VERSION 2026-10-08
Privacy policy
What Kork stores, who else handles it, and how to get it back or delete it.
Who is responsible
Kork is run by SUBCULT (subcult.tv). Write to [email protected] with questions or requests about your data.
If you have an account
We store:
- your email address, when you confirmed it, and when you signed up;
- your password as an argon2id hash (we never store the password itself);
- which version of the terms you accepted, and when;
- your pages: names, titles, bios, themes and every block you add;
- custom domains you add to a page;
- images you upload, with their type and size;
- daily totals of views and clicks for your pages (see below);
- a record of each signed-in session, and single-use links for email confirmation, password reset and email changes. These are stored as hashes and expire;
- a new email address you asked to switch to, until you confirm it;
- email addresses collected by your sign-up blocks, and your Brevo API key if you send sign-ups to Brevo (encrypted, and never shown again after you enter it).
- your plan and its source and expiry; if you subscribe through Stripe, customer, subscription and price identifiers, subscription status, billing-period dates, cancellation state and payment-failure timestamps;
- if you connect Patreon, your Patreon user identifier, membership eligibility and check dates, and an encrypted refresh token used to check membership again. We do not store your Patreon password;
- identifiers and types of processed Stripe webhook events, to prevent duplicate processing. Card numbers and security codes are handled by Stripe, not stored by Kork.
If you visit a page
- Kork's analytics database does not store visitors' IP addresses, cookies or browser details.
- We count page views and link clicks as one number per page or link per day. Nothing in that count identifies a visitor.
- To skip bots, the server checks the browser's user agent when counting and then discards it.
- To limit abuse, the server keeps IP addresses in memory for up to an hour to rate-limit signups, sign-ins, password resets, reports and click counts. They are not written to the database or logs.
- The Kork application logs each request's method, host, path, status and duration, without IP addresses or user agents.
- Our reverse proxy can log request details when an upstream request fails, including the visitor's IP address and browser headers. Query strings and Referer headers are redacted. These operational logs rotate by size, retaining up to three 50 MB files; they have no fixed age limit. Successful requests to Kork are not access-logged by this proxy.
- If you report a page, we store the page, the reason and the details you write, but not who sent it.
If you join a page's mailing list
When you enter your email address in a page's sign-up form, we store it and email you a confirmation link. If you don't confirm within 48 hours, we delete it. Once you confirm, the address belongs to the page owner's list: either we keep it so the owner can see and download it, or we send it to the owner's own Brevo account and delete our copy. The owner decides which, and is responsible for how they use the list; ask them to remove you. The page owner can delete your address at any time, and it is deleted with their account.
Cookies
Kork sets one cookie, zelda_session, and only when you sign in to the editor. It keeps you signed in for up to 30 days or until you sign out. Public pages set no cookies. There are no analytics or advertising cookies.
Embeds and links on pages
A page owner can embed players from YouTube, Vimeo, Spotify, SoundCloud, Twitch or Apple Music. When a page with an embed loads, your browser connects to that provider, which can see your IP address and may set cookies under its own policy. Links on a page go straight to their destination.
Services that handle data for us
- Cloudflare carries all traffic to Kork. It sees visitors' IP addresses and request details in order to deliver pages.
- Brevo sends account emails (confirmation, password reset and email change) and mailing-list confirmation links, so it receives the recipient's email address and the message.
- Stripe, when billing is enabled, processes Pro subscription payments and provides Checkout and the customer portal. It receives your billing information and the account identifiers needed to connect a subscription to Kork.
- Patreon, when you choose to connect it, authorizes access to your identity and qualifying SUBCULT membership. Kork uses that information to decide whether to grant Pro.
- Kork runs on a server operated by SUBCULT. The database and uploaded images are stored there.
We don't sell your data and Kork has no ads.
How long we keep it
We keep account data for as long as the account exists. When you delete your account, your pages, blocks, domains, uploaded images, stats, mailing-list addresses, sessions, billing connection and email address are removed from the active database. Stripe and Patreon retain their own records under their policies. Processed Stripe event identifiers are retained separately for duplicate prevention and are not deleted with an account.
The application keeps 14 nightly copies of its backups. Encrypted infrastructure backups can retain earlier copies under their separate retention schedules, so account deletion does not immediately remove data from every backup. Backups are used for recovery, not to republish deleted accounts. Reverse-proxy logs follow the size-based rotation described above.
Your choices
- Download your data: Settings → Download my data gives you a ZIP with your account details, pages, blocks, domains, themes, stats, mailing-list addresses and uploaded images.
- Correct it: edit your pages any time, and change your email or password in Settings.
- Delete it: Settings → Delete account.
- For anything else, write to [email protected].
Changes
We'll post changes to this policy here with a new version date.
See also the terms of service.