This notice describes how Evan Kirby (“I”, “me”) handles personal data for services on kirby.run and its subdomains.
1. Who is responsible
Controller: Evan Kirby, Winter Park, Florida, United States.
Privacy contact: kwsprivacy@agentmail.to
This policy covers websites, apps, and APIs I operate under kirby.run and *.kirby.run, including current and future side projects on that domain, unless a service posts a more specific notice for its unique processing. Shared practices in this policy (contact, rights, children, transfers) still apply.
This is a privacy notice, not terms of service, a license, or a warranty.
2. What data I process
Depending on the service, processing may include:
- Account data — username, password hash, role, related account flags (for example on the VOD platform). Email is not required for VOD accounts today.
- Session and security data — authentication cookies (such as
vod_session), ephemeral rate-limit signals, and security/access logs from hosts. - User content — titles, descriptions, visibility settings, media files, posters, manifests; optional client-side encryption parameters (salt/KDF settings). Unlock passwords for client-side encryption are not uploaded to my servers.
- Technical and delivery data — IP address (including short-lived binding in playback/CDN tokens), User-Agent, requested URLs, timestamps, typically via CDN or hosting providers.
- Device storage — some tools store data in browser localStorage on your device (and may sync subsets to a server when that tool is designed to).
- Communications — messages you send to the privacy contact email.
- Analytics (future) — website analytics and/or video playback analytics categories only after you consent; vendors will be named in the Services Schedule when enabled.
I do not intentionally collect payment card numbers, government IDs, precise GPS, or advertising IDs on these services today.
3. Why I process data
- Provide the service you request (sites, accounts, uploads, playback, sync tools) — contract / steps you ask for.
- Secure the service (authentication, rate limits, token binding, abuse prevention) — legitimate interests in security.
- Operate infrastructure (hosting, CDN, storage, databases) — contract and legitimate interests in reliable delivery.
- Respond to privacy or support email — legitimate interests / contract.
- Website or video analytics in the future — consent only; not loaded until consent.
- Comply with law when required — legal obligation.
I do not sell personal information. I do not share personal information for cross-context behavioral advertising. There are no advertising networks on the main product paths today.
4. Cookies and similar technologies
Today, cookies are used only where essential for a service to work (for example the HttpOnly vod_session cookie for VOD sign-in). Some tools use localStorage on your device. Non-essential analytics cookies or scripts will not load until you consent, if and when those features ship.
5. Service providers
I use infrastructure providers that process data to run the services. Current providers are listed in the Services Schedule. Privacy request email is handled via AgentMail (agentmail.to) at kwsprivacy@agentmail.to. Each provider’s own privacy documentation describes their subprocessors.
6. International transfers
Users may be worldwide. Providers may process data in the United States and other countries. Where required, I rely on the transfer mechanisms and safeguards those providers make available (for example standard contractual clauses in their customer terms).
7. Retention
I keep account and content data only while needed to provide the service, or until you delete it or I complete a deletion request. Session cookies expire (VOD sessions last about 14 days). Delivery tokens expire in minutes to hours. CDN and cloud access logs may remain briefly on provider systems outside my direct control.
8. Your rights
Email kwsprivacy@agentmail.to to request access, correction, deletion, or an export of personal data I hold about you, or to object or request restriction where applicable law allows. I may need to verify that you control the relevant account. I will respond without undue delay. Requests are handled manually.
9. Children
These services are for people 18 and older only. They are not directed at children. If I learn I have collected personal data from someone under 18, I will delete it.
10. User-generated content
If you upload content, you must have the rights to do so and must not unlawfully include other people’s personal data. Public and unlisted links may be reachable by anyone who has the URL. Where client-side encryption is offered, media confidentiality depends on keeping the unlock password private. Privacy or takedown requests: kwsprivacy@agentmail.to.
11. Analytics (not enabled by default)
I may later offer:
- Website analytics — aggregate traffic such as pages, referrers, and coarse device/geo signals.
- Video playback analytics — playback quality and related metrics.
Those tools will load only after consent. When enabled, the vendor name and whether it is hosted by me or a SaaS provider will be added to the Services Schedule.
12. Services Schedule
Living list of services under this policy. New side projects on kirby.run get a row here.
| Service | Where | Notable data | Providers |
|---|---|---|---|
| Personal site | kirby.run |
Hosting access logs; no first-party accounts; privacy contact inbox | Google Cloud; AgentMail |
| Private planning tool | Path on kirby.run |
Browser localStorage; optional sync of shared votes/rows to cloud storage | Google Cloud |
| Stocks demo | kirby.run/stocks |
Local game state; third-party font request | Google Cloud; Google Fonts |
| VOD platform | vod.kirby.run, api.vod.kirby.run, vod-assets.kirby.run |
Accounts; vod_session cookie; uploads; IP-bound playback tokens |
Bunny.net; Backblaze B2; Google Cloud (legacy components if still deployed); jsDelivr (Shaka Player) |
13. Changes
I may update this notice when practices or the Services Schedule change. The “Last updated” date at the top will change when I do. Material changes to analytics or new data categories will be reflected here before or when those features go live.