Prunekit

Privacy Policy

Effective date: July 16, 2026

Prunekit is operated by its developer as an individual based in British Columbia, Canada. This policy explains what personal information Prunekit collects from the businesses that use it, and how that information is handled. Contact for anything in this policy: derek@prunekit.com.

What Prunekit is built not to collect

Prunekit is designed so that your customers' personal data never reaches us. You register descriptions of data you hold (an entity name, a storage location label, a jurisdiction), and Prunekit tells your systems when to delete. The data itself stays with you.

Some fields you fill in are free text: entity names, descriptions, and confirmation notes. Write descriptions of data categories there, not the data itself. If you paste personal information into a free-text field, it will be stored as part of your records until you delete it.

What we collect

Account information. Your organization name, contact email, webhook URL, and any optional details you provide such as a privacy officer contact, locale, or timezone.

Credentials. API keys are stored as one-way hashes; we cannot read them back. Webhook secrets are stored encrypted.

Service records. The entities, policies, deletion jobs, audit log entries, and compliance reports your use of the API creates.

Operational records. Webhook delivery outcomes, emails we have sent you, and server logs that include IP addresses, request paths, and timestamps.

The Prunekit dashboard stores your API key in your browser's local storage so you stay signed in. We do not use advertising trackers or third-party analytics.

How we use it

We use this information to run the service: scheduling and delivering webhooks, recording confirmations, generating reports, securing the API, and sending you service email such as verification messages, failure alerts, and digests. We do not sell personal information and we do not use it for advertising.

Where your information is stored

Prunekit runs on cloud infrastructure, email delivery, and business email providers located in the United States. Your information is stored and processed there, which means it may be subject to access by authorities under United States law. A current list of our service providers is available on request.

How long we keep it

We keep your information for as long as your organization exists. Deleting your organization removes your records from the service. Server logs and email delivery records are kept only as long as needed for security and troubleshooting.

Your rights

You can export everything Prunekit holds about your organization at any time through the API, free of charge. You can correct your account details through the API and can delete your organization entirely. For anything you cannot do through the API, or to ask questions, request the service-provider list, or make a complaint, email derek@prunekit.com. Prunekit's operator is the person responsible for the protection of personal information under this policy.

If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada or your provincial privacy regulator.

Security

All API traffic is encrypted in transit. Credentials are hashed or encrypted at rest as described above, and compliance reports are cryptographically signed so tampering is detectable. No internet service can promise perfect security, but the design principle behind Prunekit is that the safest data is data we never hold.

Changes to this policy

If we change this policy in a material way, we will email registered organizations at least 30 days before the change takes effect and update the date at the top of this page.