Skip to content

Legal

Privacy Policy

Last updated September 24, 2026

EmitKit lets you send product events from your code, SDK or AI agent to a real-time feed and get push notifications about them. It is operated by Chris Jayden (“we”, “us”). This policy explains what personal data we process, why, where it goes and what control you have. Questions go to hi@emitkit.com.

Who is responsible

We are the controller for the data about you and your team that we need to run your account. The events and identities your projects send us may contain personal data about your own users, such as an email address in an event description or a user ID. You decide what to send, so you are the controller for that data and we process it on your behalf, only to provide EmitKit to you.

What we collect

  • Account data: your name, email address, password (stored only as a hash) or passkey, your organizations and memberships, and the email addresses of people you invite.
  • Content you send: events (channel, title, description, icon, tags, metadata and user ID), identities you create through the API, and your projects, channels and settings.
  • API keys: stored only as a hash. We cannot show a key again after it is created.
  • Push subscriptions: when you turn on notifications, your browser gives us a delivery address and encryption keys for that device. We use them only to send you notifications.
  • Technical data: IP address, browser user agent and timestamps in sign-in sessions and request logs, used to keep you signed in, enforce rate limits, prevent abuse and fix problems.

This website (emitkit.com) sets no cookies and loads no analytics, advertising or other third-party scripts. The EmitKit app uses essential cookies only, to keep you signed in.

How we use it

  • To provide EmitKit: store and show your events, deliver push notifications, and send sign-in, verification and invitation emails.
  • To keep EmitKit secure and reliable: authentication, rate limiting, abuse prevention and debugging.
  • To contact you about your account or important changes to the service.

We do not sell personal data, use it for advertising or train AI models on your events. Under the GDPR, we rely on the performance of our contract with you, our legitimate interest in keeping the service secure and working, and our legal obligations.

Where it is processed

EmitKit runs on Cloudflare: Workers run the website, app and API; D1 stores account, project and channel data; Analytics Engine stores events; Queues hand events to the notification sender; Email Sending delivers our emails; and Workers AI suggests an emoji when you name a new channel. Cloudflare operates a global network, so data may be processed outside your country. Cloudflare’s data processing addendum includes the EU Standard Contractual Clauses.

When you turn on push notifications, each notification travels through your browser’s push service (for example Apple, Google, Mozilla or Microsoft). Its content is encrypted for your device, so the push service cannot read it.

How long we keep it

  • Events are kept for 90 days and then deleted automatically.
  • Account, organization, project and channel data is kept until you delete it or your account.
  • Sessions, rate-limit counters and retry records expire automatically.
  • Database backups for point-in-time recovery are kept for up to 30 days, so deleted data can remain in them for that long.

Your choices and rights

You can delete events, projects and your account at any time from the EmitKit app. You also have the right to access, correct, export or erase your personal data, and to object to or restrict how we use it. Email hi@emitkit.comand we will respond within one month. If you are unhappy with our answer, you can complain to your data protection authority.

If one of your users asks us about data you sent, we will refer them to you. The API can erase an identity you created for them.

Security

All traffic is encrypted with HTTPS. Passwords and API keys are stored only as hashes, every request is checked against the organization it belongs to, and access to production systems is limited to the operator.

Children

EmitKit is a tool for developers and is not directed at anyone under 16.

Changes

When this policy changes, we update this page and the date above. If a change materially affects how we use your data, we will email you before it takes effect.

Contact

Chris Jayden, operator of EmitKit: hi@emitkit.com