Skip to content

Legal

Privacy policy

Last updated 25 September 2026

This is a plain-language summary; the full terms will be published soon. KanMaps will tell every workspace owner by email at least 30 days before any change takes effect.

KanMaps collects as little as it can to run skill-tree roadmaps for you and your customers. This page explains what we store, why, and what you can do about it.

If you have an account

We store your name, email address, a hashed password (or the fact that you sign in with Google or GitHub), your profile picture if you upload one, your sessions and your notification preferences.

We use your email to sign you in, to send invitations you ask us to send, and to send the notifications you have switched on — mentions, replies, things you backed shipping. You can switch notification emails off in your account.

If you visit a public roadmap

You don’t need an account to spend votes. Your browser keeps a random token and we store only a keyed hash of it, so your votes stay yours on that device. For abuse prevention we keep a daily-salted hash of your IP address, never the address itself.

Guests who comment or suggest an idea give a display name only — we never ask guests for an email address. If you sign in later, your votes and suggestions move to your account.

Cookies and local storage

We use a small number of first-party cookies: your sign-in session, a cookie that remembers that you unlocked a password-protected map or opened a share link, and a first-touch attribution cookie (for example “came from a Made with KanMaps badge”) that expires after 30 days.

Your browser’s local storage remembers view preferences, staged Build-mode votes and what you have already seen, so we can show “since your last visit”. There are no third-party advertising or tracking cookies.

Product analytics

We record a short list of first-party product events — such as “landing page viewed”, “map published” or “upgrade started” — to understand how people use KanMaps. These events are stored by us, not sent to an analytics company, and are never used for advertising.

Who processes data for us

KanMaps runs on Cloudflare (hosting, database, file storage and realtime). Payments are handled by Stripe — we never see or store card numbers. If email delivery is configured, messages are sent through our email provider. Each processor only handles data needed for its job.

Your choices and rights

You can export any map, edit or delete your comments, change your email, unlink Google or GitHub, and delete your account from Account settings. Deleting your account removes your profile and sessions; comments you wrote are kept anonymised so conversations still make sense.

For anything else — a copy of your data, a correction, a question — write to support@kanmaps.app.

How long we keep things

Maps you delete stay in the trash for 30 days and are then removed. Sessions expire on their own. Anonymous voter records are kept while the votes they hold can still be refunded. Workspace billing records are kept as long as tax law requires.

Changes to this policy

If we change how we handle personal data we will update this page and, for meaningful changes, tell account holders by email. See also the terms of service.

Questions about this page? Write to support@kanmaps.app.