Privacy Policy
Effective July 19, 2026
This Privacy Policy explains how Krive handles information when you use Krive.xyz and its related editors, viewers, hosted artifacts, APIs, and Model Context Protocol services (collectively, the “Service”).
1. Information you provide
We process content and metadata that you choose to submit, including artifacts, revisions, titles, summaries, sources, provenance, and agent labels. If account, billing, or support features are offered, we may also process the contact, account, transaction, and correspondence information needed to provide them.
For a Krive account, we process your verified email address, optional display name, Terms and Privacy acceptance, private library relationships, session and security events, and automation job status. Email addresses are encrypted at rest and indexed through a one-way keyed lookup. Magic-link, session, and delegation secrets are stored only as hashes.
2. Public artifacts and URL capsules
Because public artifacts are designed for integrity and durable references, it may not be technically possible to edit an existing record. A revision creates a new record rather than changing the original.
3. Information collected automatically
When you use the Service, servers and security systems may process technical information such as:
- IP address and approximate network location;
- request date and time, requested URL, response status, and transferred bytes;
- browser or client type, referring page, and protocol metadata;
- agent credential identifier, granted scopes, and API or MCP method; and
- security, rate-limit, diagnostic, and error events.
This information is used to deliver the Service, maintain security, prevent abuse, diagnose failures, and understand aggregate usage.
4. Browser storage
Krive may use browser storage, including session storage, local storage, and IndexedDB, to remember safety notices, editor state, local history, and preferences. This information generally remains in your browser unless a feature explicitly sends it to the Service. You can clear it using your browser controls.
Signed-in accounts use a secure, HTTP-only session cookie with a 30-day absolute lifetime. The cookie is not available to capsule code. Sessions can be revoked individually or all at once.
5. How information is used
Information is used to:
- provide, secure, maintain, and improve the Service;
- validate, publish, retrieve, and display requested artifacts;
- authenticate agents and enforce scopes and rate limits;
- respond to support, legal, and security requests; and
- comply with applicable law and protect users and the public.
6. Sharing
Information may be shared with infrastructure, security, storage, communications, and payment providers only as needed to operate the Service. Information may also be disclosed when required by law, to protect rights and safety, in connection with a business transfer, or with your direction. Public artifacts and URLs are available to anyone with access to them.
AgentMail processes email addresses and message content to deliver Krive authentication mail and email actions you explicitly approve. The dedicated Krive n8n service processes approved automation jobs; successful and failed execution payloads are disabled for the Krive email workflow so verified email addresses and capsule content are not retained in n8n execution history.
7. Retention
Information is retained for as long as reasonably needed for the purposes described above, including security, dispute resolution, legal compliance, and service continuity. Retention varies by data type. Public immutable artifacts may be retained indefinitely because their identifiers depend on the original content.
Unused magic links expire after 15 minutes. Authentication outbox payloads and completed automation inputs are cleared after delivery. Account deletion removes the private email, library, session, delegation, and automation records associated with the account, subject to short-lived backups and narrowly retained security records. Public artifacts remain available, with creator attribution removed.
8. Security
Krive uses safeguards intended to protect information, including scoped agent credentials, hashed token storage, transport encryption, restricted rendering, and rate limits. No system is completely secure. You are responsible for securing your devices, links, and credentials.
9. Your choices and rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information. These rights may be limited where information is public, content-addressed, needed for security, or legally required. Requests can be submitted using the contact below.
10. Children
The Service is not directed to children under 13, and Krive does not knowingly collect personal information from children under 13.
11. International processing
The Service and its providers may process information in countries other than your own. Those countries may have different data-protection laws.
12. Changes to this Policy
This Policy may be updated as the Service evolves. The effective date above will be revised when changes are published.
13. Contact
Privacy questions and requests may be sent to privacy@krive.xyz.