Privacy Policy
Effective 2026-09-18
Private by default
Kaddy’s default AI models run within Kaddy’s hosting platform. Your prompts, app data, and model responses are not sent to the company that developed the model.
This includes open-weight models such as DeepSeek, GLM, Kimi, and gpt-oss. Kaddy uses independently hosted versions of these models—it does not call DeepSeek, Z.ai, Moonshot AI, or OpenAI’s hosted APIs to run them. Those companies do not receive your content through Kaddy, and your content is not used to train these models. You can see and change the model used by each app in its settings.
Models operated by third-party providers
Kaddy also offers models operated by OpenAI, Anthropic, and SpaceXAI. These are clearly identified as external providers in the model picker. They are never selected silently: your app uses one only when you or an editor you authorize chooses it.
When one of these models is selected, Kaddy transmits the prompt and the context needed to answer it to that provider—much as it would be transmitted if you used the provider directly. Kaddy does not use your content for model training and does not authorize these providers to train on content sent through Kaddy. The provider processes the request as a business API service under its own applicable terms.
Our promise
Kaddy is made by Forged Apps. Your apps, their data, source code, memories, conversations, and files are yours. We use that content to provide, secure, support, and improve Kaddy for you. We do not sell it, use it to train Kaddy models, or permit AI providers to train on it through Kaddy.
What we collect
We collect your verified email address and the information needed to run your account and Kaddy space. We store the content you put in Kaddy: app data, source code, conversations, memory, settings, images, backups, and information from integrations you choose to connect. If you buy a paid plan, Stripe processes your payment details; Kaddy receives billing status and Stripe account identifiers, not your card number.
How Kaddy uses your content
Kaddy processes your content to host your apps, keep their data and backups, answer conversations, run requested actions, and provide support or investigate security and reliability problems. Model requests and responses may be retained in operational logs within Kaddy’s hosting platform for reliability, security, cost control, and support. We show the hosting boundary in the model picker so you can make an informed choice before sending a request.
Analytics that avoid your app content
We use PostHog US Cloud to understand whether Kaddy is working and which product flows are useful. It receives a hashed account identifier, basic account and product events, limited browser and MCP client metadata, and your email as an account profile property. It does not receive app data, chats, source code, AI prompts, tool arguments or results, request bodies or headers, or raw error messages and stacks. Session replay masks text and inputs and blocks the workspace, generated apps, media, and source-like elements. Analytics are disabled outside production and do not run on localhost or HTTP.
Service providers and sharing
We use Cloudflare to operate Kaddy, PostHog for the limited analytics described above, Stripe for payments, Cloudflare email services for sign-in and service messages, and Featurebase for in-product support. When you sign in, Featurebase receives a signed account identity so it can provide support; information you submit in a support conversation is handled by Featurebase for that purpose. OpenAI, Anthropic, or SpaceXAI receives model-request content only when you or an editor you authorize chooses one of its externally operated models. Connected services receive information only when you choose to use them. We may disclose information when required by law or to protect Kaddy, its users, or the public. We do not sell or rent personal information.
Retention, security, and your choices
We keep account and app information while your space is active. App backups, including a final backup made when an app is deleted, have a standard 30-day recovery window. Backup copies may remain longer in protected archives or disaster-recovery systems until they are safely deleted, and we do not use them for any other purpose. You can review and edit app memory, archive or delete apps, and manage sharing from Kaddy. A public app link makes its live app available to anyone with the link; invite editors only when you trust them. To request access, correction, export, or deletion of your account information, email support@kaddy.diy. We use reasonable technical and organizational safeguards, but no online service can promise absolute security.
Changes and contact
We may update this policy as Kaddy changes. For material changes, we will update the effective date and provide notice through Kaddy or another reasonable channel. Questions or privacy requests: support@kaddy.diy.