InterfaceKitLegal

On this page

  • 01Scope
  • 02Sources of information
  • 03Account and authentication information
  • 04Browser and device information
  • 05Agent usage information
  • 06Communications and support
  • 07Browser storage
  • 08Information we do not currently request
  • 09How we use information
  • 10Legal bases
  • 11Service providers
  • 12Other disclosures
  • 13No sale or targeted advertising
  • 14Retention
  • 15International processing
  • 16Security
  • 17Your rights and choices
  • 18Children
  • 19Changes and contact

Privacy Policy

What InterfaceKit collects, how it is used, and the rights and choices available to you.

Effective
August 7, 2026
Last updated
August 7, 2026

1. Scope

This Privacy Policy applies to InterfaceKit-operated services, including interfacekit.io, blog.interfacekit.io, guides.interfacekit.io, legal.interfacekit.io, agents.interfacekit.io, related API and preview endpoints, transactional emails, protected downloads, and support communications.

It covers personal information handled when you browse, create or use an account, request a sign-in code, download protected content, use an agent key, view account usage, or contact us. It does not cover a third-party site or product merely because InterfaceKit links to or describes it.

In this policy, “InterfaceKit,” “we,” “us,” and “our” refer to the operator of the InterfaceKit service. That operator is responsible for the processing described here unless a different party is identified.

2. Sources of information

We receive information directly from you, automatically from browsers and software that connect to the service, from systems acting under your account, and from providers that help us deliver authentication, billing, hosting, security, email, and support.

3. Account and authentication information

When you request or verify a sign-in code, we process your email address, the code, delivery status, a cryptographic hash of the code, its expiry and use status, and related timestamps. A sign-in code is usable for ten minutes. Operational records can be retained beyond that period for security, troubleshooting, and legal purposes.

When an account is created, we store your normalized email address, an internal account identifier, and creation and update timestamps. Authenticated access tokens contain the account identifier and email address and expire after seven days.

For agent access, we store key-generation and lifecycle metadata and a hashed key-validation record associated with the account. The current service derives the plaintext agent key when needed rather than storing that plaintext key in the account database.

4. Browser and device information

When a browser or other client connects, InterfaceKit and its infrastructure providers may process the IP address, timestamp, hostname, requested URL or resource, request method, response status, referrer when supplied, user agent, device or browser characteristics, and security or error information.

Cloudflare may also provide coarse network and location fields such as country, data center, and network number. Standard delivery, security, and operational logs may process or retain raw IP addresses under the applicable provider configuration.

InterfaceKit collects internal operational telemetry and first-party product analytics from its deployed web applications, Workers, API, scheduled backend tasks, and telemetry collector. This includes structured logs, exceptions, selected request and navigation metadata, performance measurements, distributed traces, service version, deployment environment, application identifiers, page views, product actions, outcomes, content engagement, an operational session identifier, and a persistent anonymous analytics identifier. We use this information to operate, debug, secure, monitor, understand, and improve the service. InterfaceKit applies controls intended to redact credential fields and avoid storing direct client IP fields, but telemetry can still contain personal information included in application, provider, referrer, or URL content.

Page-view analytics include a sanitized page URL, path, referrer, and query parameters. InterfaceKit also stores first-touch and last-touch campaign attribution, including UTM source, medium, campaign, term, and content values. When supplied in a landing URL, it can also retain the allowlisted campaign click identifiers gclid, gbraid, wbraid, fbclid, msclkid, ttclid, and li_fat_id. These values are used as attribution data, not as account or browser identities.

5. Agent usage information

For a request made with a valid agent key, usage records may include the deployment environment, request hostname, account identifier, library, collection, file name, canonical resource hash when resolved, method, status, duration, country, Cloudflare data center, network number, a key-scoped hash derived from the source IP address, and a user agent truncated to 512 characters.

The plaintext agent key and raw source IP address are not written to InterfaceKit’s agent-usage Analytics Engine dataset. Cloudflare still processes the raw IP address to deliver the request, apply pre-authorization limits, and derive the scoped hash, and raw IP information may exist in separate provider or security logs.

