TermsAcceptable usePrivacy
Kiln

Privacy

Last updated 13 August 2026

1What we collect

Account. Your email address, and a password stored only as a bcrypt hash by our authentication provider. If you enable two-factor authentication, that provider generates and holds the authenticator secret — it never reaches our servers. We never see your password in readable form.

Payments. Card details go directly to Stripe and never reach our servers. We store the Stripe identifiers for your customer record and saved payment method, and the amount and date of each top-up. If you pay with cryptocurrency we never hold a wallet or key for you; we store the payment's reference, its status, the dollar amount, and the address the payment came from where the processor reports it. Paying that way also requires you to register a refund address, which we keep so we have somewhere to return unspent balance and so we can tell whether a refund is going back where the money came from.

Agreement records. When you create an account and each time you add funds, we record which version of the terms you agreed to, the time, the IP address the request came from, and your browser's user agent string. This exists to answer a bank if a payment is disputed.

Usage. For each machine you run: its type, region, when it started and stopped, and the metered usage with the resulting charges. You can see and export this from your usage page.

Connection. When you connect to a machine we take the IP address of that request and open remote desktop access to that single address. The access rule is removed when the machine stops; the address itself is kept in our operational log of the connection.

Security. Automated threat detection watches the network behaviour of the infrastructure — the addresses and services machines connect to, not their contents. Where a finding concerns a machine you were running we keep a record of it linked to your account, including the description of the behaviour, which machine it was, and your email address. Findings are reviewed by a person; nothing is stopped or charged automatically because of one.

How the site is used. We record which pages you visit, what you click, and errors the site hits, so we can find and fix problems. We do not record video or replays of your screen, and nothing inside your machines is captured. Web addresses are stripped of anything sensitive before they are stored, and event details whose names look like credentials are dropped rather than sent. If you are signed in this is linked to your account id, never your email address.

Fraud and abuse signals. We use your payment and usage history to decide how much verification to require on a payment, and to spot patterns that look like card fraud. This is automated and it can restrict your account without a person reviewing it first — for example pausing your ability to launch machines after an unusually large or fast series of top-ups. We also record whether your account has ever been funded with cryptocurrency, because that payment route carries no trail we can check, and the reason recorded if an account is suspended. You can ask us to review any automated restriction.

2What we do not collect

We never ask you for your name, address, phone number, or date of birth, and nothing on this site requires them. If you sign in with Discord or Google we receive whatever profile they return, which usually includes a display name — see section 3. We use no advertising trackers, run no ads, and never sell or share your data for advertising.

Cookies. The ones that keep you signed in, one for the usage analytics described above, and — if you arrive through someone's referral link — one that remembers that code for 30 days so their referral can be credited.

We do not read what is on your machines. We do not open your files, and nothing you store or run inside a machine is copied to us or logged. Be clear about the limits of that, though: we sample how busy a machine is so we know when it is idle, our threat detection sees the network addresses it talks to, and because we hold the key that generates your Windows administrator password, we are technically capable of reaching a machine. That access is for operating and securing the service, not for looking at your work, but it would be untrue to tell you it is impossible.

3Who else receives it

These providers handle data on our instructions and for our purposes only: our cloud infrastructure provider, which hosts the machines and the control systems and to which we pass a label containing your email address so we can tell machines apart; Vercel, which hosts this website and therefore handles every request to it; Supabase, which provides authentication and the database; Cloudflare, whose network sits in front of the whole site and whose Turnstile provides the anti-bot check on the sign-in form; and PostHog, which receives the site-usage records described above.

These decide for themselves how they use what they receive, so their own privacy policies govern it as well as ours: Stripe, which processes card payments and runs its own fraud checks; Plisio, which processes cryptocurrency payments if you choose that method and receives your email address with the payment request; and Discord, if you sign in with it or join our server.

If you sign in with Discord or Google, they confirm your identity to us and we keep the profile they return — the account id, and depending on the provider your username or name, avatar and email. We use the Discord id to send you service notifications by direct message and, only if you allow it on Discord's own permission screen, to add you to our Discord server. If you become a paid affiliate, a role marking that is applied to your account on our Discord server, which other members of it can see. You can revoke access at any time in Discord, and anything you send us in a Discord conversation is held on Discord's systems, not just ours.

If you dispute a payment, we send Stripe what it needs to answer the dispute: your email address, your account id and when the account was created, every record of you agreeing to the terms with the IP address and browser recorded at the time, the machines you ran with their type and region, and the metered record of what each cost. Without it we cannot answer the dispute.

When you choose a password, we check it against the Have I Been Pwned breach database using a method that sends only the first five characters of its hash. Your password, and its full hash, never leave your browser.

We do not sell personal data, and we do not share it for advertising.

4How long we keep it

Agreement records, including the IP address recorded with them: 24 months, then deleted automatically. We keep them to administer your account, to answer a bank if a payment is disputed, and to establish or defend a legal claim. Twenty-four months is several times longer than the window in which a card payment can normally be disputed, and we delete them after that rather than holding an address indefinitely for a purpose that has passed. The record of what you actually bought and spent — the ledger and the metered usage — is kept separately and for longer, under the paragraph below.

Billing and usage records are kept while your account is open and afterwards for as long as tax and accounting rules require.

Operational records are kept indefinitely. These are the log of actions taken on the platform — machines started and stopped, connections opened and the address they were opened to, security findings, and administrative actions on an account with the reason given. We keep them because they are what lets us investigate an incident or answer a dispute about something that happened long ago. They are not deleted on a timer today.

Machine contents are kept only while the disk is kept, by us. By default a disk is saved between sessions; it is deleted when you terminate the instance, when an instance without persistence reaches its twelve-hour limit, or when you leave the balance empty past the fourteen-day storage grace period. Once deleted it cannot be restored by us, and we hold no backups — see section 5 of the terms. Our infrastructure provider operates its own storage systems underneath ours, and how long data persists in those is theirs to determine, not ours — which is why we say a disk cannot be recovered by us rather than promising it has ceased to exist everywhere.

Where it is held. Machines, disks and the systems that run them are in the eastern United States. Our website, database and the other providers named above are US-based services.

5Your choices

You can export your usage history as a CSV file at any time from your usage page, and change your password from your settings. To change the email address on your account, ask us.

You can ask us to delete your account and the personal data attached to it. We will keep the billing records we are legally required to keep, and nothing else. Your unspent purchased balance is refunded — that is a commitment in section 7 of the terms, not a discretion. Promotional balance has no cash value and is not included, and a refund is never more than you have paid us.

Depending on where you live you may also have the right to a copy of your data, to correct it, or to object to how we use it. Contact us and we will action it.

6Security

Access to your account requires your password, and two-factor authentication if you enable it. Machine disks are encrypted. Your instances accept no inbound network connections except remote desktop from the single address you connect from, and only while running.

No system is perfect. If we discover a breach affecting your personal data we will tell you and the relevant regulator as the law requires.

7Contact

Questions about any of this, or to exercise any of the rights above: use the contact route for formal notices in section 15 of the terms.

Terms of Service