What Kitana Lite collects, why it needs it, and what it never does with it.
What we collect
Kitana Lite collects three things to do the job you asked it to do:
- Your email address, so we can sign you in and send you the report you asked for. Sign-in is a one-time code, so we never hold a password.
- Your brand sources (the guideline file you upload or the website you point us at), so the agent knows what your brand is supposed to look like.
- The creatives you submit for review, and the scores and findings produced from them.
Alongside those, we record how the product is used(which steps of a review you reached, whether it succeeded or failed, and how long it took) and error reports when something breaks. These carry a review ID, not your name. Where we need to tell a company signup from a personal one we keep the domain of your email address, never the address itself.
For each device you are signed in on we keep a rough description of it, something like “Chrome on macOS”, so you can recognise your own sessions on the Account page and end any you do not recognise. We do not store the full identifying string your browser sends, only a one-way fingerprint of it and that short label, and we do not store your IP address against your session.
We do not collect analytics about you from other sites, we do not record your screen or your keystrokes, and we do not buy data about you from anyone. Usage measurement is kept in the tab you are using and is not written to your device, so there is nothing here to opt out of storing.
How we use it
Your brand sources and creatives are used to run the reviews you start, and to show you your own history. They are not used to train any model, and they are never shown to another customer.
Who else sees it
A small number of processors handle parts of the job. Each sees only what that part needs:
- Stripe: payments. Card details go to Stripe directly; we never hold them.
- Our model provider: the review itself. Assets and brand rules are sent to be scored.
- Our email provider: sign-in codes and finished reports.
- Our product-analytics provider: which steps of a review were reached, and whether it finished. It receives a review ID, your workspace's name and your email's domain, and for a paid plan which plan it is and what each payment, top-up or refund came to. It does not receive your email address, your card details, your brand sources or your creatives.
- Our error-monitoring provider: the technical details of a failure, plus any bug report you choose to send from inside the product, so we can fix it. Web addresses are stripped of anything after the
?before they are sent. Automatic error reports remove email addresses and never include request contents. In-product bug reports include only what you type, the page path, and browser details. They do not include screenshots or uploaded work.
If you connect Slack or an MCP client, reviews you start from there are visible to whoever can see that channel. That is the point of the integration, and it is worth knowing before you connect a shared channel.
An AI app you connect over MCP, such as Claude, ChatGPT or Cursor, is run by its own provider, not by us, and is not one of our processors. You choose to send it work: the images you ask it to review pass through it on their way to us, and the results it asks for (scores, findings, the brand kit used) are sent back to it. What that provider does with them is governed by its own terms. A connection reaches only the workspace you picked when you connected it, and you can disconnect it at any time from Account, then Integrations.
How long we keep it
Reviews and brand kits stay until you delete them or close your account. Deleting a brand kit deletes the rules extracted from it. Closing your account removes your assets and reviews. If you run a scan without an account and never sign in to claim it, the files you uploaded are deleted after 24 hours.
Your choices
You can delete a brand kit or a review at any time from inside the product, and you can ask us to delete your account and everything under it. Ask, and we will confirm when it is done.
Contact
Questions about any of this go to admin@replikit.ai, and a person reads them.