Legal
Privacy Policy
Last updated: 8 May 2026
MyKudos is built on a simple principle: your reputation data is yours. We collect only what we need to run the service, store it securely in the EU, and never sell it. This policy explains what we collect, why, and what you can do about it.
1. What we collect
LinkedIn profile data - When you sign in with LinkedIn, we receive your name, profile photo, email address, and LinkedIn profile URL. We do not receive your password, your connections, or your messages.
Kudos content- The text written by your colleagues when they submit a kudo through your request link. This includes the written testimonial and the relationship context (e.g. “Peer” or “Manager”).
Request data - Recipient names (first name only for quick links, full name and email for direct email requests), the message you crafted, and the channel you used to share the link.
Session data - A secure session token stored in an HTTP-only cookie to keep you signed in. No tracking cookies, no analytics cookies.
2. Why we collect it
LinkedIn data is used to verify that kudos come from real, identifiable people - not anonymous submissions. The verification is the core trust signal of the product.
Kudos content is stored so you can build and manage your reputation library over time.
Request data lets us send branded email requests on your behalf and track the status of outstanding requests in your dashboard.
Session datakeeps you signed in so you don't have to authenticate on every visit.
3. Where your data lives
All data is stored in Supabase, hosted on AWS infrastructure in the EU (Ireland, eu-west-1). Your data does not leave the European Economic Area.
Transactional emails are sent via Resend, whose infrastructure is EU-compliant. Only the minimum necessary data (recipient email, sender name, the request link) is passed to Resend per email send.
4. Who has access
You - You can see all your data in your dashboard. Your kudos are private by default. Nothing is published without your explicit action.
Giver of a kudo - The person who wrote the kudo can see their own submission. They cannot see other kudos in your library.
MyKudos team - We have access to the database for operational purposes (bug fixes, support requests). We do not read kudo content unless you ask us to investigate a specific issue.
We never sell, rent, or share your data with advertisers or data brokers.
6. If a kudo is about you
If someone has written a kudo about you that you believe is inaccurate, defamatory, or unauthorized, you may request removal by contacting privacy@mykudos.club. Please include:
- The relevant URL - your dashboard if you're the recipient, or a public pack URL if you've seen it shared.
- A description of the issue and why you believe the content is problematic.
- Verification of your identity - for example, a LinkedIn profile URL or a message sent from the same email address you used to authenticate.
We respond within 7 business days and will notify you of the outcome.
7. Data tracked on verified pack views
When someone views a verified pack at /v/[token], we track:
- Total view count
- First viewed timestamp
- Last viewed timestamp
We do not track:
- Viewer identity - no fingerprinting, no IP logging.
- Which specific kudos were clicked or read.
- Time spent on the page.
- Device information beyond what is necessary for the page to render.
This minimal tracking exists so the sender knows their pack was opened. It is not analytics and is not shared with third parties.
8. Product Analytics
We track product events to understand how MyKudos is used and to improve the product. The events table records:
- When users sign up, complete onboarding, create asks, receive kudos, and create or share reference packs.
- For verified Reference Pack views: Reference Pack ID, sender ID, view count, and timestamps only - never viewer identity, IP address, or fingerprint.
- Event properties such as themes, languages, channels used (for example WhatsApp vs email), and counts.
We do not use third-party analytics like Google Analytics. All event data lives in our own database (Supabase EU).
You can request a copy or deletion of your event data at privacy@mykudos.club.
9. AI Features
MyKudos uses Anthropic's Claude API to generate text suggestions such as positioning statements and cover note drafts. Only text you personally write or paste (such as job descriptions or your own notes) is sent to Anthropic. We never send kudos content, giver names, or any third-party personal data to Anthropic's API. Anthropic processes this data in accordance with their privacy policy at anthropic.com/privacy.
10. Giver rights
If you wrote a kudo and want it removed, you may email privacy@mykudos.club from the same address you used to authenticate with LinkedIn. Please include:
- The name of the recipient.
- The approximate date you submitted the kudo.
We will remove the kudo from the recipient's library within 7 business days. Please note: if the recipient has already shared the kudo in a verified pack, that pack may continue to display the content until the sender regenerates or revokes it. We will inform the recipient of the removal request.
11. Your rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) - You can request a copy of all personal data we hold about you.
- Right to rectification (Art. 16) - You can correct inaccurate data directly in your profile settings.
- Right to erasure (Art. 17) - You can delete your account and all associated data by emailing privacy@mykudos.club.
- Right to data portability (Art. 20) - You can request an export of your kudos in a machine-readable format.
