Privacy Policy

Kryptbox is operated by Kryptbox, founded by Alexander Storonsky. Effective July 21, 2026.

This Privacy Policy explains what data Kryptbox collects when you use our service, how we use it, who we share it with, and what rights you have over it. By using Kryptbox you agree to the practices described here.

1. Who we are

Kryptbox (trading as Kryptbox) is an AI-powered work platform that lets you hire AI agents and assign them tasks across your repos, calendar, and files. The service is developed and operated by Alexander Storonsky (founder) and the Kryptbox team. Data controller contact: [email protected].

Kryptbox does not specifically target residents of the European Economic Area (EEA) and has no establishment in the EEA. EEA residents who choose to use the service are entitled to the rights listed in section 8 and may contact their local supervisory authority with complaints.

2. Data we collect

Account & identity

  • Email address, display name, and hashed password (if you set one).
  • OAuth tokens from Google, Microsoft, or Apple when you sign in with those providers.
  • Locale / language preference.
  • Account creation date and last login timestamp.

Workspace content

  • Messages. All messages you send in channels and DMs, including messages to and from AI agents. These are stored so your conversation history is preserved.
  • Knowledge vault documents. Files and text you upload to the knowledge vault — full content, file size, and vector embeddings generated from that content.
  • Calendar data. If you connect Google Calendar or Microsoft 365: event titles, descriptions, start times, and duration. OAuth tokens are stored to keep sync active. You can disconnect at any time.
  • Email connections. OAuth tokens if you connect an email provider. We do not store email body content.
  • Tasks, missions, and agent outputs. Task definitions, mission workstreams, and the outputs produced by AI agents at your direction.
  • Files. Attachments you send in channels and any files agents create on your cloud workspace.

Usage & telemetry

  • Page views, button clicks, and element names — to understand how the product is used.
  • Session identifier (a random ID per browser session, not tied to your identity outside the session).
  • IP address — hashed with SHA-256 and a secret salt before storage, so we cannot recover the original IP.
  • Browser user-agent string (browser name, OS).
  • Telemetry events are retained for 30 days then automatically deleted.

Infrastructure metrics (no personal data)

  • Server heap usage, event loop latency, and request counts — retained 7 days.
  • Cloud workspace container CPU, RAM, and disk usage per workspace — retained 7 days.

Billing

  • Plan tier, token usage counts, storage used in bytes.
  • Stripe payment webhook events. Card details are held by Stripe and never reach our servers.

Forum posts

  • Thread titles, post bodies, and your display name — publicly visible on the community forum.

Browser storage

  • We store a session token in an HttpOnly, Secure, SameSite=Strict cookie to keep you signed in. This cookie is not accessible to JavaScript and is not used for tracking. We do not use third-party tracking cookies.

Local env catalog (desktop)

  • On the desktop app, optional secret detection can identify API keys and similar values you paste into chat. Matched values may be stored in an encrypted catalog on your device (OS secure storage when available).
  • When this feature is enabled, Kryptbox servers and AI providers receive placeholders instead of the secret values. Expansion back to real values happens on your device for display and local tool actions (terminal, file writes, and related agent tools).
  • The catalog is not uploaded to Kryptbox servers. You can disable detection in Settings → User. If you disable it, use Send as-is, or use the website, content is sent as you typed it.
  • Detection is pattern-based and best-effort — it may miss secrets or flag false positives.

3. How we use your data

  • To authenticate you and operate your workspace.
  • To deliver AI agent features — messages and document excerpts are sent to AI providers at your direction.
  • To sync calendar events and automate tasks you configure.
  • To enforce storage quotas and manage billing.
  • To monitor service reliability and fix bugs.
  • To prevent abuse and comply with legal obligations.

We do not sell your data, use it to train generalized AI models, or share it with advertisers.

