KillSesh ("we", "us", "our") operates the KillSesh security platform at killsesh.com. This policy explains what data we collect, why, and how we protect it.
Account information: Email address and authentication tokens when you sign up.
Email metadata (with your permission): When you connect a Gmail or Outlook account, we access email headers, sender addresses, and subject lines to scan for breach notifications and phishing indicators. We do not read or store email body content beyond what is needed for threat analysis.
Breach scan results: Records of which breaches your email appears in, threat scores, and scan timestamps.
Session data: Connected app/session information from your Google or Microsoft account to detect unauthorized access.
Account registry: Services you've registered with (discovered via inbox scanning or manually added).
Payment information: Processed by Stripe. We never see or store your card number.
We use the following services to operate KillSesh:
We retain your data for as long as your account is active. When you delete your account:
Deletion is completed within 30 days of your request.
You can at any time:
For GDPR (EU) and CCPA (California) requests, email privacy@killsesh.com.
All data is encrypted in transit (TLS 1.3) and at rest. Database access is protected by Row-Level Security — each user can only access their own data. API endpoints require authentication. We conduct regular security reviews of our codebase.
KillSesh is not intended for use by anyone under 18. We do not knowingly collect data from minors.
We may update this policy. Material changes will be communicated via email to active subscribers. Continued use after changes constitutes acceptance.
Questions about this policy: privacy@killsesh.com