PRIVACY POLICY - ClaudeKit
Last updated: September 16, 2026
Effective date: September 16, 2026
1. INTRODUCTION
ClaudeKit ("we", "our", or "us") operates the ClaudeKit browser extension ("the Extension"), the optional ClaudeKit web workspace, api.claudekit.app, and the ClaudeKit website. This policy explains what information these services handle, why they handle it, where it is stored, and the choices available to you.
ClaudeKit is local by default. Settings, exports, and ordinary Claude-to-Claude forks stay on your device. If you create a ClaudeKit account and pair the Extension, selected structured data such as usage snapshots, saved prompts, device details, and entitlement status can sync to your workspace. Conversation transcripts are not included in workspace sync.
2. INFORMATION THE EXTENSION HANDLES
2a. Claude account context and usage data
The Extension reads Claude's lastActiveOrgcookie to identify the active Claude organization, then requests session and weekly utilization data from Claude's own API. The Extension does not read passwords or authentication tokens, does not modify the cookie, and does not send the cookie or Claude organization ID to ClaudeKit servers. Usage history is stored locally unless you pair the Extension with a ClaudeKit workspace, in which case structured percentage and reset-time snapshots are also stored for your account.
2b. Website and conversation content used locally
To provide token counting, exports, prompt saving, and conversation forking, the Extension reads content from the Claude page you are using. This content is processed locally unless you explicitly start a Pro cross-LLM handoff. When you use a right-click Claude action on another website, the selected text is sent directly to Claude at your request; it is not sent to ClaudeKit servers.
2c. Data stored on your device
- Extension settings, notification preferences, and badge position
- Saved prompts and prompt categories
- Aggregated usage history and reset-notification state
- Cached entitlement status, transfer preferences, and the anonymous install ID
- Conversation exports you choose to create
2d. ClaudeKit service records
The Extension uses a randomly generated install ID that is not based on your name, email, Claude account, or device hardware. The ClaudeKit API stores the install ID and timestamps; Pro plan, entitlement, billing period, and renewal status where applicable; Dodo customer, subscription, and payment identifiers when applicable; fork type, destination, date, and timestamp; and webhook ID, event type, and receipt time. These records support licensing, quota enforcement, billing lifecycle updates, abuse prevention, and operational support.
2e. Pro cross-LLM handoff processing
When you explicitly start a Pro handoff to ChatGPT, Gemini, xAI, DeepSeek, or Grok, the selected Claude conversation is sent over HTTPS to api.claudekit.app and processed by Cloudflare Workers AI to create a compact handoff summary. The summary is returned to the Extension for copying or optional auto-paste.
ClaudeKit does not write conversation transcripts or generated summaries to D1, KV, R2, object storage, analytics, or application logs. Operational logs may include non-content metadata such as the destination, AI model, input and output character counts, processing duration, chunking status, event type, and error state. Cloudflare states that Workers AI customer content is not used to train Workers AI models or improve Cloudflare or third-party services without explicit consent.
2f. Clipboard and optional destination-site access
The Extension can write prepared fork or handoff text to your clipboard but does not read your clipboard. If you enable auto-paste, the Extension requests optional access to supported destination sites and uses that access only to fill the destination message composer. It does not press Send, start a model response, or read destination conversations. Disabling auto-paste removes this optional site access.
2g. Billing information
Dodo Payments acts as the payment provider and merchant of record for ClaudeKit Pro and blog sponsor subscriptions. Dodo may collect contact, billing, payment, tax, fraud-prevention, and transaction information under its own privacy policy. ClaudeKit receives only the records needed to manage access, such as a Dodo customer ID, subscription or payment ID, plan, entitlement status, billing period, renewal date where applicable, and signed webhook event identifiers. ClaudeKit does not receive or store full card numbers or bank credentials.
2h. Network and security metadata
Like other internet services, Cloudflare processes network information such as IP address, request headers, user agent, and security signals to route and protect requests. ClaudeKit does not write IP addresses to its application database or use them for advertising or user profiling.
2i. Optional web workspace and sync
When you create a ClaudeKit account, we process your email address, optional display name, authentication session, plan status, connected-device name, browser and Extension version, last-sync time, structured usage percentages and reset times, and prompts you choose to save to the cloud library. Pairing codes expire quickly, and device access tokens are stored only as one-way hashes. ClaudeKit does not request your Claude password or store Claude session cookies.
3. WEBSITE DATA
The ClaudeKit website uses Umami Cloud and Google Analytics for website analytics. Umami processes page paths, referrers, browser, operating system, device type, screen size, language, approximate country or region, UTM campaign parameters, session duration, and selected events such as install-link clicks, page reads, and form-success events. Google Analytics may process page URL, referrer, browser and device data, approximate location, session data, and cookies or similar identifiers. ClaudeKit disables Google ad-personalization signals in its Google Analytics configuration. ClaudeKit does not send names, email addresses, conversation content, or extension install IDs to website analytics providers. Umami uses IP addresses to derive anonymous session and approximate-location metrics but states that it does not store the IP address.
ClaudeKit also runs a first-party daily visitor counter for public social proof. The browser creates a random local identifier and sends it to ClaudeKit's website API. The API stores only a one-day hash of that identifier, the date, last seen time, last page path, and page-view count in ClaudeKit's Supabase Postgres database. ClaudeKit does not store IP addresses in this table, and the one-day hash is not designed to identify a visitor across different days.
ClaudeKit sells a small number of direct sponsor placements on public blog pages. Sponsored links are clearly labeled and do not use an advertising network, behavioral targeting, or sponsor-provided tracking pixels. ClaudeKit may measure aggregate placement views and link clicks through its website analytics. When you follow a sponsor link, the sponsor's site receives the information normally sent with a web request and applies its own privacy policy.
Sponsor checkout forms collect the buyer's name and email, sponsor or product name, destination URL, and short sponsor message. ClaudeKit stores this information in Cloudflare D1 with reservation, checkout-session, customer, and subscription identifiers so it can prevent double booking, verify payment, publish the placement, and remove it when billing is no longer active.
Some ClaudeKit articles contain affiliate marketing links. This means ClaudeKit may receive a commission when you purchase a product or service through an eligible link, at no additional cost to you. Affiliate relationships do not determine ClaudeKit's editorial recommendations. ClaudeKit uses Skimlinks and its affiliates (the "Skimlinks Group") to identify eligible merchant links, attribute referrals, and report commissions.
Skimlinks may process page and link information, referral and merchant details, device and browser information, IP address, and transaction attribution data. Its automated technologies include SkimJS and Link Wrapper. Skimlinks states that the third-party t_gid cookie may be used outside the UK and EMEA. More information is available in the Skimlinks and Taboola privacy policies linked below.
Some website forms are processed by Formspree. Depending on the form, this may include information you voluntarily submit such as name, email, profession, country, interests, uninstall reason, and feedback. Form submissions are separate from Extension data and are used only to provide requested resources, respond to feedback, or send the ClaudeKit updates described next to the form. You can ask us to delete a submission or unsubscribe from future email.
Website polls and interest checks may store the selected option, poll identifier, timestamp, and any optional email you submit in ClaudeKit's Supabase Postgres database. Poll responses are separate from Extension data and are used only to evaluate interest in possible ClaudeKit features or follow up with people who ask to hear more.
UTM campaign parameters are stored in your browser's session storage for attribution during the current browser session. The ClaudeKit Extension does not use advertising cookies, and direct blog sponsorships do not add sponsor tracking pixels. Google Analytics ad-personalization signals are disabled in ClaudeKit's analytics configuration.
4. HOW WE USE INFORMATION
- Provide usage tracking, reset alerts, token counting, exports, prompt saving, and forks
- Create a requested cross-LLM handoff and optionally place it in a destination composer
- Verify Pro access, enforce quotas, and synchronize billing lifecycle changes
- Authenticate workspace accounts and sync selected prompts, devices, and usage snapshots
- Secure, debug, maintain, and improve ClaudeKit without logging conversation content
- Measure aggregate website traffic and understand which public pages and campaigns work
- Process requested resources, support messages, interest forms, and uninstall feedback
- Comply with legal, tax, payment, fraud-prevention, and security obligations
We do not sell personal information, use Extension data for advertising, build advertising profiles, or use conversation content to train AI models.