Requests with an invalid key are not attributed to an InterfaceKit account in the agent-usage dataset. They can still generate ordinary security, rate-limit, or delivery records.

6. Communications and support

If you email or otherwise contact us, we process your contact details, message, attachments, and related correspondence. Authentication, billing-lifecycle, and support delivery records may include an email address, message type, delivery status, provider identifiers, and related timestamps.

7. Browser storage

After successful sign-in on interfacekit.io, the product stores the access token, expiry, and basic account information in browser local storage under the key “interfacekit.auth.” Logging out removes that local record. The Cookies and Local Storage Notice describes this and current practices across all InterfaceKit web properties.

After the signed-in product checks account access, it copies the access token into three cookies named “interfacekit_runtime_session.” The cookies are scoped to “/protected-runtimes,” “/src/generated-runtimes,” and “/src/generated-blueprint-runtimes,” so the browser automatically sends the token only with requests under a matching path. The cookies expire with the access token, are cleared when you log out or the product clears an invalid session, use SameSite=Strict, and use Secure on the production HTTPS service.

Each deployed InterfaceKit web application stores an operational telemetry session identifier and its last-activity time in browser local storage under the key “interfacekit.telemetry.session.” The application replaces the identifier after thirty minutes of inactivity and includes it with operational telemetry and product analytics so related activity can be understood together.

Each deployed web application also stores a first-party analytics record under the key “interfacekit.telemetry.identity.” It contains a randomly generated anonymous identifier and can contain first-touch and last-touch campaign attribution. After sign-in, the record is associated with the internal account identifier and current plan. Logging out clears that association and attribution and creates a new anonymous identifier. The record otherwise remains until you log out or clear site data.

8. Information we do not currently request

InterfaceKit does not request payment-card details through its own application forms. If you choose a paid plan, InterfaceKit sends you to Stripe Checkout, where Stripe requests and processes the payment details needed to complete the purchase. InterfaceKit receives billing identifiers and subscription state from Stripe, but the current InterfaceKit application does not receive or store the full payment-card number or security code.

InterfaceKit does not currently ask for government identifiers, precise location, health information, biometric information, or demographic profiles. Do not send sensitive personal information through support unless it is necessary and we have asked for it.

9. How we use information

  • Provide the sites, account, passwordless sign-in, downloads, APIs, libraries, and agent-readable resources.
  • Authenticate requests, issue and rotate credentials, apply plan and rate limits, and protect accounts.
  • Create and manage billing customers, checkout and customer-portal sessions, subscriptions, and plan access.
  • Deliver sign-in and billing-lifecycle emails and respond to support, privacy, and product messages.
  • Create account-scoped usage summaries and show recent agent activity.
  • Operate, debug, secure, monitor, and improve the service.
  • Detect abuse, investigate incidents, enforce our terms, and protect InterfaceKit and others.
  • Comply with legal obligations and establish, exercise, or defend legal claims.

10. Legal bases

Where applicable law requires a legal basis, we rely on performance of a contract to provide requested service features; legitimate interests in securing, maintaining, and improving the service; compliance with legal obligations; protection of vital interests where relevant; and consent for a specific use when required.

You may withdraw consent for future processing when consent is the basis. Withdrawal does not affect processing that occurred before withdrawal. Some information is necessary to provide an account or protected feature, so deleting or restricting it can require us to close or limit the account.

11. Service providers

We disclose information to providers for the operational purposes described here. A provider’s role and the terms that apply can depend on the service and data flow involved.

Cloudflare supports web delivery, Workers, storage, security, rate limiting, logs, telemetry collection, and agent request analytics. Cloudflare Email Service delivers passwordless sign-in and billing-lifecycle email. Modal hosts API compute and scheduled backend tasks. Neon hosts account, usage-summary, billing-identifier, subscription-state, billing-email delivery, operational telemetry, exception, trace, metric, and product-event records.

Stripe provides subscription checkout and the customer portal. InterfaceKit sends Stripe the account email, internal account identifier, deployment environment, selected billing period, Stripe customer identifier, and configured price. Stripe can collect payment details in Checkout or the customer portal and sends InterfaceKit billing events and customer, subscription, price, status, renewal-date, and cancellation information through its API and webhooks.

