Legal

Privacy Policy

Last updated: 8 May 2026

MyKudos is built on a simple principle: your reputation data is yours. We collect only what we need to run the service, store it securely in the EU, and never sell it. This policy explains what we collect, why, and what you can do about it.

1. What we collect

LinkedIn profile data - When you sign in with LinkedIn, we receive your name, profile photo, email address, and LinkedIn profile URL. We do not receive your password, your connections, or your messages.

Kudos content- The text written by your colleagues when they submit a kudo through your request link. This includes the written testimonial and the relationship context (e.g. “Peer” or “Manager”).

Request data - Recipient names (first name only for quick links, full name and email for direct email requests), the message you crafted, and the channel you used to share the link.

Session data - A secure session token stored in an HTTP-only cookie to keep you signed in. No tracking cookies, no analytics cookies.

2. Why we collect it

LinkedIn data is used to verify that kudos come from real, identifiable people - not anonymous submissions. The verification is the core trust signal of the product.

Kudos content is stored so you can build and manage your reputation library over time.

Request data lets us send branded email requests on your behalf and track the status of outstanding requests in your dashboard.

Session datakeeps you signed in so you don't have to authenticate on every visit.

3. Where your data lives

All data is stored in Supabase, hosted on AWS infrastructure in the EU (Ireland, eu-west-1). Your data does not leave the European Economic Area.

Transactional emails are sent via Resend, whose infrastructure is EU-compliant. Only the minimum necessary data (recipient email, sender name, the request link) is passed to Resend per email send.

4. Who has access

You - You can see all your data in your dashboard. Your kudos are private by default. Nothing is published without your explicit action.

Giver of a kudo - The person who wrote the kudo can see their own submission. They cannot see other kudos in your library.

MyKudos team - We have access to the database for operational purposes (bug fixes, support requests). We do not read kudo content unless you ask us to investigate a specific issue.

We never sell, rent, or share your data with advertisers or data brokers.

5. Content authorship

Kudos are user-generated content. MyKudos does not author, curate, edit, or verify the substance of any kudo. We verify only the LinkedIn identity of the giver at the moment of writing - confirming who they are, not what they wrote.

The truthfulness of any claim within a kudo is the responsibility of the giver, not MyKudos. Recruiters and hiring managers who view a verified pack should treat kudo content as the personal opinion of the giver.

6. If a kudo is about you

If someone has written a kudo about you that you believe is inaccurate, defamatory, or unauthorized, you may request removal by contacting privacy@mykudos.club. Please include:

  • The relevant URL - your dashboard if you're the recipient, or a public pack URL if you've seen it shared.
  • A description of the issue and why you believe the content is problematic.
  • Verification of your identity - for example, a LinkedIn profile URL or a message sent from the same email address you used to authenticate.

We respond within 7 business days and will notify you of the outcome.

7. Data tracked on verified pack views

When someone views a verified pack at /v/[token], we track:

  • Total view count
  • First viewed timestamp
  • Last viewed timestamp

We do not track:

  • Viewer identity - no fingerprinting, no IP logging.
  • Which specific kudos were clicked or read.
  • Time spent on the page.
  • Device information beyond what is necessary for the page to render.

This minimal tracking exists so the sender knows their pack was opened. It is not analytics and is not shared with third parties.

8. Product Analytics

We track product events to understand how MyKudos is used and to improve the product. The events table records:

  • When users sign up, complete onboarding, create asks, receive kudos, and create or share reference packs.
  • For verified Reference Pack views: Reference Pack ID, sender ID, view count, and timestamps only - never viewer identity, IP address, or fingerprint.
  • Event properties such as themes, languages, channels used (for example WhatsApp vs email), and counts.

We do not use third-party analytics like Google Analytics. All event data lives in our own database (Supabase EU).

You can request a copy or deletion of your event data at privacy@mykudos.club.

9. AI Features

MyKudos uses Anthropic's Claude API to generate text suggestions such as positioning statements and cover note drafts. Only text you personally write or paste (such as job descriptions or your own notes) is sent to Anthropic. We never send kudos content, giver names, or any third-party personal data to Anthropic's API. Anthropic processes this data in accordance with their privacy policy at anthropic.com/privacy.

10. Giver rights

If you wrote a kudo and want it removed, you may email privacy@mykudos.club from the same address you used to authenticate with LinkedIn. Please include:

  • The name of the recipient.
  • The approximate date you submitted the kudo.

We will remove the kudo from the recipient's library within 7 business days. Please note: if the recipient has already shared the kudo in a verified pack, that pack may continue to display the content until the sender regenerates or revokes it. We will inform the recipient of the removal request.

