Privacy Policy
What InterfaceKit collects, how it is used, and the rights and choices available to you.
- Effective
- July 27, 2026
- Last updated
- July 27, 2026
1. Scope
This Privacy Policy applies to InterfaceKit-operated services, including interfacekit.io, blog.interfacekit.io, guides.interfacekit.io, legal.interfacekit.io, agents.interfacekit.io, related API and preview endpoints, transactional emails, protected downloads, and support communications.
It covers personal information handled when you browse, create or use an account, request a sign-in code, download protected content, use an agent key, view account usage, or contact us. It does not cover a third-party site or product merely because InterfaceKit links to or describes it.
In this policy, “InterfaceKit,” “we,” “us,” and “our” refer to the operator of the InterfaceKit service. That operator is responsible for the processing described here unless a different party is identified.
2. Sources of information
We receive information directly from you, automatically from browsers and software that connect to the service, from systems acting under your account, and from providers that help us deliver authentication, hosting, security, and support.
3. Account and authentication information
When you request or verify a sign-in code, we process your email address, the code, delivery status, a cryptographic hash of the code, its expiry and use status, and related timestamps. A sign-in code is usable for ten minutes. Operational records can be retained beyond that period for security, troubleshooting, and legal purposes.
When an account is created, we store your normalized email address, an internal account identifier, and creation and update timestamps. Authenticated access tokens contain the account identifier and email address and expire after seven days.
For agent access, we store key-generation and lifecycle metadata and a hashed key-validation record associated with the account. The current service derives the plaintext agent key when needed rather than storing that plaintext key in the account database.
4. Browser and device information
When a browser or other client connects, InterfaceKit and its infrastructure providers may process the IP address, timestamp, hostname, requested URL or resource, request method, response status, referrer when supplied, user agent, device or browser characteristics, and security or error information.
Cloudflare may also provide coarse network and location fields such as country, data center, and network number. Standard delivery, security, and operational logs may process or retain raw IP addresses under the applicable provider configuration.
5. Agent usage information
For a request made with a valid agent key, usage records may include the deployment environment, request hostname, account identifier, kit, collection, file name, canonical resource hash when resolved, method, status, duration, country, Cloudflare data center, network number, a key-scoped hash derived from the source IP address, and a user agent truncated to 512 characters.
The plaintext agent key and raw source IP address are not written to InterfaceKit’s agent-usage Analytics Engine dataset. Cloudflare still processes the raw IP address to deliver the request, apply pre-authorization limits, and derive the scoped hash, and raw IP information may exist in separate provider or security logs.
Requests with an invalid key are not attributed to an InterfaceKit account in the agent-usage dataset. They can still generate ordinary security, rate-limit, or delivery records.
6. Communications and support
If you email or otherwise contact us, we process your contact details, message, attachments, and related correspondence. Authentication-delivery and support logs may include an email address and provider delivery identifiers.
7. Browser storage
After successful sign-in on interfacekit.io, the product stores the access token, expiry, and basic account information in browser local storage under the key “interfacekit.auth.” Logging out removes that local record. The Cookies and Local Storage Notice describes this and current practices across all InterfaceKit web properties.
8. Information we do not currently request
InterfaceKit does not currently ask for payment-card details, government identifiers, precise location, health information, biometric information, or demographic profiles. Do not send sensitive personal information through support unless it is necessary and we have asked for it.
If paid checkout or another feature begins collecting additional categories of personal information, we will update this policy before or when that collection begins as required.
9. How we use information
- Provide the sites, account, passwordless sign-in, downloads, APIs, libraries, and agent-readable resources.
- Authenticate requests, issue and rotate credentials, apply plan and rate limits, and protect accounts.
- Deliver sign-in emails and respond to support, privacy, and product messages.
- Create account-scoped usage summaries and show recent agent activity.
- Operate, debug, secure, monitor, and improve the service.
