chekd — Privacy Policy
Effective July 12, 2026 · policy version 2026-07-12.1.
The one-sentence version: normal chekd evidence stays local; clearly labeled provider jobs, feedback, analytics, licensing, and optional sharing send only the data described below when you choose or use those features.
1. Who we are
chekd is operated by John Kilfoil, a solo developer based in Florida, USA (“chekd”, “we”, “us”). Contact: privacy@chekd.net.
2. What this policy covers
This policy covers (a) the chekd desktop/CLI app and its cockpit, (b) purchasing and license keys, (c) the optional paid data platform, and (d) the chekd.net website. Payments themselves are processed by LemonSqueezy as Merchant of Record under their own privacy policy and buyer terms — see §3.2 and §5.
3. What we collect, surface by surface
3.1 Normal local runs
chekd walks your web app in a browser on your machine and stores findings, corrections, screenshots, and taste data as local files in your project / ~/.chekd. Normal deterministic runs do not upload that evidence. Outbound activity is limited to the separately described features you invoke: a selected model/provider (§3.3), feedback (§3.4), opt-in cockpit analytics (§3.5), purchase/license administration (§3.2), or the optional data platform (§3.6). chekd does not silently switch providers.
3.2 Buying chekd: purchase and license data (this is the small slice we do always process)
When you buy a chekd Plus subscription, LemonSqueezy (the Merchant of Record) collects your payment details — we never see your card number. LemonSqueezy then sends us the minimum needed to deliver your license, and we store it: your email address, order ID, license key, plan, and issue date (in Cloudflare Workers KV, in the United States). We use this only to deliver your key, look it up for support (“I lost my key”), and handle refunds. License keys verify offline on your machine — using chekd does not phone home to check your license.
3.3 User-selected model providers
If you explicitly select a local or cloud model provider for a model-backed job, chekd sends that provider the evidence required for the bounded job (which may include screenshots, page content, findings, or source context). The provider processes it under its own terms and privacy policy. Your selection, payer, and cost ceiling are shown before metered work; chekd does not silently fall back to another provider.
3.4 Feedback you choose to send
When you press Send in Settings, chekd sends your feedback category and note, plus app version and coarse operating-system context, to our Cloudflare-hosted feedback store. A reply email is optional. We use feedback to respond and improve chekd; the note and email never enter analytics.
3.5 Product and website analytics
Cockpit analytics are off by default and send events only after you opt in. Allowed events contain fixed enums, counts, outcomes, version, and coarse device context; they exclude URLs, repository paths, selectors, code, finding text, email, and free-form text. The public website uses cookieless PostHog EU analytics with a random first-party identifier in local storage, page path, coarse referrer category, coarse device/browser/OS/viewport buckets, and button/section events. It does not send form contents, email, full referrer URLs, or a full user-agent string. Neither surface uses analytics for advertising or cross-site tracking.
3.6 The optional data platform: paid-plan, opt-in, all-or-nothing (currently not live)
If — and only if — you are on the paid plan and you affirmatively switch on data collection, chekd may upload a best-effort scrubbed copy of: the page content it captured, the findings it produced, and the DOM selectors involved. The switch is all-or-nothing (no partial sharing), off by default, and separate from your purchase — paying for chekd is never, by itself, agreeing to share data.
Before anything is uploaded, a client-side scrubber attempts to remove secrets (API keys, tokens, auth headers), email addresses, and values you typed into forms; the upload endpoint also refuses requests unless the body is marked scrubbed, the license is valid, and the server-side consent log contains current grants for every named purpose under the active policy version. We collect selectors and findings in preference to raw content. Every consent you give is logged per-purpose, timestamped, and stamped with the version of this policy in force — and you can turn the switch off at any time.
chekd.net is hosted on Cloudflare, whose infrastructure keeps standard server logs such as IP address and request path for security and delivery. We do not use those logs to build advertising profiles.
4. Why we collect it (named, distinct purposes)
Data-platform uploads (§3.6) are used for these specific purposes, and no others:
train-models— to train and improve chekd’s own machine-learning models (the taste/finding engine).owner-analytics— aggregate product analytics for the operator (what kinds of findings occur, detection quality), to improve the product.