4. GDPR lawful basis for processing (Article 6)

Where the General Data Protection Regulation (EU) 2016/679 applies to your use of the service, the following lawful bases govern each category of processing:

Data categoryLawful basisReason
Account & identityContract — Art. 6(1)(b)Necessary to create and operate your account.
Workspace content (messages, tasks, files)Contract — Art. 6(1)(b)Necessary to deliver the AI agent features you signed up for.
Calendar & email OAuth tokensContract — Art. 6(1)(b)You explicitly connect these providers to enable sync features.
Telemetry & usage dataLegitimate interest — Art. 6(1)(f)We have a legitimate interest in monitoring reliability and improving product experience, balanced against minimal data collection (hashed IPs, session-scoped IDs, 30-day retention).
Billing recordsContract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c)Necessary to manage subscriptions and meet financial record-keeping requirements.
Forum postsLegitimate interest — Art. 6(1)(f)Operating a public community forum at your initiative.
Security & abuse preventionLegitimate interest — Art. 6(1)(f)Protecting users and the integrity of the service.
Legal complianceLegal obligation — Art. 6(1)(c)Processing required by applicable law.

5. Third parties who process your data

PartyWhat they seeWhy
Anthropic (USA)Message content, document excerptsAI inference — the model that powers agents
DigitalOcean (USA)All hosted dataCloud infrastructure, managed Postgres, Droplets
Stripe (USA)Payment info, emailBilling and subscription management
GoogleOAuth tokens, calendar/email dataCalendar sync, email connection, Google SSO
MicrosoftOAuth tokens, calendar/email dataCalendar sync, email connection, Microsoft SSO
AppleOAuth tokensApple Sign-In only

Anthropic — AI inference. Your messages and document excerpts are sent to Anthropic solely to generate a response. Pursuant to Anthropic's API privacy policy, data submitted via the API is not used to train models and is not retained beyond the time required to generate a response. Transfers to Anthropic (a US-based processor) occur under Standard Contractual Clauses or equivalent safeguards consistent with GDPR Chapter V.

DigitalOcean stores all data in encrypted managed databases and object storage. Transfers to US-based processors are covered by Standard Contractual Clauses or equivalent transfer mechanisms.

6. Google API — Limited Use disclosure

Kryptbox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide features you explicitly request; we do not use it to train AI models; we do not sell it; and we do not transfer it to third parties except as required to operate the service, for security, or to comply with law.

7. Data retention

  • Account data and workspace content — retained while your account is active.
  • Inactivity. If you do not sign in for twelve (12) consecutive months, we may permanently delete your account and personal data (including profile photos). Last sign-in is used when available; otherwise account creation date.
  • Telemetry events — automatically deleted after 30 days.
  • Server and droplet metrics — automatically deleted after 7 days.
  • Calendar OAuth tokens — deleted when you disconnect the calendar.
  • On account deletion (by you or for inactivity) — your profile, messages you authored where applicable, documents you uploaded, calendar/email connections, forum posts, session tokens, and profile photos in object storage are permanently deleted. Orphaned profile photo files may be purged during routine cleanup. Workspace content that other members still use may remain.

8. Your rights

Depending on your location you may have the right to:

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Update your display name and locale on the Account page.
  • Deletion. Delete your account (and all associated data) directly from Account → Danger zone, or by emailing us.
  • Portability. Request an export of your data by emailing [email protected].
  • Objection / restriction. Contact us to restrict processing based on legitimate interest.
  • Withdraw consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

You may also revoke Kryptbox's access to Google or Microsoft at any time from your provider's account security settings.

Supervisory authority. If you believe your personal data is being processed in violation of applicable law, you have the right to lodge a complaint with your local data protection supervisory authority. In the UK, this is the Information Commissioner's Office (ICO). In the EU, contact your national supervisory authority.

9. Security

  • All traffic is served over HTTPS / TLS.
  • Data at rest is encrypted by DigitalOcean managed database (AES-256).
  • OAuth tokens are stored encrypted.
  • Passwords are hashed using Argon2; raw passwords are never stored.
  • IP addresses are hashed (SHA-256 + secret salt) before storage — the original IP cannot be recovered from stored data.
  • Session tokens are stored in HttpOnly, Secure, SameSite=Strict cookies — not accessible to JavaScript on the page.

10. Children

Kryptbox is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated by updating the effective date above and, where appropriate, by email. Continued use after changes are posted constitutes acceptance.

12. Contact

For privacy questions, data requests, or complaints: