Privacy Policy
Version 1.1 · Effective August 10, 2026
This policy explains what KILLCRITIC by X1OTHINK, a service of Repair Tune LLC ("we," "us"), collects, why, who it's shared with, and your choices. The short version: we collect what you give us to run the product, we don't sell your data, we don't run ads or third-party trackers, and you can delete your data.
1. Data We Collect — Full Label
Everything the app collects, in one table. We collect nothing outside this table.
| Category | What exactly | Why | Shared with | Kept until |
|---|---|---|---|---|
| Account | Name, email address, password (stored only as a scrypt hash — we cannot read it), plan, Terms acceptance record, account creation date | Sign-in, account management, service emails | Email delivery provider (Resend) when we send you email | Until account deletion |
| Business profile | Business name, category, address, city, state, phone, website URL, hours, services, description, photo count, posting frequency | Audits, content generation, reports | AI provider (Anthropic) to generate content about your business | Until you delete the business or account |
| Reviews you add or import | Reviewer name, star rating, review text, review date, source, your reply drafts and posted replies | Review management, sentiment analysis, AI reply drafting | AI provider (Anthropic) to draft replies | Until you delete the business or account |
| Competitor data you enter | Competitor names, ratings, review counts, photo counts, posting frequency, website scores | Comparison and gap analysis | AI provider (Anthropic) for gap explanations | Until you delete the business or account |
| SEO & content data | Keywords, tracked rankings you record, generated articles and drafts, content calendar, site-audit results for URLs you submit | The SEO Hub and Content Studio features | AI provider (Anthropic) for generation | Until you delete the item, business, or account |
| Brand voice | Writing samples you paste in, and the style profile our AI derives from them. If you give us your website URL, the readable text of that page is fetched and analysed too | Making generated content sound like you wrote it | AI provider (Anthropic) to build and apply the profile | Until you delete the brand voice, business, or account |
| Weekly tasks & listings progress | Your generated weekly task list and which tasks you've ticked off; which directories you've marked as submitted, live, or not started in the Listings Hub | Tracking your progress | AI provider (Anthropic) generates the task list; listing progress is shared with nobody | Until you delete the business or account |
| Backlink data | Your website domain, and the backlink profile returned for it: linking page URLs, linking domains, anchor text, follow status, domain ratings, and dated snapshots of the totals | Backlink monitoring (Growth and Pro plans) | SEO data provider (DataForSEO) — we send them your domain to look it up | Until you delete the business or account |
| Cached AI output | Generated analysis text kept alongside a fingerprint of the inputs that produced it | Avoiding a paid regeneration of identical analysis on every page view | Nobody | Until the underlying data changes, or you delete the business or account |
| Plan usage signals | Which features you use and how many times, with the first and last date; the date you last signed in; and, when a feature your plan doesn't include turns you away or you reach your daily AI limit, which feature and how often. Counts and dates only — never the content of what you generated | Telling us when a plan is the wrong fit for a customer, which features earn their place, and who needs help getting value | Nobody | Until account deletion |
| Abuse-prevention counters | Short-lived counters keyed to your IP address, your account ID, or (for sign-in and password-reset attempts) your email address, with a count and an expiry | Rate limiting — stopping credential-stuffing, signup floods, and runaway AI spend | Nobody | Most counters expire within 24 hours; the one that limits how often we can email you about your trial lasts 7 days. Entries tied to your account and email are also deleted with the account |
| Password resets | A one-time reset token stored only as a SHA-256 hash, its expiry, and whether it has been used | Letting you reset a forgotten password securely | Nobody (the link itself goes to your email via Resend) | Expires after 1 hour; rows deleted with the account |
| Billing | Stripe customer ID, subscription ID, plan, subscription status, billing period end, how many location slots you pay for, and your subscription's unit price. We NEVER see or store card numbers — payment details go directly to Stripe | Subscription management | Stripe (payment processor) | Until account deletion; Stripe retains records per its own policy |
