Privacy Policy
Last updated: August 25, 2026
1. Who is responsible
This site and its services are operated by Konrad Kaliciński. Contact: LinkedIn.
This policy covers this site (kgbuilder.dev) and the chat assistants published under it - for example the plant protection register assistant at sor.kgbuilder.dev.
2. In short
- Browsing this site requires no account and no personal data.
- If you use a chat assistant, you sign in with your e-mail address, and your questions and the assistant's answers are stored so the assistant can work and be improved.
3. What we collect, and when
When you just browse this site
- Nothing that identifies you: the site is static - no account, no advertising or tracking cookies.
- Anonymous visit statistics (Umami, self-hosted): page views, referrer, and an approximate device/browser type. No identifying cookies, no cross-site tracking, no data selling.
- A local preference: your light/dark theme choice is stored only in your browser and never sent to a server.
If you use a chat assistant
Then, additionally:
- E-mail address - to sign you in with a one-time link (magic link) and recognize your account. We store it in a normalized (lower-case) form.
- Sign-in markers - the date of your last successful sign-in.
- Login tokens and sessions - stored only as irreversible hashes (SHA-256), never in plain text. The usable values exist only in the link e-mailed to you and in a cookie in your browser.
- Your questions and the assistant's answers - the conversation content, stored so you can return to it and so the service can be run, debugged, and improved.
- Technical interaction records - which query the assistant ran against the graph, how many results it returned, the outcome and timings. These support reliability and abuse prevention and are not shown to other users.
4. Why we process this data
- To provide the service you ask for - signing you in and answering your questions.
- To keep the service secure and reliable - abuse prevention and aggregate statistics.
We do not use your questions to train third-party AI models.
5. Who we share data with
To run the assistants we rely on a few service providers:
- OpenAI (USA) - your question, together with the relevant context from the graph, is sent to the OpenAI API to generate an answer. Please do not put sensitive personal data in your questions.
- OVH (EU) - server and database hosting, and delivery of the sign-in link e-mails.
- Umami - anonymous statistics, self-hosted on the same infrastructure.
We do not sell your data or share it with advertisers.
6. How long we keep data
- Magic-link tokens: valid for a few minutes, then they expire.
- Sessions: expire after about a week, or immediately when you sign out.
- Accounts and their data: if you do not sign in for 3 months, your account and personal data (e-mail address and conversations) are deleted automatically, and the technical interaction records are anonymized - we sever the link to you and keep them only for aggregate statistics. You can also ask us to delete your data sooner.
7. Your choices
You can ask us to access, correct, or delete the personal data tied to your account, or to stop processing it. To do so, reach out via LinkedIn.
8. Cookies and local storage
- One essential session cookie - set only after you sign in to an assistant. It is httpOnly and is not used for tracking.
- Your theme preference is stored in your browser's local storage.
- We use no advertising or tracking cookies.
9. Changes
This policy may be updated; the "last updated" date above will change when it is. Significant changes affecting chat users will be signaled inside the assistant.
10. Contact
Konrad Kaliciński - LinkedIn.