Privacy Policy — KDPie
Last updated: 8 September 2026
This Privacy Policy explains how Pavel Dziubenko, an individual trader established in Montenegro (“we”, “us”) processes personal data when you use KDPie (the “Service”) and the website kdpie.com. We are the data controller for the processing described here. Contact: [email protected]; our postal address is available on request by email.
1. Data we collect
Account data. Email address, plan and subscription status, and the credentials you sign in with — held for us in hashed form by our authentication processor, never in clear text. Registration asks for an email address and a password, and nothing else: no registration or account field asks for, or stores, your name, your telephone number or your postal address. (The payment provider’s own checkout collects the billing details it needs for tax — see “Billing data” below; those never reach us.)
Usage and research data. Search phrases and seed topics you enter, book identifiers (ASIN/ISBN) you track, research results and reports generated for your workspace, quota and credit usage, queue/job metadata, and technical logs (timestamps, feature usage, error diagnostics).
Billing data. Purchases are processed by Paddle as Merchant of Record. Paddle collects your payment details, billing address, and tax location; we never receive or store your full card details. We receive from Paddle only what we need to operate your subscription (e.g. subscription status, plan, billing period, a transaction reference).
Cookies / session. Signing in stores a session identifier in your browser. That identifier is what keeps you signed in; the app sends it with each request it makes to our API, where the matching session record lives, and signing out deletes both copies. The app also keeps a few small values in the browser itself so it behaves sensibly between page loads, and this is all of them: which plan card you clicked and when; a short-lived note that a payment or a plan change is being confirmed, holding the workspace it belongs to, what it was for, when it finished, and a snapshot of your billing state at that moment — whether a subscription was already active, your plan, your credit limits, your granted top-up allowance and how many packs of each type you had bought; a short-lived mark that someone just signed in, and when; and the marketplace each form was last set to. Signing out clears the plan card, the payment note and the remembered marketplaces; the sign-in mark is kept only for the browser tab you signed in on and ends with it. The plan card, the payment note and the sign-in mark also stop counting on their own after a short time — the plan card does so even if you never sign in at all. We never transmit any of these values on their own, and none of them is used to recognise you on other websites, nor is any of them analytics of any kind; the remembered marketplace reaches us only as part of a form you submit with it selected. The payment provider’s own checkout script, which runs on the Billing screen, stores things of its own — see section 3. The public website currently loads no third-party analytics or tracking scripts. Two counters — Google Analytics 4 and Meta Pixel (site analytics and ad measurement) — are prepared but currently switched off: when we turn them on, they will load only after you accept them in a cookie banner (declining, or ignoring the banner, keeps the site fully usable with no analytics cookies at all), a “Cookie settings” link will appear here to change your choice at any time — the choice itself is remembered only in your browser, never on our servers — and this paragraph will be updated the same day they go live.
We do not intentionally collect special categories of personal data, and the Service is not directed at children.
2. Why we process it (legal bases under GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the Service (accounts, research runs, reports, quotas) | Contract (Art. 6(1)(b)) |
| Billing and subscription management via Paddle | Contract; legal obligation (tax/accounting) |
| Service security, anti-abuse, fair-use enforcement | Legitimate interest (Art. 6(1)(f)) |
| Product diagnostics and improving the shared research dataset (aggregated/de-identified) | Legitimate interest |
| Service emails (receipts, important account/service notices) | Contract |
| Keeping the session identifier and the functional values section 1 lists as the app’s own in your browser (none of them analytics or tracking) | Contract (Art. 6(1)(b)) — they exist to deliver the Service you signed in to; the plan card remembered before you have an account rests on legitimate interest (Art. 6(1)(f)) |
| Website analytics and ad measurement on the public site (Google Analytics 4, Meta Pixel — prepared, currently switched off; will run only with consent) | Consent (Art. 6(1)(a)) — via the cookie banner, revocable any time |
| Marketing emails (if any) | Consent — opt-in, revocable any time |
3. Processors and recipients
We use a small set of processors to run the Service:
- Supabase — database and authentication hosting (account data, workspace data, research data).
- Paddle — Merchant of Record for payments (see above; Paddle acts as an independent controller for its checkout). Its checkout script runs on the Billing screen and stores values of its own in your browser, under its own policy; we neither set nor read them.
- AI providers (e.g. Anthropic) — fragments of your inputs (search phrases, niche/report context) are sent to third-party AI models to power AI features (explanations, the research advisor, autonomous research). We send what the feature needs, not your account credentials.
- Market-data providers — search phrases you research are queried against third-party marketplace-data services to fetch volumes, listings, and rankings.
- Hosting/infrastructure providers for the application itself: Render (application, API and background workers, EU region) and Cloudflare (delivery of the public website).
- Google (Google Analytics 4) and Meta (Meta Pixel) — site analytics and ad measurement on the public website, prepared but currently switched off; when enabled they load only after your consent in the cookie banner (see §1). Each processes that data under its own terms; the Pixel also serves Meta’s ad measurement, where Meta may act as a joint controller for the collection.
Some processors are located outside the EEA; where required, transfers rely on adequacy decisions or Standard Contractual Clauses. We do not sell personal data.
4. Retention
- Account and workspace data: for the life of the account and a reasonable period after deletion for backup integrity.
- Research inputs/results: retained while the account is active; aggregated, de-identified research signals may be retained indefinitely as part of the shared dataset (they no longer identify you).
- Billing records: as required by tax and accounting law (held primarily by Paddle).
- Technical logs: short rotation windows appropriate to diagnostics and security.
5. Your rights
If EU/EEA/UK data-protection law applies to you, you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is based on consent. Write to [email protected]; we respond within the statutory deadline. You also have the right to lodge a complaint with your local supervisory authority.
Account deletion: write to [email protected] — the address is also on the account screen in the app — and we delete your account and personal workspace data within 30 days; anonymous aggregate research signals and legally required billing records are retained as described above. Deletion is carried out by a person, and it does not by itself end a paid subscription: cancel the subscription first if it is still active.
6. Security
Data is stored with access controls and tenant isolation (your workspace’s data is scoped to your workspace), secrets are managed outside the codebase, and payment data never touches our systems. No internet service can guarantee absolute security; we notify affected users and authorities of breaches where required by law.
7. Changes
We may update this Policy; material changes will be announced on the site or by email. The “Last updated” date always reflects the current version.