kywrdkywrd, five characters

What we collect, and why.

Headline: 25 of 30 characters

Specific to kywrd's own architecture, not boilerplate.

Draft — pending legal review

This is a pre-launch draft. It has not been reviewed by a lawyer and should not be relied on as a final privacy commitment until it has been.

What we collect

When you sign in, we get what Google’s sign-in flow provides: your email address, name, and avatar image. Beyond that, we store which organization you belong to, the apps and keywords you choose to track, and the observations kywrd derives from tracking them — rank positions, listing snapshots, competitor diffs, and the recommendations kywrd generates.

We do not collect data about your app’s own end users. kywrd has no SDK to embed in your app, does not access your app’s analytics, crash reports, or any user-level data. kywrd only ever reads what is on a public store listing page and what you explicitly choose to track.

We do not sell your data

kywrd does not sell your data to anyone, for any reason. We do not share it with anyone beyond the subprocessors listed below, and each of those is there to help run kywrd itself — none of them is an advertiser, a data broker, or a third party we share your information with for their own use.

Where it's stored

Account, organization, keyword, and rank data live in a Postgres database (Supabase) that kywrd’s dashboard and API query directly. Raw pulls from each store — the actual scraped listing pages and search results — are written first to Cloudflare R2 as append-only snapshots, one per app per store per day. That R2 archive, not the database, is the source of truth for your history: if we ever change how the database is structured, we rebuild it from these snapshots rather than re-scraping the stores.

All of it is stored and processed in the United States — we do not maintain infrastructure elsewhere.

Measured vs. modeled, in your data too

The same provenance discipline the product shows you applies to what we store. Every keyword metric we save carries one of these labels, permanently attached to the number:

  • measuredPublished by the store. Not our estimate.published by the store — Apple search popularity, for example.
  • modeledOur estimate. Google publishes no search volume, so this is a model.our estimate, most notably Google Play search volume, which Google does not publish.
  • heuristicA rule of thumb, not a measurement. Directional only.a rule of thumb, such as keyword difficulty — directional, not measured.

Subprocessors

Everyone who touches your data, and specifically what they see.

kywrd’s subprocessors, what each does, and what data reaches it.
SubprocessorWhat it doesWhat reaches it
SupabaseDatabase and authentication.Your account, organization, tracked apps and keywords, and rank/listing history.
CloudflareHosting, background job queues, and R2 object storage.This site, the queue that schedules daily data pulls, and the append-only raw snapshot archive.
AnthropicGenerates listing copy and diff explanations.Public store listing text, your tracked keywords, and any tone notes you type. Not used to train models.
GoogleOAuth sign-in only.Your email, name, and avatar, at the moment you sign in.
StripePayments — not yet enabled.Nothing today. No payment data is collected or sent while billing is disabled.
Residential proxy providerRoutes Google Play data requests.The Play store pages and search results kywrd already pulls publicly. No account or personal data. Provider name to be added once selected.

Cookies

kywrd sets a session cookie to keep you signed in. No advertising cookies, no cross-site tracking pixels, no third-party ad networks. This marketing site runs no analytics at all — no page-view tracking, no heatmaps, no A/B testing scripts. That is a stronger claim than a cookie banner, so we are making it plainly instead of asking you to accept one.

Retention

We keep your account and tracking data for as long as your subscription is active, plus a limited period after cancellation in case you resubscribe. Raw R2 snapshots are kept as the historical record behind your rank charts; we have not yet set a maximum retention window for them.

Your rights, and deletion

You can access, export, or request deletion of your account data by emailing hello@kywrd.app. When you ask us to delete your data, we delete it and keep only what the law requires us to retain — for example, records needed for tax or billing purposes. We have not set a fixed number of days this takes; ask, and we will tell you what is realistic for your request.

We honor these rights — access, export, and deletion — for anyone who asks, regardless of where you are. We do not restrict them by jurisdiction, and we do not require you to prove that a specific law (GDPR, CCPA, or otherwise) applies to you before we act on a request.

Where your data is processed

kywrd stores and processes all customer and observation data in the United States, through the subprocessors listed above. We do not claim an exemption from any data protection law because of where our servers are — if you are signing up from outside the US, your data reaching US-based infrastructure is itself a transfer, and the rights described above apply to you the same as anyone else.

Children

kywrd is a business tool for app developers and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes to this policy

If we make a material change to this policy, we will notify active customers — by email or an in-product notice — before it takes effect.

Contact

kywrd is operated by Attayn Group LLC, doing business as Kywrd and Kywrd.app. Privacy questions: hello@kywrd.app.