12. Other disclosures

We may disclose information when reasonably necessary to comply with law or valid legal process; respond to emergencies; investigate fraud, abuse, or security incidents; enforce agreements; or protect the rights, safety, and property of users, InterfaceKit, or others.

Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of the service. A recipient may use it only as permitted by this policy unless it gives legally required notice of a change.

We may share information at your direction or with your consent. We may also use or disclose aggregated or de-identified information where it cannot reasonably identify an individual, subject to applicable law.

13. No sale or targeted advertising

InterfaceKit does not sell personal information for money. We do not disclose personal information for cross-context behavioral advertising or use third-party advertising pixels in the current InterfaceKit application code.

If these practices change, we will update this policy and provide any notice, consent, or opt-out mechanism required by applicable law before the new practice begins.

14. Retention

We retain personal information for the time reasonably necessary for the purposes described here, including providing an account, protecting the service, keeping required business records, resolving disputes, and complying with law. Retention depends on the record, account status, security needs, provider settings, and legal requirements.

The browser access token and protected-runtime cookies expire after no more than seven days. A sign-in code expires after ten minutes, though its authentication record may remain longer. Raw agent request events, account-scoped summaries, security records, billing identifiers and subscription state, billing-email delivery records, correspondence, and backups follow schedules based on operational needs, provider settings, account status, and applicable recordkeeping requirements.

Operational telemetry, including logs, exceptions, traces, metrics, and product events, does not currently have an automatic expiration period and may be retained until InterfaceKit establishes and applies a deletion or archival schedule. Access remains limited to internal operational use.

When information is no longer needed, we take reasonable steps to delete or de-identify it, subject to backup cycles, legal holds, fraud-prevention needs, and technical constraints.

15. International processing

InterfaceKit and its providers may process information in countries other than where you live, and those countries may have different data-protection laws. Processing locations and any transfer arrangements depend on the provider, service, account configuration, and applicable law. Contact humans@interfacekit.io with questions about a specific transfer.

16. Security

We use measures intended to protect information, including hashed sign-in codes, expiring access tokens, path-scoped SameSite=Strict protected-runtime cookies, Secure cookies on the production HTTPS service, scoped agent credentials, rate limits, restricted service credentials, and limits on sensitive usage logging. No transmission or storage system is completely secure, and we cannot guarantee absolute security.

You are responsible for protecting access to your email account, browser session, and agent key and for notifying us promptly of suspected compromise.

17. Your rights and choices

Depending on where you live, you may have rights to know or access personal information; correct it; delete it; receive a portable copy; restrict or object to processing; withdraw consent; opt out of certain disclosures; appeal a decision; or complain to a data-protection authority. These rights can be limited by law.

To make a request, email humans@interfacekit.io from the address associated with the account and describe the request. An authorized agent may submit a request where local law allows it. We may verify identity and authority before acting. We will not discriminate against you for exercising a privacy right.

You can remove the local signed-in session and protected-runtime cookies by logging out or clearing site data. Clearing site data also removes the local operational telemetry session record, though a new record is created when you use the site again. These actions do not delete the account or server-side records.

18. Children

InterfaceKit is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child under 16 has provided personal information, contact humans@interfacekit.io so we can investigate and take appropriate action.

19. Changes and contact

We may update this policy as the service, providers, or law changes. We will update the stated date and provide additional notice or obtain consent when required.

Questions, privacy requests, and complaints can be sent to humans@interfacekit.io.

Questions about this document?

humans@interfacekit.io ↗
InterfaceKit

Explore

  • Kits
  • Pricing
  • Blog
  • Guides

Solutions

  • For vibe coding
  • For developers
  • For AI agents

Popular guides

  • Make UI not look AI-generated
  • Get good UI from AI
  • Prompt AI for UI design
  • Audit and fix AI-generated UI

Company

  • About
  • Contact
  • Status

© 2026 InterfaceKit. All rights reserved.

PrivacyTermsCookies