11. Your rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15) - You can request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16) - You can correct inaccurate data directly in your profile settings.
  • Right to erasure (Art. 17) - You can delete your account and all associated data by emailing privacy@mykudos.club.
  • Right to data portability (Art. 20) - You can request an export of your kudos in a machine-readable format.
  • Right to object (Art. 21) - You can object to processing based on legitimate interest by contacting us.

To exercise any of these rights, email privacy@mykudos.club. We will respond within 30 days.

13. Data retention

We keep your data for as long as your account is active. When you delete your account, all personal data is permanently deleted within 30 days.

Kudos content that was sent to you by a colleague remains in your library until you archive or delete it, or until you delete your account.

14. Cookies

We use one essential cookie: a secure, HTTP-only session cookie to keep you signed in. This cookie contains no personal data beyond a session identifier.

We do not use advertising cookies, third-party tracking cookies, or analytics cookies that identify you across the web. No cookie consent banner is required because we only set strictly necessary cookies.

15. Processors (subprocessors) / Auftragsverarbeiter

Deutsch

Wir nutzen folgende Auftragsverarbeiter zur Erbringung unserer Dienste. Mit allen wurde ein Auftragsverarbeitungsvertrag (DSGVO Art. 28) abgeschlossen:

  • Supabase Inc. (USA, Datenverarbeitung in der EU/Irland) — Datenbank, Authentifizierung, Speicher
  • Vercel Inc. (USA) — Hosting, Edge-Auslieferung
  • Resend (USA) — Transaktionale E-Mails
  • Anthropic PBC (USA) — KI-Verarbeitung von Nutzerinhalten (z. B. Verfeinerung von Texten)
  • Upstash Inc. (USA, Datenverarbeitung in EU/Frankfurt) — Rate-Limiting
  • LinkedIn Corporation (USA / Irland) — OIDC-Login (separater Verantwortlicher)

Für Übermittlungen in die USA stützen wir uns auf die EU-Standardvertragsklauseln (Beschluss 2021/914).

English

We use the following processors to operate our service. A Data Processing Agreement (Art. 28 GDPR) is in place with each:

  • Supabase Inc. (USA, data processing in EU/Ireland) — database, authentication, storage
  • Vercel Inc. (USA) — hosting, edge delivery
  • Resend (USA) — transactional email
  • Anthropic PBC (USA) — AI processing of user content (e.g. text refinement)
  • Upstash Inc. (USA, data processing in EU/Frankfurt) — rate limiting
  • LinkedIn Corporation (USA / Ireland) — OIDC login (independent controller)

For transfers to the USA we rely on the EU Standard Contractual Clauses (Decision 2021/914).

16. Security measures / Sicherheitsmaßnahmen

Wir setzen technische und organisatorische Maßnahmen ein, um deine Daten zu schützen. Dazu gehören Verschlüsselung in der Übertragung (TLS), Verschlüsselung gespeicherter Daten, datenbankweite Zugriffskontrolle (Row Level Security), Audit-Logging, Rate Limiting, regelmäßige verschlüsselte Backups, sowie Zugriffsbeschränkungen.

We use technical and organizational measures to protect your data, including encryption in transit (TLS), encryption at rest, database-level access control (Row Level Security), audit logging, rate limiting, regular encrypted backups, and access restrictions.

17. Third parties mentioned in kudos / Drittpersonen in Kudos

Kudos können Personen erwähnen, die selbst keine Nutzer:innen von MyKudos sind. Wenn du in einem Kudo erwähnt wirst und möchtest, dass dein Name entfernt oder anonymisiert wird, schreib uns an hello@mykudos.club. Wir bearbeiten solche Anfragen innerhalb von 14 Tagen.

Kudos may mention individuals who are not themselves MyKudos users. If you are mentioned in a kudo and want your name removed or anonymized, contact hello@mykudos.club. We process such requests within 14 days.

18. Deletion by kudo givers / Löschung durch Kudo-Geber:innen

Wenn jemand einen Kudo für dich geschrieben hat und diesen später vollständig löschen lassen möchte, wird der gesamte Kudo aus deiner Bibliothek entfernt. Wir können nicht einseitig den Inhalt behalten, wenn die schreibende Person ihre Einwilligung zurückzieht.

If someone has written a kudo for you and later requests its deletion, the entire kudo will be removed from your library. We cannot unilaterally retain the content if the writer withdraws their consent.

19. How to delete your data

Email privacy@mykudos.club with the subject line “Delete my account” from the email address associated with your account. We will permanently delete all your data within 30 days and confirm when it's done.

20. Contact

For privacy questions, data requests, or GDPR complaints: privacy@mykudos.club

You also have the right to lodge a complaint with the relevant data protection authority in your EU member state.