Privacy Policy
Version 1.0 · Effective August 8, 2026
This policy explains what KILLCRITIC by X1OTHINK, a service of Repair Tune LLC("we," "us"), collects, why, who it's shared with, and your choices. The short version: we collect what you give us to run the product, we don't sell your data, we don't run ads or third-party trackers, and you can delete your data.
1. Data We Collect — Full Label
Everything the app collects, in one table. We collect nothing outside this table.
| Category | What exactly | Why | Shared with | Kept until |
|---|---|---|---|---|
| Account | Name, email address, password (stored only as a scrypt hash — we cannot read it), plan, Terms acceptance record, account creation date | Sign-in, account management, service emails | Email delivery provider (Resend) when we send you email | Until account deletion |
| Business profile | Business name, category, address, city, state, phone, website URL, hours, services, description, photo count, posting frequency | Audits, content generation, reports | AI provider (Anthropic) to generate content about your business | Until you delete the business or account |
| Reviews you add or import | Reviewer name, star rating, review text, review date, source, your reply drafts and posted replies | Review management, sentiment analysis, AI reply drafting | AI provider (Anthropic) to draft replies | Until you delete the business or account |
| Competitor data you enter | Competitor names, ratings, review counts, photo counts, posting frequency, website scores | Comparison and gap analysis | AI provider (Anthropic) for gap explanations | Until you delete the business or account |
| SEO & content data | Keywords, tracked rankings you record, generated articles and drafts, content calendar, site-audit results for URLs you submit | The SEO Hub and Content Studio features | AI provider (Anthropic) for generation | Until you delete the item, business, or account |
| Billing | Stripe customer ID, subscription ID, plan, subscription status, billing period end. We NEVER see or store card numbers — payment details go directly to Stripe | Subscription management | Stripe (payment processor) | Until account deletion; Stripe retains records per its own policy |
| Integration credentials | WordPress site URL, username, and application password (if you connect WordPress); Google OAuth tokens (if you connect Google) | Publishing content and syncing data on your instruction | Sent only to the service you connected (your WordPress site / Google) | Until you disconnect the integration, or delete the business or account |
| Cookies | Two essential cookies: kc_session (signed login session) and kc_business (which of your businesses is active). No advertising, analytics, or tracking cookies | Keeping you signed in | Nobody | Session cookie expires after 30 days |
| Technical logs | IP address, browser user-agent, and request logs generated by our hosting provider (Railway) | Security, debugging, abuse prevention | Hosting provider (Railway) as processor | Short-term rolling logs |
| Emails you trigger | Password reset emails and report emails you request, sent to your account email | The feature you triggered | Email delivery provider (Resend) | Delivery logs per provider policy |
2. What We Don't Do
- We do not sell or rent your personal information.
- We do not share your personal information for cross-context behavioral advertising.
- We do not use advertising trackers or third-party analytics.
- We do not use your data to train AI models. Content sent to our AI provider (Anthropic) is used to generate your output; we send only what the feature needs.
- We do not knowingly collect data from anyone under 18. The Service is for business use by adults.
3. Service Providers (Processors)
We share data only with the providers that run the product, each bound by its own terms: Railway (hosting and database), Stripe (payments), Anthropic (AI generation), Resend (email delivery), and — only if you connect them — Google and your WordPress site. We may also disclose information if required by law, or to protect the rights, safety, or security of KILLCRITIC, our users, or the public.
4. Security
- All traffic is encrypted in transit (HTTPS).
- Passwords are hashed with scrypt and never stored in plain text.
- Sessions use signed, HTTP-only cookies.
- Requests the app makes to URLs you submit are filtered to block internal and private network targets.
- No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you as required by law.
5. Your Rights and Choices
- Access, correction, deletion, portability: you can edit business data in Settings, delete a business (which permanently deletes all its data) from My Businesses, and request full account deletion or a data export by emailing legal@killcriticseo.com. We honor verified requests within 30 days.
- Integrations: disconnect WordPress or Google at any time in Settings — stored credentials are deleted immediately.
- Emails: we send only transactional email (password resets, reports you request, billing/legal notices). There is no marketing list to unsubscribe from.
- State privacy laws(e.g., California, Colorado, Virginia): where they apply to us, you have the rights above plus the right not to be discriminated against for exercising them. We do not "sell" or "share" personal information as those laws define it.
6. Data Location and International Users
Data is stored on servers in the United States. If you use the Service from outside the U.S., you understand your information is processed in the U.S.
7. Changes
We'll post any changes here and update the version and effective date above; for material changes we'll notify you by email or in-app before they take effect.
8. Contact
Privacy questions or requests: legal@killcriticseo.com