- Detect abuse, investigate incidents, enforce our terms, and protect InterfaceKit and others.
- Comply with legal obligations and establish, exercise, or defend legal claims.
10. Legal bases
Where applicable law requires a legal basis, we rely on performance of a contract to provide requested service features; legitimate interests in securing, maintaining, and improving the service; compliance with legal obligations; protection of vital interests where relevant; and consent for a specific use when required.
You may withdraw consent for future processing when consent is the basis. Withdrawal does not affect processing that occurred before withdrawal. Some information is necessary to provide an account or protected feature, so deleting or restricting it can require us to close or limit the account.
11. Service providers
We disclose information to providers only for defined operational purposes and subject to their applicable contractual and legal obligations. Current providers are listed on the Subprocessors page.
Cloudflare supports web delivery, Workers, storage, security, rate limiting, logs, and agent request analytics. Modal hosts API compute and scheduled backend tasks. Neon hosts the account and usage-summary database. Resend delivers passwordless sign-in email.
12. Other disclosures
We may disclose information when reasonably necessary to comply with law or valid legal process; respond to emergencies; investigate fraud, abuse, or security incidents; enforce agreements; or protect the rights, safety, and property of users, InterfaceKit, or others.
Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of the service. A recipient may use it only as permitted by this policy unless it gives legally required notice of a change.
We may share information at your direction or with your consent. We may also use or disclose aggregated or de-identified information where it cannot reasonably identify an individual, subject to applicable law.
13. No sale or targeted advertising
InterfaceKit does not sell personal information for money. We do not disclose personal information for cross-context behavioral advertising or use third-party advertising pixels in the current InterfaceKit application code.
If these practices change, we will update this policy and provide any notice, consent, or opt-out mechanism required by applicable law before the new practice begins.
14. Retention
We retain personal information for the time reasonably necessary for the purposes described here, including providing an account, protecting the service, keeping required business records, resolving disputes, and complying with law. Retention depends on the record, account status, security needs, provider settings, and legal requirements.
The browser access token expires after seven days. A sign-in code expires after ten minutes, though its authentication record may remain longer. Raw agent request events in Cloudflare Analytics Engine are intended to be retained for about three months. Account-scoped summaries, security records, correspondence, and backups may follow different schedules.
When information is no longer needed, we take reasonable steps to delete or de-identify it, subject to backup cycles, legal holds, fraud-prevention needs, and technical constraints.
15. International processing
InterfaceKit and its providers may process information in countries other than where you live. Those countries may have different data-protection laws. Where required, we rely on appropriate contractual, organizational, or legal safeguards for international transfers.
16. Security
We use measures intended to protect information, including hashed sign-in codes, expiring access tokens, scoped agent credentials, rate limits, restricted service credentials, and limits on sensitive usage logging. No transmission or storage system is completely secure, and we cannot guarantee absolute security.
You are responsible for protecting access to your email account, browser session, and agent key and for notifying us promptly of suspected compromise.
17. Your rights and choices
Depending on where you live, you may have rights to know or access personal information; correct it; delete it; receive a portable copy; restrict or object to processing; withdraw consent; opt out of certain disclosures; appeal a decision; or complain to a data-protection authority. These rights can be limited by law.
To make a request, email humans@interfacekit.io from the address associated with the account and describe the request. An authorized agent may submit a request where local law allows it. We may verify identity and authority before acting. We will not discriminate against you for exercising a privacy right.
You can remove the local signed-in session by logging out or clearing site data. That action does not delete the account or server-side records.
18. Children
InterfaceKit is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child under 16 has provided personal information, contact humans@interfacekit.io so we can investigate and take appropriate action.
19. Changes and contact
We may update this policy as the service, providers, or law changes. We will update the stated date and provide additional notice or obtain consent when required.
Questions, privacy requests, and complaints can be sent to humans@interfacekit.io.
Questions about this document?
humans@interfacekit.io