Privacy policy
7 October 2026
This policy covers Kaloko at kaloko.app, its hosted application and its integrations. Contact support@sinfin.cz about your personal data.
Who is responsible
Kaloko is operated by Sinfin s.r.o., company ID 45800171, Písnická 763/29, 142 00 Prague 4, Czech Republic. Sinfin is responsible for personal data used to manage accounts, operate and secure the service, provide support and handle billing.
Your organization decides which people, screenshots, recordings and other work it puts into Kaloko and who can see them. For personal data in that content, Sinfin processes the data on the organization’s instructions. Ask your organization’s administrator about its purposes and permissions; a data processing agreement is available from support@sinfin.cz.
Google sign-in and Workspace domain verification
Public pages may load Google Identity Services to offer sign-in with an account already known to your browser. Loading this component sends Google technical connection data, such as your IP address and browser information. Google or your browser controls whether the account prompt appears; Kaloko receives your identity after you choose to continue. For a new account, you then confirm the organization you want to create. The browser-bound sign-up proof is valid for ten minutes and is removed when used or during expired-state cleanup.
If you choose Google, Kaloko requests only openid, email and profile. Google provides an account identifier, your email address and its verification status, and may provide your name and profile picture. For a managed account it also provides the Workspace domain. Kaloko uses the identifier and verified email to connect your sign-in to a Kaloko account, and the managed domain to check eligibility to join an organization or to verify a domain you asked to verify.
Kaloko stores the account identifier, email, verification status, managed domain when present, display value and the dates the identity was connected and used. The current Google connection uses your email as its display value; it does not store your Google profile picture. The sign-in token is checked to establish your identity; Google access tokens and refresh tokens are not kept as account credentials.
This connection does not request access to Gmail messages, Drive files, calendars or contacts. Google sign-in data is not used for advertising, sold, or passed to AI evaluators to develop, improve or train generalized AI or machine-learning models. Kaloko’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
The stored identity is processed on Cloudflare as part of Kaloko’s database and backups. Your account email may also be used to deliver the service emails you request or enable through Resend and to identify you to authorized members of your organization. We do not share Google sign-in data with unrelated third parties for their own marketing.
Other information Kaloko processes
Account and team information includes your email, organization and project memberships, roles, invitations, preferences and connected sign-in methods. GitHub sign-in uses your GitHub account identifier, profile and verified email addresses. An organization’s own identity provider supplies the claims needed for its configured sign-in.
Work content includes the runs you upload, screenshots, captured pages, recordings, design files, questions, evaluation results, comments and approval records. It can contain personal data visible in the application you test. Use test data and the masking tools before uploading personal information.
Technical and security records include request information, IP address, browser or device information, sign-in events, audit events, usage counts and error reports. Billing records include the billing contact, organization, tax details and subscription status. Card details go directly to Stripe. If you contact support, we process your message and the information you provide.
Why we use these data
We use these data to sign you in, apply permissions, host and display your work, record reviews, send requested notifications, operate connected integrations, charge for paid plans, answer support requests and prevent abuse. We use usage and website measurements to understand how the service is used and improve it.
Depending on the purpose and your relationship with us, processing is necessary to provide the requested service under a contract, to meet legal obligations such as accounting, or for our legitimate interests in secure operation, support and service improvement. Where we rely on consent, you can withdraw it. Choosing an optional integration does not grant it access beyond the permissions and content you authorize.
Who can receive data
Authorized people in your organization and projects can see content according to their roles. Public sharing makes the selected content available to anyone with access to the public link. Organization administrators manage memberships and can inspect the audit information available to their plan.
Cloudflare hosts the application, database, files and hosted browsers. Resend delivers emails and receives recipient addresses and message content. Stripe processes payments and billing information. Our Sentry monitoring receives error reports; the application removes email addresses, URL query strings, user context, request bodies, cookies and headers from its error events before sending them.
When hosted AI evaluation is used, Anthropic receives the screenshot or crop and the evaluation question for vision evaluation; TypeSafe receives a reduced text outline with email addresses and tokens masked for semantic evaluation. When an organization enables the Clef experiment, Cloudflare Workers AI receives screenshots and selected recording frames. These are evaluation inputs from your work, not an export of your Google sign-in profile.
Slack, Teams, Jira, Linear, GitHub, an identity provider or a SIEM receive the information needed for the integrations your organization connects. We may disclose data when required by law or necessary to address abuse and protect the service. We do not sell personal data or use Google user data for targeted advertising.
Storage and protection
For the standard hosted service, the operator is in the Czech Republic, but Cloudflare chooses the data centers and Kaloko does not promise storage only in the EU. Our providers may process data outside your country. Where personal data are transferred outside the EEA, the applicable data-protection requirements and transfer safeguards must be met; contact us for the arrangements that apply to your organization.
For Enterprise, an arrangement to store customer content in the EU can be agreed following a technical assessment. Before an agreement is made, we confirm availability, the data and services covered, including backups, and the processing conditions. Restricting all processing to the EU requires a separate assessment of AI features, integrations and other providers; it is not automatically included in the Enterprise plan.
Connections use HTTPS and Cloudflare encrypts stored database and file data at rest. Kaloko applies organization and project access controls, hashes sign-in session and API tokens, and encrypts stored integration secrets. Access for support and operations is limited to what is needed to provide and protect the service.
Retention and deletion
A connected Google identity stays in your account until you disconnect it or it is removed as part of an account-deletion request. Disconnecting it removes the identity link, not your organization memberships, comments, approval history or security audit records. Removing Kaloko in your Google Account stops that Google authorization; it does not by itself delete data already held by Kaloko.
Uploaded runs follow their expiry dates and your plan’s retention settings, normally 30 days unless another expiry or retention rule applies. Kept, accepted or reference runs can be retained longer according to the plan and settings. Runs moved to the trash can normally be restored for seven days before their files are purged. Backups are separate from the live service and deleted data may remain in them until their retention period ends.
Account, support, billing and security records are retained as needed for the service, legal obligations and the establishment or defence of claims. The audit log normally retains events for 730 days; specified approval and evidence events remain longer while the related run exists. Contact support@sinfin.cz to request deletion or the retention details for your data; we will explain any records that must remain and why.
Your choices and requests
You can manage sign-in methods in Settings → Profile, disconnect Google there, and revoke its authorization in your Google Account. If it is your last permitted sign-in method, connect another method first. Manage email preferences and signed-in devices in Settings. Your organization manages project access and shared work.
Write to support@sinfin.cz to request access, correction, deletion, restriction or portability of your personal data, or to object to processing where the applicable law provides that right. We may need to verify your identity and involve the organization responsible for the content. You can also complain to your data-protection authority; in the Czech Republic this is the Office for Personal Data Protection (ÚOOÚ).
Cookies and website measurement
Kaloko uses cookies for sign-in and to remember language and display preferences. It also sets the first-party cookies kl_v and kl_utm for 30 days to remember the homepage headline variant, campaign parameters and first landing page. If you create an organization, that attribution is stored with it. These values are not used for advertising or shared for third-party marketing. Cloudflare Web Analytics measures website use without analytics cookies. Browser settings let you remove or block cookies; blocking sign-in cookies prevents signing in.
Changes to this policy
We publish changes on this page with an updated date. If we change how we use Google user data or make another material change, we will notify affected users before the change takes effect and request consent where required.