5. SHARING AND PROCESSORS
We share information only as needed to provide the requested services:
- Anthropic: Claude usage requests and user-requested Claude actions
- Cloudflare: website and API delivery, security, Workers AI inference, D1 storage for website counters, polls, and sponsor placements, and legacy Extension entitlement storage during migration
- Supabase: account authentication and Postgres storage for SaaS workspace data
- Dodo Payments: checkout, subscription, tax, fraud, and payment processing
- Umami Cloud: anonymous, cookie-free website analytics
- Google Analytics: website traffic and page analytics with ad-personalization signals disabled
- Skimlinks: affiliate-link identification, referral attribution, reporting, and commission processing
- Formspree: website form delivery and storage
We may also disclose information when required by law, to protect users or the service, or as part of a business transfer subject to applicable privacy obligations. We do not sell or rent Extension data to data brokers or advertisers.
6. RETENTION
- Local Extension data: retained until you clear it or uninstall ClaudeKit
- Conversation transcripts and AI summaries: processed for the requested handoff and not retained in ClaudeKit application storage or logs
- Install, entitlement, fork, and webhook records: retained while needed to operate licensing, subscriptions, quota enforcement, security, support, and legal obligations
- Billing records: retained by ClaudeKit and Dodo as required for subscriptions, one-time purchases, tax, disputes, fraud prevention, and other legal obligations
- Sponsor creative: retained while a placement is active and as needed for billing, support, disputes, and legal records
- Workspace account and sync data: retained while your account is active or until you delete the data, subject to limited security, backup, and legal retention
- Website analytics: retained according to ClaudeKit's Umami Cloud and Google Analytics settings
- Daily visitor counter: retained in ClaudeKit's Supabase Postgres database for up to 90 days
- Affiliate attribution: retained according to Skimlinks' publisher and privacy terms
- Website polls and interest checks: retained while needed to evaluate product interest or follow up with people who ask to hear more
- Website forms and email: retained while needed to provide the requested follow-up, maintain records, or satisfy legal obligations
Where a record is no longer needed, we delete or anonymize it. Some records may be retained longer when required by law, payment rules, security needs, dispute handling, or backup cycles.
7. SECURITY AND INTERNATIONAL PROCESSING
ClaudeKit uses HTTPS for server transmissions, signed payment webhooks, restricted secrets, and provider access controls. No system can guarantee absolute security, so please avoid including secrets or information you do not want processed in a cross-LLM handoff.
ClaudeKit and its providers may process information in countries other than your own. Where required, providers use contractual and legal safeguards for international transfers.
8. YOUR RIGHTS AND CHOICES
- Clear local Extension data or uninstall ClaudeKit
- Decline or remove optional notification and auto-paste permissions
- Use manual clipboard mode instead of destination-site access
- Request access, correction, or deletion of ClaudeKit server records and website submissions
- Disconnect a paired browser or delete cloud-synced prompts from the workspace
- Unsubscribe from non-transactional email using the link provided or by contacting us
To help us locate Extension records, include your ClaudeKit install ID. For billing requests, include the email used at checkout. We may need to verify a request and may retain records where required by law. Depending on where you live, you may also have rights to object, restrict processing, receive a portable copy, or complain to a data-protection authority.
9. CHILDREN'S PRIVACY
ClaudeKit is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can review and delete it where appropriate.
10. THIRD-PARTY POLICIES
11. CHANGES TO THIS POLICY
We may update this policy when ClaudeKit's features, providers, or legal obligations change. Material changes to Extension data practices will also be disclosed through the Extension or its store listing when required. The date at the top shows the latest revision.
12. CONTACT
Email: avishshah1108@gmail.com
Website: claudekit.app