This notice describes how Evan Kirby (“I”, “me”) handles personal data for services on kirby.run and its subdomains.
1. Who is responsible
Controller: Evan Kirby, Winter Park, Florida, United States.
Privacy contact: kwsprivacy@agentmail.to
This policy covers websites, apps, and APIs I operate under kirby.run and *.kirby.run, including current and future side projects on that domain, unless a service posts a more specific notice for its unique processing. Shared practices in this policy (contact, rights, children, transfers) still apply.
This is a privacy notice, not terms of service, a license, or a warranty.
2. What data I process
Depending on the service, processing may include:
- Account data — username, password hash, role, related account flags (for example on the VOD platform). Email is not required for VOD accounts today.
- Session and security data — authentication cookies (such as
vod_session), ephemeral rate-limit signals, and security/access logs from hosts. - User content — titles, descriptions, visibility settings, media files, posters, manifests; optional client-side encryption parameters (salt/KDF settings). Unlock passwords for client-side encryption are not uploaded to my servers.
- Technical and delivery data — IP address (including short-lived binding in playback/CDN tokens), User-Agent, requested URLs, timestamps, typically via CDN or hosting providers.
- Device storage — some tools store data in browser localStorage on your device (and may sync subsets to a server when that tool is designed to).
- Communications — messages you send to the privacy contact email.
- Analytics — website analytics remain unshipped. Video playback analytics (Mux Data) on VOD player pages after you opt in; vendors named in the Services Schedule.
I do not intentionally collect payment card numbers, government IDs, precise GPS, or advertising IDs on these services today.
3. Why I process data
- Provide the service you request (sites, accounts, uploads, playback, sync tools) — contract / steps you ask for.
- Secure the service (authentication, rate limits, token binding, abuse prevention) — legitimate interests in security.
- Operate infrastructure (hosting, CDN, storage, databases) — contract and legitimate interests in reliable delivery.
- Respond to privacy or support email — legitimate interests / contract.
- Video playback analytics (Mux Data) on VOD player pages — consent only; script not loaded until you Allow. Website analytics remain unshipped.
- Comply with law when required — legal obligation.
I do not sell personal information. I do not share personal information for cross-context behavioral advertising. There are no advertising networks on the main product paths today.
4. Cookies and similar technologies
Today, cookies are used only where essential for a service to work (for example the HttpOnly vod_session cookie for VOD sign-in). Some tools use localStorage on your device (including vod-mux-consent-v1 for playback analytics choice). Non-essential analytics scripts do not load until you consent.
5. Service providers
I use infrastructure providers that process data to run the services. Current providers are listed in the Services Schedule. Privacy request email is handled via AgentMail (agentmail.to) at kwsprivacy@agentmail.to. Each provider’s own privacy documentation describes their subprocessors.
6. International transfers
Users may be worldwide. Providers may process data in the United States and other countries. Where required, I rely on the transfer mechanisms and safeguards those providers make available (for example standard contractual clauses in their customer terms).
7. Retention
I keep account and content data only while needed to provide the service, or until you delete it or I complete a deletion request. Session cookies expire (VOD sessions last about 14 days). Delivery tokens expire in minutes to hours. CDN and cloud access logs may remain briefly on provider systems outside my direct control.
8. Your rights
Email kwsprivacy@agentmail.to to request access, correction, deletion, or an export of personal data I hold about you, or to object or request restriction where applicable law allows. I may need to verify that you control the relevant account. I will respond without undue delay. Requests are handled manually.
9. Children
These services are for people 18 and older only. They are not directed at children. If I learn I have collected personal data from someone under 18, I will delete it.
10. User-generated content
If you upload content, you must have the rights to do so and must not unlawfully include other people’s personal data. Public and unlisted links may be reachable by anyone who has the URL. Where client-side encryption is offered, media confidentiality depends on keeping the unlock password private. Privacy or takedown requests: kwsprivacy@agentmail.to.
11. Analytics
- Website analytics — not enabled.
- Video playback analytics — Mux Data (SaaS). On
player.htmland UUID lookup only, after you tap Allow. Measures startup time, buffering, bitrate, errors, and related quality-of-service metrics. Media still streams fromvod-assets.kirby.run(Bunny); Mux does not host the video. Beacons go to Mux. The Mux environment key is public-by-design (not a secret). Signed CDN URLs are stripped before reporting. Logged-in viewers are sent as a SHA-256 hash of the account id, not the username. Reject / No thanks = playback still works, no Mux script.
You can change the choice later under Advanced → Playback analytics on the player page.
12. Services Schedule
Living list of services under this policy. New side projects on kirby.run get a row here.
| Service | Where | Notable data | Providers |
|---|---|---|---|
| Personal site | kirby.run |
Hosting access logs; no first-party accounts; privacy contact inbox | Google Cloud; AgentMail |
| Private planning tool | Path on kirby.run |
Browser localStorage; optional sync of shared votes/rows to cloud storage | Google Cloud |
| Stocks demo | kirby.run/stocks |
Local game state; third-party font request | Google Cloud; Google Fonts |
| VOD platform | vod.kirby.run, api.vod.kirby.run, vod-assets.kirby.run |
Accounts; vod_session cookie; uploads; IP-bound playback tokens; Mux Data QoS after opt-in |
Bunny.net; Backblaze B2; Google Cloud (legacy components if still deployed); jsDelivr (Shaka Player); Mux Data (src.litix.io) |
13. Changes
I may update this notice when practices or the Services Schedule change. The “Last updated” date at the top will change when I do. Material changes to analytics or new data categories will be reflected here before or when those features go live.