Legal

Privacy Policy

On this page1. Who we are and what this Policy covers

Effective date: 15 September 2026

1. Who we are and what this Policy covers

CROWNSTONE PARTNERS LTD, company number 17452360, operates Kiilln at kiilln.com. Our address is Dept 6956, 43 Owston Road, Carcroft, Doncaster, United Kingdom, DN6 8DA. For privacy enquiries or requests, email info@kiilln.com.

We are the controller of personal data processed for administering Kiilln accounts, purchases, support and the operation of our website and Services. This Policy explains our handling of information about visitors and users, including personal data in prompts or project materials where applicable.

Kiilln provides code generation, preview and export. We do not provide production hosting for applications created with Kiilln. If a user exports and operates an application elsewhere, that operator is responsible for the information collected through it and for its own privacy notices.

If we process personal data solely on a business customer's instructions, our role and obligations for that processing must be addressed in an appropriate data processing agreement. This Policy does not replace that agreement.

2. Personal data we handle

The information involved depends on how you use Kiilln. It can include:

CategoryInformation involved
Account informationEmail address, account identifiers, login and authentication information, and any profile details you provide.
Purchase and billing informationPackage purchased, amount and currency, order and transaction references, payment status, billing details supplied at checkout, refund records and payment-dispute information.
Balance and activity recordsBalance purchased, credited, used or restored; dates and times; the account, project or action associated with an entry.
Project ContentPrompts, instructions, code, files, generated code, project names and related information you submit or create. These materials may contain personal data if you include it.
Technical and security informationIP address, browser and device information, session and request identifiers, access times, error information and records needed to investigate misuse or unauthorised access.
CommunicationsSupport requests, complaints, feedback, refund enquiries and the attachments or explanations you choose to provide.
Preferences and permissionsCookie choices, consent records and any communication preferences you give us.

Payment-card details entered during checkout are handled for payment authorisation and processing. Please do not send full card numbers, card security codes, account passwords or authentication codes to our support address.

We receive information directly from you, through your interaction with the Services, and from service providers involved in payment processing, authentication, infrastructure or security, to the extent relevant to their functions. For example, a payment service can return a payment result and transaction reference. We may also receive information from a person reporting suspected abuse or an authority making a lawful request.

3. How and why we use information

Where data protection law requires a lawful basis, we rely on the basis appropriate to the purpose:

PurposeBasis
Registering your account, authenticating access, supplying requested generation, preview and export, and managing your paid BalancePerformance of our contract with you, or steps you request before entering into it. Where you act for a business that is our customer, our legitimate interest in administering and delivering that business relationship.
Processing purchases, delivering Balance, administering refunds and resolving purchase enquiriesPerformance of the contract, with legal obligation where recordkeeping or a statutory remedy requires processing.
Responding to support requests and correcting service problemsPerformance of the contract where the request concerns our Services; otherwise our legitimate interest in responding to enquiries and maintaining reliable operation.
Protecting accounts, investigating fraud or abuse, enforcing reasonable use restrictions and maintaining system securityOur legitimate interests in protecting users, the Services and our business, subject to the impact on individuals; legal obligation where applicable.
Keeping accounting records, responding to lawful regulatory requests and meeting other applicable legal dutiesCompliance with a legal obligation.
Establishing, exercising or defending legal claimsOur legitimate interests in protecting legal rights, and legal obligation where applicable.
Understanding technical performance and improving reliability through proportionate operational metricsOur legitimate interest in maintaining an effective service; consent for device storage or access where required. This purpose does not include training AI on your prompts or project code.
Optional cookies or optional promotional communications, if offeredConsent where required. We will explain the particular purpose at the point of choice.

We assess whether an interest is legitimate and whether processing is necessary and proportionate, taking account of your rights. We do not use this general description to authorise unrelated uses of private Project Content.

Account, payment and essential operational information is necessary to provide the relevant Services. If you do not provide required information, we may be unable to create the account, process a purchase or fulfil your request. Optional information is not a condition of access unless it is genuinely needed for a feature you request.

4. Private projects and no AI training

Projects are private by default. We do not use your prompts or project code to train AI models. We do not authorise providers processing that content on our behalf to use it for their own AI training.

Project Content must still be processed to carry out your instructions, generate Output, provide a preview and enable export. Necessary access may also occur for support, security, abuse investigation or legal compliance. Access is limited to authorised persons and providers with a relevant purpose.

Private status does not mean that data is processed only on your device or that authorised service providers never receive it. It means we do not make your projects available to the public or other users by default.

Avoid submitting unnecessary personal data about other people, special-category data such as health information, criminal-offence data, passwords or live secret keys. If a business use requires us to process personal data on your instructions, contact us before submitting that data to confirm suitable arrangements.

