Privacy Policy

Effective date: 1 September 2026

This policy explains what personal data Kordmate processes, why, and what rights you have under the EU General Data Protection Regulation (GDPR). It describes the service as it works today — Kordmate currently has no analytics and no advertising technology.

1. Who is responsible for your personal data

Kordmate is currently operated by Freddy Konrad, a private individual based in Sweden, under the name Kordmate. Until a company is registered, he is the data controller for the processing described in this policy. Kordmate is the name of the service and is not itself a registered company.

For all privacy matters, use the Contact page or email support@kordmate.com.

2. The personal data we process

Account data. Your email address and a password (stored only in hashed form by our authentication provider). If you log in with Google, we instead receive your email address, name and profile picture from your Google account.

Content you create. Your Scenes (the Devices, Cables, labels, notes and technical values you place on the Canvas), Scene folders, Device templates, Snapshots, and your workspace preferences (such as unit system, theme and canvas display settings). If you use custom branding on a Business or Business+ plan, this also includes the logo image you upload on the Account page — it is stored privately, linked only to your account, and used only in the exports you create.

Technical data. Our infrastructure providers process IP addresses and technical request data (such as server logs) as an inherent part of delivering and securing the service. We do not use this data to build profiles of you.

Guest use. If you use the Canvas without an account, your work is stored only in your own browser and is not sent to our servers.

Snapshots you share. Sharing is off by default. If you make a Snapshot public, anyone with the link can see the Scene name, any note you attach, and the full contents of the Scene. Your name and email address are never shown on a shared Snapshot.

Billing data. If you purchase the Business plan, payments are processed by Stripe on Stripe's own checkout pages — your card details go directly to Stripe and never reach our servers. We store only your Stripe customer and subscription identifiers and your subscription status (such as whether it is active and when it renews) so we can grant Business access. Stripe's own privacy policy applies to the payment itself. Business+ is arranged separately and is not purchased through Stripe Checkout; we then process the account details needed to grant that access. See also our Terms of Payment.

Contact messages. If you write to us through the Contact page, we receive the email address, topic and message you submit. We do not store that message in the Kordmate database. It is delivered to our support inbox by email, and we send you a short confirmation email.

What we do not collect. We use no analytics or tracking, collect no advertising or behavioral data, and never store your card details ourselves.

3. Why we process your data, and on what legal basis

  • Providing your account and storing your content (creating and logging in to your account, saving Scenes, folders, Device templates, Snapshots and preferences, and displaying Snapshots you choose to make public) — performance of our contract with you (Article 6(1)(b) GDPR).
  • Account emails (email confirmation and password reset, delivered from mail.kordmate.com by Resend) — performance of our contract with you (Article 6(1)(b) GDPR).
  • Contact inquiries (receiving a message you send through the Contact page and sending you a confirmation that it arrived) — our legitimate interest in answering you (Article 6(1)(f) GDPR), and, for Business+ inquiries, taking steps at your request before a contract (Article 6(1)(b) GDPR).
  • Billing for Business or Business+ (starting Business checkout with Stripe, keeping your subscription status up to date, or arranging Business+ access) — performance of our contract with you (Article 6(1)(b) GDPR), and compliance with legal obligations such as bookkeeping rules (Article 6(1)(c) GDPR).
  • Security and service operation (infrastructure logs, preventing abuse and unauthorized access, including Cloudflare on the Contact page and a limit on how often a connection can submit that form) — our legitimate interest in running a safe and functioning service (Article 6(1)(f) GDPR).

We do not currently rely on consent for any processing, because we do nothing that requires it — such as marketing or analytics.

4. Who we share your data with

We use a small number of service providers (processors) that store or handle data on our behalf:

  • Supabase — database, file storage and authentication provider; stores your account data and your content, including any branding logo you upload.
  • Resend — sends account emails and Contact-page messages and confirmations from mail.kordmate.com.
  • Cloudflare — used on the Contact page. The widget loads only there and processes browser and network signals to prevent automated abuse. See Cloudflare's Cloudflare privacy information.
  • Vercel — hosts the Kordmate web application.
  • Stripe — payment provider; processes your payment and card details if you purchase the Business plan. Business+ is not processed through Stripe Checkout.
  • Google — only if you choose to log in with Google. Google's own privacy policy applies to your Google account.

We do not sell personal data and do not share it with advertisers.

5. International transfers

Our Supabase project — where your account data and content are stored — is hosted in the United States, and Vercel, Resend and Cloudflare are US companies. These transfers outside the EU/EEA are protected by safeguards under Chapter V of the GDPR: Supabase's data processing agreement incorporates the European Commission's Standard Contractual Clauses, and Vercel is certified under the EU-U.S. Data Privacy Framework. Resend's data processing addendum likewise incorporates those clauses, and Resend is certified under the EU-U.S. Data Privacy Framework. Cloudflare, Inc., Google LLC and Stripe, Inc. are likewise certified under the EU-U.S. Data Privacy Framework.

6. How long we keep your data

We keep your account data and content for as long as you have an account. You can delete individual Scenes, folders, Device templates and Snapshots yourself at any time — deleted content is removed from the live database immediately and cannot be restored through the app, though residual copies may remain for a short period in our providers' routine infrastructure backups. If you delete your account (section 8), your account data and all content stored under it are deleted, including the subscription status we hold. Stripe retains its own transaction records for as long as financial and bookkeeping law requires. We do not keep a copy of Contact-page messages in our database; the support inbox and Resend's delivery logs keep what those systems keep. We keep a short-lived record of a hashed connection and hashed recipient email, used only to limit how often the Contact form can be submitted, and only for as long as that monthly limit needs. We have no other fixed retention periods at this stage.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have incorrect data corrected;
  • have your data erased;
  • restrict processing;
  • receive the data you have provided in a machine-readable format (data portability); and
  • object to processing that is based on our legitimate interests.

To exercise any of these rights, use the Contact page or email support@kordmate.com. We may need to verify that you are the account owner before acting on a request, and we respond within the timeframes the GDPR requires (normally within one month).

8. Deleting your account and data

You can delete your account yourself on the Account page. To protect your account, we first ask you to confirm your password — or, if you log in with Google, to log in with Google again. Deleting your account permanently removes your account data and the Scenes, folders, Device templates, Snapshots, preferences and any uploaded branding logo stored under it, and any shared snapshot links stop working. An active Business or Business+ subscription is cancelled at the same time, without a refund of remaining paid time. If you need help, use the Contact page or email support@kordmate.com.

9. Complaints

If you believe we handle your personal data incorrectly, please contact us first through the Contact page or at support@kordmate.com. You also always have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY, imy.se) or with the supervisory authority in the EU/EEA country where you live.

10. Children

Kordmate is not directed at children under 13, and you must be at least 13 years old to create an account.

11. Changes to this policy

We will update this policy when the service changes — for example if we add new features, new providers or, in the future, analytics. The current version, with its effective date, is always available on this page. If changes are significant, we will take reasonable steps to inform registered users. See also our Cookie Policy, Terms of Use and Terms of Payment.