| Integration credentials | WordPress site URL, username, and application password (if you connect WordPress); Google OAuth tokens (if you connect Google) | Publishing content and syncing data on your instruction | Sent only to the service you connected (your WordPress site / Google) | Until you disconnect the integration, or delete the business or account |
| Cookies | Three essential cookies: kc_session (signed login session), kc_business (which of your businesses is active), and kc_oauth_state (a short-lived random value that protects the Google connection flow from cross-site request forgery). No advertising, analytics, or tracking cookies | Keeping you signed in | Nobody | kc_session 30 days; kc_business 1 year; kc_oauth_state 10 minutes |
| Technical logs | IP address, browser user-agent, and request logs generated by our hosting provider (Railway). Your IP address is also used by us directly, as described under Abuse-prevention counters | Security, debugging, abuse prevention | Hosting provider (Railway) as processor | Short-term rolling logs |
| Sales chat (website visitors) | Whatever you type into the chat box on our homepage. You do not need an account to use it, and we do not store the conversation | Answering questions about the product before you sign up | Our AI provider (Anthropic), which generates the reply | Not stored by us — the message is sent, answered, and discarded. A short-lived counter tied to your IP address limits abuse (see above) |
| Billing incidents | If something goes wrong with a charge — a duplicate payment, or a subscription change we couldn't complete — we log your email, what happened, the amount, and the Stripe reference | So a billing mistake can be found and put right rather than quietly absorbed | Nobody (the underlying payment records live with Stripe) | The record is permanent for accounting, but your email is removed from it when you delete your account |
| Admin plan changes | If our staff grant or change your plan by hand (a comped or corrected account), we log your email, which staff member did it, the old and new plan, and when | So a plan you did not pay for can always be explained and audited | Nobody | The log entry is permanent, but your email is removed from it when you delete your account |
| Emails you trigger | Password reset emails and report emails you request, sent to your account email | The feature you triggered | Email delivery provider (Resend) | Delivery logs per provider policy |
2. What We Don't Do
- We do not sell or rent your personal information.
- We do not share your personal information for cross-context behavioral advertising.
- We do not use advertising trackers or third-party analytics.
- We do not use your data to train AI models. Content sent to our AI provider (Anthropic) is used to generate your output; we send only what the feature needs.
- We do not knowingly collect data from anyone under 18. The Service is for business use by adults.
3. Service Providers (Processors)
We share data only with the providers that run the product, each bound by its own terms: Railway (hosting and database), Stripe (payments), Anthropic (AI generation), Resend (email delivery), DataForSEO (backlink data, on Growth and Pro), and — only if you connect them — Google and your WordPress site. We may also disclose information if required by law, or to protect the rights, safety, or security of KILLCRITIC, our users, or the public.
4. Security
- All traffic is encrypted in transit (HTTPS).
- Passwords are hashed with scrypt and never stored in plain text.
- Sessions use signed, HTTP-only cookies.
- Requests the app makes to URLs you submit are filtered to block internal and private network targets.
- No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you as required by law.
5. Your Rights and Choices
- Access, correction, deletion, portability: you can edit business data in Settings, delete a business (which permanently deletes all its data) from My Businesses, and request full account deletion or a data export by emailing legal@killcriticseo.com. We honor verified requests within 30 days.
- Integrations: disconnect WordPress or Google at any time in Settings — stored credentials are deleted immediately.
- Emails: we send only transactional email (password resets, reports you request, billing/legal notices). There is no marketing list to unsubscribe from.
- State privacy laws (e.g., California, Colorado, Virginia): where they apply to us, you have the rights above plus the right not to be discriminated against for exercising them. We do not "sell" or "share" personal information as those laws define it.
6. Data Location and International Users
Data is stored on servers in the United States. If you use the Service from outside the U.S., you understand your information is processed in the U.S.
7. Changes
We'll post any changes here and update the version and effective date above; for material changes we'll notify you by email or in-app before they take effect.
8. Contact
Privacy questions or requests: legal@killcriticseo.com