5. Who may receive information

We disclose information only for a relevant purpose and to an appropriate extent. Recipients can include:

  • AI processing providers, receiving the prompts, code and context necessary to generate the requested result;
  • infrastructure, storage and authentication providers, supporting account access and operation of the Services;
  • payment processing, banking and card-network participants, handling authorisation, settlement, refunds, fraud checks and payment disputes;
  • technical security and diagnostic providers, supporting incident prevention, investigation and service reliability;
  • communications and support providers, helping us receive and respond to enquiries or send service notices;
  • professional advisers, such as legal and accounting advisers, where needed for their work;
  • courts, regulators, public authorities or other entitled recipients, where disclosure is required by law or necessary and lawful to protect rights; and
  • a prospective or actual successor to the business, where a lawful transaction requires disclosure subject to appropriate confidentiality and data protection safeguards.

Different recipients need different information. A provider receiving payment details does not, merely because of that role, require access to your entire project. Where a provider acts as our processor, its processing must be governed by appropriate instructions and contractual protections. Some payment or professional-service participants may act as independent controllers for their own legal duties.

We do not grant a right to publish, market or commercially exploit your private Project Content merely because a provider helps us deliver the Services.

6. International processing

The location of our company does not necessarily determine where every part of the service processes data. Where personal data is transferred internationally, we must follow the rules that apply to that transfer.

Some of our service providers process personal data outside the United Kingdom, including in the European Economic Area and the United States.

You can contact info@kiilln.com for information about the safeguards applicable to your data, including a copy where available. We may redact information necessary to protect security, confidential commercial terms or another person's rights.

7. How long we retain information

We keep personal data for as long as reasonably necessary for the purpose for which it is processed, including applicable legal and recordkeeping obligations. The relevant criteria include:

  • Accounts and projects: whether your account remains open, whether you still need the stored project, whether you request deletion and whether retention is necessary to supply a feature or resolve an issue.
  • Purchases and Balance records: the need to maintain an accurate non-expiring paid balance, establish the use of a particular purchase, process refunds, meet accounting obligations and resolve disputes. A non-expiring Balance does not justify retaining all project files indefinitely.
  • Support and complaint records: the time needed to handle the matter, follow up on a recurring issue and retain evidence for relevant claims or obligations.
  • Technical and security records: their usefulness for investigating errors or incidents and the risk associated with retaining them. These records should not be kept indefinitely merely because collection is technically possible.
  • Consent and preference records: the need to respect and demonstrate your choices.

Where data is no longer needed, it is deleted or anonymised. A deletion request may not require immediate removal of information that must be retained by law or for a valid unresolved claim. Residual copies in backups may remain until the applicable backup replacement or deletion process completes; they remain protected and must not be restored for ordinary use without applying relevant deletion requests.

You may ask us for more detail about retention of a particular category. Closing your account does not cancel obligations to retain necessary transaction records, but it does not authorise continued use of your content for unrelated purposes.

8. Security

We use technical and organisational measures appropriate to the nature of the information and the risks of processing. These include limiting access to authorised purposes and protecting account access and service operations. No method of storage or transmission can guarantee absolute security.

If we become aware of a personal-data breach, we will investigate and take action, including notifying affected individuals and authorities where required by law. Contact us promptly if you suspect that your account or information has been compromised.

9. Your rights

Depending on the law applicable to your information and the circumstances, you may request access, correction, deletion, restriction of processing or a portable copy of data. You may also withdraw consent where processing relies on it. Withdrawal does not invalidate earlier lawful processing.

Your right to object: you may object to processing based on legitimate interests for reasons relating to your particular situation. You may object to direct marketing at any time. We will apply the relevant legal tests and stop processing where the law requires.

Email info@kiilln.com to exercise a right. Describe what you need and the account or information concerned. We may request proportionate verification where necessary to prevent disclosure or deletion of another person's data. You do not need to provide identity documents routinely if a less intrusive verification method is sufficient.

We respond within the period required by applicable law, normally one month for UK GDPR requests, subject to lawful extensions or adjustments. We will explain any applicable limitation, refusal or extension. Requests are ordinarily free; any fee or refusal must have a lawful basis.

10. Automated decisions

Generating code in response to your instructions is an automated feature. It is not, merely by generating code, a decision about your legal rights or eligibility.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Some safeguards run automatically, such as declining a request that our content checks identify as prohibited, or declining registration from a country where Kiilln is not available.

You can contact us if an automated account or payment restriction appears incorrect and request an explanation and review where applicable.

11. Children

Kiilln is intended only for people aged 18 or over. If you believe that a person under 18 has provided personal data or created an account, contact us so we can investigate and take appropriate action, including restricting access and deleting information where appropriate and lawful.

12. Cookies and communications

Our Cookie Policy explains device storage and access technologies and available choices. Optional consent must be separate from accepting our Terms.

We may send account, transaction, service and security communications necessary to operate your account or fulfil our obligations. If promotional communications are offered, applicable choices and opt-out instructions will be provided. Declining marketing does not prevent necessary service messages.

13. Complaints and changes

Please send privacy concerns to info@kiilln.com. You may also complain directly to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint, or another competent data protection authority, including the authority in your EEA country of residence or work where applicable. You do not have to contact us first.

We may update this Policy to reflect changes in processing or legal requirements. We will provide appropriate notice of material changes and obtain fresh consent where necessary. A revised notice does not itself authorise a new use incompatible with the original purpose or override the no-training commitment.