Privacy
Written for the person deciding whether to sign their team in, not for a lawyer.
Updated September 2026
An account is an email address, a name, a phone number and a password hash. The phone number is asked for once so an admin can reach the people they invite; it is not used for marketing. Sign in with Google sends Google your consent, not your password, and gives Kurdinator your name and address.
Everything you put into a workspace — the company profile, blueprints, projects, tasks, comments, evidence and files — belongs to that workspace and is visible only to its members according to their role. Kurdinator does not read it for any purpose other than running the product and, when you ask for help, answering you.
When you build a blueprint from your SOPs or a brief, their text is sent to the AI provider to be read and the resulting blueprint is stored in your workspace. The files themselves are not kept; their names and sizes are, so the blueprint can say what it was built from.
When the deployment has email connected, Kurdinator sends confirmation and reset letters, invitations, and letters about work that concerns you — a morning letter with what is late and due today, a task that became yours, an approval asked of you, a comment that named you, a task of yours that can start. Each person can turn the work letters off from their profile. Nothing is sent to anyone outside the workspace.
One cookie holds your session. The browser also keeps small conveniences on your device — the tab you were on, a filter, a draft. The public website carries no analytics script. The product records service events — sign-ins, plans generated, limits reached — without plan content, so the operator can see whether the service is healthy.
The planning demo on the front page is limited per network. A hashed form of the network address is kept for 24 hours to enforce that limit; nothing you type into the demo is stored.
Kurdinator shows no advertising and does not sell, rent or share what you put into it. Providers that process data on Kurdinator’s behalf — Cloudflare for hosting and files, Resend for email, the AI provider for reading documents — do so only to provide the service.
Plans export to CSV from inside the product. A full JSON export of a workspace, or the deletion of a workspace or an account, is done on request through the support desk and confirmed in writing.
Questions: write from the support desk inside the product, or through the website.