- Right to object (Art. 21) - You can object to processing based on legitimate interest by contacting us.
To exercise any of these rights, email privacy@mykudos.club. We will respond within 30 days.
12. Legal basis for processing
We process your personal data under two legal bases as defined in GDPR Art. 6:
Contract performance (Art. 6(1)(b)) - Processing your name, email, and LinkedIn identity is necessary to provide the MyKudos service you signed up for, including verifying your identity and delivering kudo requests.
Legitimate interest (Art. 6(1)(f)) - We retain request logs and usage patterns to maintain service quality, prevent abuse, and improve the product. We do this only where your interests and rights do not override our legitimate interest.
13. Data retention
We keep your data for as long as your account is active. When you delete your account, all personal data is permanently deleted within 30 days.
Kudos content that was sent to you by a colleague remains in your library until you archive or delete it, or until you delete your account.
15. Processors (subprocessors) / Auftragsverarbeiter
Deutsch
Wir nutzen folgende Auftragsverarbeiter zur Erbringung unserer Dienste. Mit allen wurde ein Auftragsverarbeitungsvertrag (DSGVO Art. 28) abgeschlossen:
- Supabase Inc. (USA, Datenverarbeitung in der EU/Irland) — Datenbank, Authentifizierung, Speicher
- Vercel Inc. (USA) — Hosting, Edge-Auslieferung
- Resend (USA) — Transaktionale E-Mails
- Anthropic PBC (USA) — KI-Verarbeitung von Nutzerinhalten (z. B. Verfeinerung von Texten)
- Upstash Inc. (USA, Datenverarbeitung in EU/Frankfurt) — Rate-Limiting
- LinkedIn Corporation (USA / Irland) — OIDC-Login (separater Verantwortlicher)
Für Übermittlungen in die USA stützen wir uns auf die EU-Standardvertragsklauseln (Beschluss 2021/914).
English
We use the following processors to operate our service. A Data Processing Agreement (Art. 28 GDPR) is in place with each:
- Supabase Inc. (USA, data processing in EU/Ireland) — database, authentication, storage
- Vercel Inc. (USA) — hosting, edge delivery
- Resend (USA) — transactional email
- Anthropic PBC (USA) — AI processing of user content (e.g. text refinement)
- Upstash Inc. (USA, data processing in EU/Frankfurt) — rate limiting
- LinkedIn Corporation (USA / Ireland) — OIDC login (independent controller)
For transfers to the USA we rely on the EU Standard Contractual Clauses (Decision 2021/914).
16. Security measures / Sicherheitsmaßnahmen
Wir setzen technische und organisatorische Maßnahmen ein, um deine Daten zu schützen. Dazu gehören Verschlüsselung in der Übertragung (TLS), Verschlüsselung gespeicherter Daten, datenbankweite Zugriffskontrolle (Row Level Security), Audit-Logging, Rate Limiting, regelmäßige verschlüsselte Backups, sowie Zugriffsbeschränkungen.
We use technical and organizational measures to protect your data, including encryption in transit (TLS), encryption at rest, database-level access control (Row Level Security), audit logging, rate limiting, regular encrypted backups, and access restrictions.
17. Third parties mentioned in kudos / Drittpersonen in Kudos
Kudos können Personen erwähnen, die selbst keine Nutzer:innen von MyKudos sind. Wenn du in einem Kudo erwähnt wirst und möchtest, dass dein Name entfernt oder anonymisiert wird, schreib uns an hello@mykudos.club. Wir bearbeiten solche Anfragen innerhalb von 14 Tagen.
Kudos may mention individuals who are not themselves MyKudos users. If you are mentioned in a kudo and want your name removed or anonymized, contact hello@mykudos.club. We process such requests within 14 days.
18. Deletion by kudo givers / Löschung durch Kudo-Geber:innen
Wenn jemand einen Kudo für dich geschrieben hat und diesen später vollständig löschen lassen möchte, wird der gesamte Kudo aus deiner Bibliothek entfernt. Wir können nicht einseitig den Inhalt behalten, wenn die schreibende Person ihre Einwilligung zurückzieht.
If someone has written a kudo for you and later requests its deletion, the entire kudo will be removed from your library. We cannot unilaterally retain the content if the writer withdraws their consent.
19. How to delete your data
Email privacy@mykudos.club with the subject line “Delete my account” from the email address associated with your account. We will permanently delete all your data within 30 days and confirm when it's done.
20. Contact
For privacy questions, data requests, or GDPR complaints: privacy@mykudos.club
You also have the right to lodge a complaint with the relevant data protection authority in your EU member state.