Meta Graph API):
instagram_basic,instagram_content_publish,pages_show_list,pages_read_engagement,business_management. - YouTube (Google API):
youtube.upload,youtube.readonly.
We never use these tokens for any purpose other than what you initiate. You can disconnect any account at any time from /dashboard/connections, which deletes the stored tokens immediately.
Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
4. Third-party processors
We share data with the following processors strictly for service delivery:
- Clerk — authentication
- Neon (Postgres) — primary database
- Upstash Redis — job queue
- Cloudflare R2 — media storage
- Stripe — payments
- OpenRouter / Anthropic / OpenAI / Runware / Kling — AI generation (scripts, images, voice). Content sent to these providers is limited to the topic and prompts needed for generation.
- Tavily — content source fetch
- Meta + Google — when you publish, the rendered video and caption are uploaded to the platforms you chose.
5. Data retention
Account, brand, and render data are retained while your account is active. If you delete your account, we delete all associated personal data within 30 days, except where retention is required by law (e.g., billing records for tax purposes).
6. Your rights
Depending on your jurisdiction, you may have rights to access, correct, port, or delete your personal data. Email [email protected] and we will respond within 30 days.
7. Security
We use industry-standard encryption in transit (TLS) and at rest. OAuth tokens are encrypted at rest. No system is perfectly secure — please use a strong password and report suspected breaches to [email protected].
8. Changes
We may update this policy. Material changes will be communicated by email or in-product notice at least 14 days before they take effect.
9. Contact
Krytr · [email protected]