kisenon

Privacy Policy

Effective 2026-07-10 · v2 · Supersedes v1 (2026-05-23)

1. Who we are

The Kisenon service (the “Service”) is operated by Seiraiyu LLC, a Georgia, USA limited liability company. This Privacy Policy explains what data we collect about you, how we use it, who we share it with, and the choices and rights you have. Where you use the Service to process personal data of your own users, we act as your processor — see our Data Processing Addendum.

2. What we collect

Account data, from your identity provider. When you sign in via Google or GitHub we receive: your email address, your name, your avatar URL, and the provider-issued user identifier.

Service usage data. The names and metadata of the projects, branches, and database endpoints you create; the audit log entries describing operations you take (operation type, timestamp, actor, target resource); connection metadata (timestamp, source IP) retained for security and abuse response.

Billing data. For paid plans, the usage we meter (compute time, storage, data transfer) and the billing contact and payment details you provide, which are processed by our payment processor. We do not store full card numbers ourselves.

Your database contents. The rows you store in the Postgres branches we host on your behalf. We treat these as customer data, not as analytics input or training input.

What we do not do. We do not run third-party analytics, advertising pixels, session-replay scripts, or cross-site trackers on this site or the console. We do not sell or rent your personal data.

3. How we use it

  • To provide, secure, and operate the Service.
  • To meter usage and bill paid plans.
  • To send transactional email (security alerts, billing, material changes to legal terms).
  • To compute aggregate, non-identifying usage statistics for capacity planning.
  • To investigate abuse, fraud, and security incidents.
  • To comply with legal obligations.

4. Sub-processors and disclosure

We share data with the sub-processors and recipients listed in our Data Processing Addendum, which we keep current. In summary:

  • Cloud infrastructure providers — Google Cloud (data-plane compute and object storage in the United States) and Amazon Web Services (the global control plane, secrets, and email) host the Service.
  • Identity providers (Google, GitHub) — for OAuth sign-in. These vendors see your sign-in request and return your basic profile to us.
  • Payment processor — for paid plans, to process payments and manage subscriptions.
  • Legal process — when compelled by law. We will notify you unless legally prohibited.

We do not sell your personal data. We do not share it with advertisers.

5. Where your data lives

Your database contents are hosted in the United States. Tenant data (database pages and archived write-ahead log) is stored in Google Cloud Storage in the US (us-central1) on versioned buckets; the control-plane metadata that describes your projects is hosted on our global control plane on Amazon Web Services in the US. All storage is encrypted at rest by the cloud provider. If we add a data region outside the United States we will update this page before any of your data is stored there.

6. How long we keep it

  • Database contents and project metadata: while your account is active and for 30 days after deletion (grace period).
  • Snapshots: for the retention window of your plan (currently 7 days on the free tier and up to 365 days on paid plans).
  • Audit log entries: 2 years from the event; entries under legal hold are retained until the hold is lifted.
  • OAuth refresh tokens: rotated on a 12-hour window; access tokens are rotated approximately every 15 minutes.
  • Aggregate usage statistics: indefinitely, in non-identifying form.

7. Your rights

You may request that we:

  • Confirm whether we hold data about you and disclose what we hold.
  • Provide an export of your account data in a portable format.
  • Correct inaccurate data.
  • Delete your account and the data associated with it (subject to legal retention requirements; audit records under legal hold are anonymized rather than deleted).

Email legal@seiraiyu.com from the email address on your account. We respond within 30 days. We are not currently SOC 2, ISO 27001, GDPR-certified, or CCPA-certified, but we honor the analogous rights as a matter of policy.

8. Security

All customer-facing connections — the web console, the control-plane API, and your Postgres connections — are encrypted in transit with TLS using publicly trusted (Let’s Encrypt) certificates. Data at rest is encrypted at the storage layer by the cloud provider. API keys and service tokens are stored only as one-way hashes. Production access is restricted to named operators, and security-relevant actions are recorded in an audit log. In the event of a confirmed personal-data breach affecting you, we will notify you without undue delay and, where we act as your processor, in line with the timelines in our Data Processing Addendum.

9. Cookies

We use only first-party session cookies necessary to operate the Service: authentication cookies issued by NextAuth.js, and a kisenon_tos_accepted cookie that records that you have accepted these Terms. We do not use analytics cookies, advertising cookies, or third-party tracking cookies.

10. Children

The Service is not directed to children under 13 and we do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this Policy

We may update this Privacy Policy from time to time. For material changes we will notify you by email or in-app at least 14 days before the change takes effect. The current version is identified at the top of this page.

12. Contact

Seiraiyu LLC · Georgia, USA · legal@seiraiyu.com

Seiraiyu LLC · Georgia, USA · legal@seiraiyu.com
Terms · Privacy · DPA · Open Source