Privacy Policy

UXKIN collects as little personal information as it can. This page explains what we collect, why, how long we keep it and what you can do about it.

Last updated October 4, 2026

UXKIN (“UXKIN”, “we”, “us”) operates uxkin.com. Questions about this policy: support@uxkin.com.

What we collect

If you browse without an account

  • Server logs. Like most websites, our hosting provider records technical request data such as IP address, browser type, the page requested and the time. These logs are used to run and secure the service.
  • Analytics. Google Analytics records which pages you visit, roughly where from (country or city), your device and browser type, how you found UXKIN, and a few actions: signing up, buying a plan (which plan and its price) and copying an agent prompt, never your email or name. We don't use advertising pixels or advertising cookies. Visits from Albania are not counted: to tell, your browser asks Cloudflare which country it is in, and remembers the answer on your device.

If you create an account

  • Email address and, optionally, a name. Used to identify your account and contact you about it. We also note whether you have verified your email address (by signing in with Google or completing a password reset). If you create an account and don't choose a plan, we send one reminder email about a day later, and never again.
  • Password. Stored only as a one-way hash (bcrypt). We cannot see your password.
  • Google sign-in. If you continue with Google, we receive your email address, your name and a Google account ID, and link them to your UXKIN account. We never receive your Google password.
  • Sessions. When you log in we set one essential cookie and keep a hashed record of the session so you stay logged in. See the Cookie Policy.
  • Collections and saved items you create.
  • Password reset links. If you ask to reset your password, we email you a single-use link and store only a hash of it. It expires after 60 minutes.
  • Plan status: whether you have full access, which plan, and its renewal date, received from our payment provider.
  • Agent tokens you generate for the Agent SDK. We store a one-way hash to check the token, and an encrypted copy so you can see your setup prompt again. We also record when a token was last used. Resetting a token disables it immediately and deletes its encrypted copy.
  • Support requests: the category, subject and message you send us through the support form, and the replies between you and us, linked to your account. New messages are also sent by email (to our support inbox, or to you when we reply).

Security records

To stop password guessing, automated sign-ups and other abuse, we keep short-lived counters of login, sign-up, password, download, search and agent requests. They are keyed by a keyed hash of the IP address, email, account or token involved, so they don't contain any of these in readable form, and they are deleted automatically, usually within a few days.

How we use it

  • To provide your account, collections and agent access.
  • To keep UXKIN secure, prevent abuse and fix problems.
  • To respond when you contact us.
  • To comply with legal obligations.

We do not sell or rent personal information, share it for targeted advertising, or use it to build advertising profiles.

Legal bases (EU and UK visitors)

  • To provide the service you asked for (performance of our contract with you): your account, collections, agent tokens, plan status and support requests.
  • Our legitimate interest in keeping UXKIN secure and working: server logs, security counters and essential cookies.
  • Our legitimate interest in understanding how UXKIN is used: Google Analytics. You can object at any time by blocking cookies for uxkin.com or with Google's Google Analytics opt-out add-on.
  • Legal obligations: for example tax and accounting records kept by our payment provider, and responding to lawful requests.

An email address is needed to create an account; everything else you give us is optional. We don't make decisions about you based solely on automated processing.

Service providers

We rely on a small number of providers who process data on our behalf, only to run UXKIN:

  • Render: application hosting and our database.
  • Cloudflare: DNS for uxkin.com (and, where enabled, protecting and speeding up traffic to it), and storage and delivery of images and videos from media.uxkin.com.
  • Resend (which uses Amazon Web Services): account emails, such as password reset links, emails about support requests, and receiving email replies to them so they can be added to the conversation.
  • Polar: payments for full access, as our merchant of record. Polar collects your payment details directly; we never see or store card numbers. At checkout we send Polar your UXKIN account ID and, if verified, your email address. Opening Billing creates a Polar customer record, even if you haven't bought anything, with your account ID, email address and name (if you gave one). We receive your plan status and a customer ID. Deleting your UXKIN account doesn't delete that Polar record; email us and we'll ask Polar to remove what the law allows.
  • Google: if you choose Continue with Google, to sign you in; and Google Analytics, to count visits and show which pages are used. Google signals and ad personalisation are turned off, and Google Analytics doesn't log or store IP addresses.
  • SiteGround: hosts our email inboxes (support@ and dmca@uxkin.com), so emails you send us, and support requests forwarded to us, are stored there.

We may also disclose information if required by law, to protect the rights and safety of UXKIN and its users, or as part of a merger or sale of the service (in which case this policy will continue to apply to your information).

How long we keep it

  • Account data: until you delete your account.
  • Sessions: up to 30 days, or until you log out. Expired sessions are deleted automatically.
  • Support requests: until you delete your account, or earlier if you ask us to delete them. Copies may remain in our support mailbox.
  • Agent tokens: the encrypted copy of a token is deleted as soon as you reset it; the rest of the record is kept until you delete your account.
  • Security counters: usually a few days.
  • Password reset records: deleted within about a day after they expire or are used.
  • Server logs: for the limited period our hosting provider retains them.
  • Google Analytics data: up to 14 months, then deleted by Google automatically.
  • Payment records (orders, invoices) are kept by Polar as merchant of record, for as long as tax and accounting law requires.
  • Backups of our database may keep deleted data for a short period until they're overwritten.

Your choices and rights

  • Delete your account at any time in Account settings, or, if your account doesn't have a plan, by emailing support@uxkin.com from the address on the account. This permanently deletes your account, collections, saved items, agent tokens, sessions, support requests and any Google sign-in link. If you have a monthly subscription, cancel it first in Billing; records Polar keeps as merchant of record (such as invoices) aren't affected.
  • Change your password or log out other devices in Account settings.
  • Access or correct your information by emailing support@uxkin.com.

Depending on where you live (for example California, the European Union or the United Kingdom), you may have additional rights: to access, correct or delete your personal information, to receive a copy of it, to restrict or object to certain processing, and to withdraw consent where we rely on it. Email support@uxkin.com to make a request; we'll respond within one month and won't treat you differently for exercising your rights. We may need to confirm your identity before acting on a request.

You also have the right to complain to a data protection authority, such as the one where you live or work.

International visitors

Our service providers process data in the United States and other countries. Where the law requires it, these transfers are covered by the safeguards in our providers' data processing terms, such as the European Commission's Standard Contractual Clauses.

Security

We use HTTPS, hashed passwords and session tokens, hashed and encrypted agent tokens, rate limiting and other safeguards. No system is perfectly secure, so please use a unique password for UXKIN.

Children

UXKIN is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, email support@uxkin.com and we will delete it.

Changes

If we change this policy, we will update the date at the top of this page. Significant changes will be highlighted on the site.