Purchase/license data (§3.2) is used only to deliver, support, and administer your license.
We do not sell your data, we do not share it for cross-context behavioral advertising, and we deliberately avoid a vague “to improve our services” catch-all — every purpose is specific enough to be meaningfully agreed to. Adding a new purpose later requires your fresh, affirmative opt-in (§11).
5. Legal bases
Where the GDPR or UK GDPR applies:
- Consent (Art. 6(1)(a)) — cockpit analytics and the data platform (§3.5–3.6). You may withdraw it at any time (§8); withdrawal stops future collection immediately.
- Contract (Art. 6(1)(b)) — purchase and license data (§3.2): we can’t deliver or support your key without it.
- Legitimate interests (Art. 6(1)(f)) — fraud prevention, abuse prevention, and securing our services.
Where US state privacy laws apply, data-platform collection is strictly opt-in, and you may opt out (turn it off) at any time.
6. Who we share it with (sub-processors)
- Cloudflare, Inc. — hosting, storage (Workers KV, D1, R2), and content delivery. Data is stored in the United States.
- LemonSqueezy, LLC (Merchant of Record, on Stripe) — payment processing, billing, sales tax/VAT, refunds, and chargebacks. They receive purchase/billing data as the merchant you transact with; they do not receive your app-content uploads.
- PostHog, Inc. — cookieless product and website analytics hosted in the EU region, subject to the controls and exclusions in §3.5.
We do not sell personal information or share it for cross-context behavioral advertising. We update this list before adding a processor that handles covered data.
7. Where it’s stored & how long
Purchase, license, feedback, and optional data-platform records are stored in the United States on Cloudflare; analytics is processed in PostHog’s EU region. Data is encrypted in transit (TLS) and, where the service provides it, at rest.
- Purchase/license records: kept while your license is active plus as long as tax, accounting, or dispute rules require.
- Data-platform uploads: kept only as long as needed for the purposes in §4, then deleted when no longer needed for those purposes; you can also delete yours at any time (§8).
- Feedback: kept while needed to respond, diagnose, and maintain an abuse/security record, then deleted or de-identified.
- Analytics: retained under our configured PostHog retention settings and deleted or aggregated when no longer needed for product measurement.
8. Your rights & controls
Regardless of where you live, you can:
- Turn collection off at any time (Settings → Data) — uploads stop immediately.
- Delete your collected data and/or your account.
- Access / export the data associated with you.
- Correct the purchase/license record we hold (e.g., an email change).
Email privacy@chekd.net to exercise any right; we will verify the request (typically by matching your license email) and respond within the timeframe the applicable law requires (e.g., 30 days under GDPR, 45 days under CCPA-style laws). We will never discriminate against you — in price, features, or support — for exercising a privacy right. EU/UK users additionally have the GDPR rights to rectification, restriction, objection, portability, and to lodge a complaint with a supervisory authority. Where a law gives effect to browser opt-out signals (such as Global Privacy Control), note that chekd’s surfaces do no cross-site tracking for such signals to opt out of.
9. International users
Cloudflare-hosted purchase, feedback, and optional platform records may be transferred to and stored in the United States; PostHog analytics is processed in its EU region. Where transfer law applies, we rely on the transfer mechanism used by the relevant processor and, for an optional data-platform upload where appropriate, your explicit informed consent. You may withdraw optional consent at any time. Business customers may request available processor terms and data-transfer information.
10. Security & incidents
Data in our custody is encrypted in transit (TLS) and at rest, access to production systems is limited to the operator, and payment card data never touches our systems (LemonSqueezy/Stripe are PCI-compliant processors). No system is perfectly secure; if a breach affects your personal data, we will notify you and the relevant authorities as the applicable law requires.
11. Changes
If we make a material change to what we collect or why, we will re-request your consent — your prior opt-in does not roll over to a new purpose or practice (this is enforced in the product: consents are stamped with a policy version, and a version bump forces re-consent). We’ll update the policy version and effective date at the top of this policy, and keep prior versions available on request.
12. Children
chekd is not directed to children under 13 (or the higher minimum age your jurisdiction sets for consent) and we do not knowingly collect their data. If you believe a child has given us personal data, email privacy@chekd.net and we will delete it.
13. Contact
privacy@chekd.net