Skip to content
cairnkit cloud

Privacy

cairnkit cloud records how your product tours performed. It is not an advertising product, it does not follow anybody between sites, and there is no third-party tracker on this page.

Last updated 14 August 2026

The short version

Your tours stay in your repository. We record events describing what happened when one ran — which step was reached, which finished, which pointed at UI that was not there — and nothing about the person beyond a random session id, unless you deliberately send us your own user id.

What the SDK sends us

When you install @cairnkit/cloud and set a publishable key, each tour signal becomes one event. Every event carries:

  • What happened — the event name, the flow id, its version, the step index, the anchor it looked for, and the path it happened on
  • Why it ended, where it ended — skipped, closed, or dismissed with the keyboard
  • A session id — opaque, random, generated in the browser and kept in localStorage for 30 minutes of inactivity. It is not a cookie and not a user id
  • A run id, so starting the same tour twice reads as two attempts rather than one confused sequence
  • Device class and viewport size — mobile, tablet or desktop, derived from the window width at the moment of the event
  • The origin the request came from

User ids, only if you send them

Sessions expire, so one person across two days looks like two people. If you need to tell them apart you can pass an id you already hold. This is the one field in the product that is personal data, which is why it is off unless you turn it on, and why cairnkit does not invent a durable device id of its own instead.

Send an internal id, never an email address. Deleting a project deletes them with it.

What your tours say

If you call reportFlows, we also store the wording of each step — the title, the body, the anchor and the order — so the dashboard can show a tour in the words a reader sees instead of ids and indices. That is copy you wrote for your own users, and we treat it as yours.

What we deliberately do not collect

  • No user agent string
  • No IP-derived location. We do not store the IP address the event arrived from
  • No page content, screenshots, or session replay
  • No cookies for tracking, and nothing that follows anyone between sites
  • No third-party analytics, tag manager, or advertising pixel — on this site either

Your account

To run the service we store your email address, your name if you give one, your workspace name and handle, and — if you enable domain joining — the email domain you verified. Your password is handled by our authentication provider and never reaches our own database.

If you connect Slack, we store the webhook URL encrypted at rest and the channel name for display. The webhook is a credential belonging to you; it is never shown in a browser again after it is saved, and disconnecting deletes it.

Who else touches it

ProcessorWhat for
SupabaseDatabase and authentication
VercelHosting and the scheduled jobs
ResendAccount email — confirmations and security notices
SlackOnly if you connect a channel, and only what the alert says

We do not sell data, and we do not share it with anyone not in that table.

How long we keep it

Events are kept while the project exists. Deleting a project removes every event recorded for it immediately, with no scheduled grace period and no backup copy to restore from; deleting a workspace does the same for every project in it, along with its keys, its Slack connection and everyone's access.

Your rights

You can export, correct or delete your data at any time, and deletion in the product is real deletion rather than a flag. If you would rather we did it for you, or you want a copy of what we hold, write to hello@cairnkit.dev and we will answer within 30 days.

If you are a customer's end user rather than a customer — that is, you saw a product tour somewhere — we hold no way to identify you, and the company whose product you were using is the right place to ask. We will help them answer.

Changes

If this policy changes in a way that affects what we collect, we will say so here and date it. The version you are reading is dated at the top.

Contact

hello@cairnkit.dev reaches us, and is read by a person.