Privacy Policy
Last updated: 31 August 2026
Krit is run by Krit Ltd, a company registered in England and Wales (company number 17383666, registered office 20 Wenlock Road, London, N1 7GU). We are the data controller for the personal data described here. You can reach us at george@krit.co.uk.
This policy explains what we collect, why, who we share it with, and what you can do about it. It is written to be read, not skimmed past.
1. What we collect
Account data. Your email address and, if you sign in with Google, the name and email Google sends us. We do not receive your Google password.
Onboarding answers. Your learning stage (GCSE, A-Level, undergraduate, postgraduate, or self-directed), subject, institution if you give one, and how you currently use AI tools. We use these to tailor sessions and to understand who uses Krit.
Session content. Everything you type into a Learn, Interrogate, or Stretch session, and everything Krit says back. This includes the anchor and distil documents produced at the end of a session. This is the most personal data we hold, and it is the reason the product works, so we want to be clear about what happens to it (see section 3).
Usage data. Which modes you use, how long sessions run, how many exchanges they contain, and the compute cost of each session. We use this to manage your weekly allowance, keep the service affordable, and see which features people actually use.
Payment data. If you subscribe or buy credits, Stripe handles your card. We never see or store your full card number. We store your Stripe customer ID, your plan, and whether you have used a free trial.
Referral data. If you refer someone or are referred, we store who referred whom so we can credit both accounts.
Feedback. If you cancel a subscription and tell us why, we keep what you wrote.
Technical data. IP address, browser type, and device information, collected automatically when you use the site. We use Cloudflare Turnstile to block bots; it runs invisibly and may collect device signals for that purpose under Cloudflare's own privacy terms.
Marketing preference. Whether you ticked the box to hear from us. The box is unticked by default, and you can untick it any time.
2. Why we use it
Under UK GDPR we need a lawful basis for each use. Here they are.
Run your account and deliver sessions
Performing our contract with you
Take payment and manage your subscription
Performing our contract with you
Manage your weekly allowance and credits
Performing our contract with you
Tailor sessions to your level and subject
Performing our contract with you
Keep the service secure and block abuse
Legitimate interest
Understand how Krit is used and improve it
Legitimate interest
Send you product updates and offers
Consent (the opt-in box)
Comply with tax, accounting, and legal duties
Legal obligation
We do not sell your data. We do not show ads.
3. Who sees your session content
Your session content is sent to Anthropic, the company that makes the AI model Krit is built on, so it can generate responses. Under our commercial agreement with Anthropic, your content is not used to train their models. Anthropic may retain inputs for a limited period for safety and abuse monitoring, then deletes them.
We do not read your sessions as a matter of course. We may look at a session if you ask us to, if we are investigating a bug you have reported, or if we have reason to believe the service is being misused.
We may use anonymised, aggregated information about sessions (for example, average length, which subjects are common) to improve Krit. This does not identify you.
4. Who else we share data with
We use a small number of service providers to run Krit. Each one only receives what it needs to do its job.
•
Supabase stores your account, session data, and usage records.
•
Anthropic generates AI responses (section 3).
•
Stripe processes payments.
•
Vercel hosts the website.
•
Cloudflare provides bot protection.
•
Google handles sign-in if you choose to use it.
•
Microsoft 365 handles our email.
•
Senja collects testimonials, only if you choose to leave one.
Some of these providers process data outside the UK. Where they do, transfers are covered by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or a UK adequacy decision.
We will share data with authorities if the law requires it, and we will tell you if we are allowed to.
If Krit Ltd is ever sold or merged, your data would transfer to the new owner under the same terms, and we would tell you first.
5. Bot protection
We use Cloudflare Turnstile to protect our sign-up and login pages from automated abuse. Turnstile runs in the background when you visit these pages and does not require any interaction from you.
Turnstile collects technical signals such as your IP address, browser type, and TLS fingerprint. These signals are used solely to distinguish human visitors from bots: they are not used to identify, profile, or target you. Cloudflare processes this data on our behalf as a data processor, and also uses it to improve Turnstile's detection capabilities as a data controller.
For more information, see Cloudflare's Turnstile Privacy Addendum (https://www.cloudflare.com/turnstile-privacy-policy/) and their Privacy Policy (https://www.cloudflare.com/privacypolicy/).
6. How long we keep it
•
Account and session data: for as long as you have an account. When you delete your account, we delete it within 30 days, except where we must keep records for legal or accounting reasons.
•
Anonymous accounts: if you try Krit without signing up, your trial data is deleted after 30 days.
•
Payment records: six years, because HMRC requires it.
•
Cancellation feedback: up to two years, then deleted.
•
Marketing preference: until you withdraw it.
7. Your rights
You can ask us to:
•
Give you a copy of your data
•
Correct anything that is wrong
•
Restrict or object to how we use it
•
Send your data to you or another service in a portable format
•
Withdraw consent for marketing at any time
Email george@krit.co.uk. We will respond within one month. There is no charge unless a request is clearly excessive.
If you are not happy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you told us first so we can fix it.
8. Age
Krit is available to anyone aged 13 or over. If you are under 18, you should have a parent or guardian's permission to use Krit, and a parent or guardian must be the one to pay for any subscription. We do not knowingly collect data from anyone under 13. If you think we have, email us and we will delete it.
9. Cookies and local storage
Krit uses a small number of essential cookies and browser storage items to keep you signed in, remember your preferences, and protect against bots. These are necessary for the service to work and do not require consent under UK law. We do not use advertising or tracking cookies.
Stripe sets its own cookies during checkout for fraud prevention. Cloudflare Turnstile may set a cookie to remember that you passed its check.
10. Security
Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it and protected with two-factor authentication. Database access is controlled row by row so that users can only ever read their own data. No system is perfectly secure, and if we discover a breach that affects you, we will tell you and the ICO as the law requires.
11. Changes
If we make a meaningful change to this policy, we will email you or show a notice in the app before it takes effect. Minor wording changes will just update the date at the top.
12. Contact
Krit Ltd
20 Wenlock Road, London, N1 7GU
george@krit.co.uk
ICO registration number: ZC230498