Privacy Policy
Effective date: 8 October 2026
Last reviewed: 2026-10-08 · Document version: 2026-10-08
Kyrelio is an interactive learning service for automation and AI systems for people aged 13 and older. This notice describes the Free Public Beta. There is no payment processing, billing or marketing messaging.
Information we store
New accounts require an email address for account administration, support, verification and recovery. Email addresses are initially unverified. When service email is enabled, we send a welcome and verification message, and password-reset links on request for verified addresses. We do not send receipt or marketing emails. Existing accounts may have no email address and require operator assistance.
- Professional Workspace: private project files, variables, simulated secret values, schedules, saved executions and logs. These are stored with your account. Never enter real secrets or personal information about other people. There is no public user-content sharing feature.
- Account information: username, email address and verification state, display name, account identifier, role, active or disabled status, creation date and most recent sign-in activity. You do not need to use your real name.
- Authentication: a salted password hash, session-token hashes, email-link token hashes and expiry times. Passwords are not stored as readable text in the account database.
- Learning: completed tasks and lessons, exercise completion, XP events, learning activity dates, lesson start/completion dates and your last visited task.
- Labs: saved workflow configurations, draft revisions, attempt dates, outcomes and validation summaries. Text you enter into a saved lab may be included. Use fictional examples; do not enter passwords, API keys or other people’s private information.
- Access: Free/Pro access status, how access was granted and related dates. These are internal access records; the service does not collect card or payment details.
- Operations: admin action records, request identifiers and saved results used to avoid duplicate updates, and generic error codes with timestamps. Sign-in protection uses hashed identifiers derived from usernames and, when hosting is configured, client IP addresses. These hashes are security data, not a claim of anonymity.
Why we use it
We use this information to authenticate accounts, restore saved work, calculate progress, control lesson access, troubleshoot problems and protect the service. Administrators may review account and learning information needed to operate and support the test, manage access and investigate abuse.
Storage and service providers
Confirmed account and learning records are stored in the service’s server database. Your browser also stores a session cookie, preferences and pending changes awaiting a successful save. See the Cookie & Storage Policy.
Authorized operators can access the database for maintenance. The normal admin interface does not display passwords, password hashes or session tokens. Hosting or infrastructure providers may process data to operate the service. Railway hosts the current deployment and processes application data and network requests, which can include IP addresses and technical request information. The operator still needs to confirm the hosting region, provider retention and applicable international-transfer arrangements before Public Beta. The current labs simulate external tools; they do not send your workflow content to live AI, CRM or messaging providers. Current exercise checks are programmed rules, not live AI grading. When service email is enabled, Resend processes recipient addresses, message contents (including time-limited account links) and delivery information to send verification and recovery emails. The configured sending region is Ireland. Resend states that customer data is stored in the United States and email content and delivery logs are retained for 30 days on its Free, Pro and Scale plans. See Resend’s data-processing and retention information. Deleting an account here does not immediately delete provider records; the operator reviews provider-held information when handling privacy requests. Verification links expire after 24 hours and reset links after 30 minutes. Used links are removed; expired link records are removed by maintenance or the next link issuance. If you email the contact address, your message is processed by the mailbox provider (currently Google/Gmail) and reviewed manually by the operator. Do not include passwords or real credentials.
No advertising pixels or third-party tracking integrations are currently enabled. We do not sell account or learning information.
Account-email safety
Welcome and verification messages and requested reset links support your account; they do not subscribe you to marketing. Email verification confirms control of a mailbox, not a person’s legal identity or age. Recovery requires an active account with a verified address. Reset links are single-use, and successful resets revoke existing sessions. Do not forward these links or include them in support messages. Our support contact does not need your password.
Our account-email templates contain no tracking pixels. Provider open and click tracking must remain disabled for these messages. Service email operates separately from your optional product-analytics choice. If you receive an unexpected account email, ignore its link and report concerns through Contact.
Learning improvement measurements
Optional first-party product analytics helps us understand lesson and course use, hint use, practice attempts, funnel steps such as signup and completion, and Pro-preview interactions. It is off until you choose Allow product analytics. When allowed, random visitor/session cookies connect visits in this browser, and signed-in events can be linked to your account. These records are pseudonymous, not anonymous. We do not fingerprint devices, track you across sites or use behavioral advertising. Events do not include form text, Workspace content, passwords or raw IP addresses. Change your choice on the Cookies page; declining stops new optional events and removes visitor cookies. It does not erase past records. Required sign-in, saved progress, learning results, access control and security records continue so the service works. Administrators may summarize these necessary records to operate the service; declining analytics does not remove your learning history.
How long information stays
We keep active account and learning data while needed to provide the service. You can request deletion by email. Sessions expire after seven days; expired server session records are targeted for cleanup 30 days after expiry. Product and lesson-interaction events are kept for about 90 days; inactive visitor/session identifiers use the same period. Event collection performs cleanup, and the operator maintenance process covers periods without new events.
Workspace execution/log history has a target of 90 days unless needed for active lessons, projects or learning records. Some histories already have shorter count limits. Workspace cleanup is reviewed manually to avoid losing active work. Security/admin audit records have a target of about 12 months. Generic runtime diagnostics have a 30-day target; expired rate-limit entries have a 1-day grace period. Routine maintenance requires the operator to run the cleanup procedure; these targets are not a promise that every record expires automatically.
Records that prevent duplicate saves, runs or milestone awards remain while replaying an old request could repeat work. There is no safe automatic time limit for these yet. They are reviewed with account deletion. Pending browser changes disappear after saving or discard; preferences remain until changed or cleared.
Our beta backup policy is a daily validated backup and the last 7 successful daily backups, with private off-volume copies when configured. Rotation is an operator task. Deleted account data may remain in backups until normal rotation expires those copies; failed or missed backups can delay that expiry. We do not promise that every copy disappears instantly. Deletion records are reapplied before a restored backup returns to service. Limited security records may remain where justified, with their reason and review date recorded.
Your information and requests
You can edit your display name and view learning information in your profile. For access to your information, corrections, account deletion or privacy questions, see Contact for the configured contact method and request details. The operator may need to verify that a request belongs to your account. Do not send your password.
There is no self-service account deletion or complete data export yet. An admin progress reset does not delete your account or all associated records. Requests are handled manually by email and require identity verification and operator review, including any records that must be retained under applicable requirements.
Depending on applicable law, you may have rights to access, correct, erase, restrict or object to processing, receive portable information, withdraw consent, or complain to the relevant privacy authority. Eligibility and exceptions vary. Disabling an account prevents access; it does not erase its records. A verified request needs a reviewed operator process that also addresses analytics and backup copies.
Eligibility and changes
Kyrelio is intended for users aged 13 and older and is not intended for children under 13. We do not ask for a date of birth. If we learn that an account belongs to a child under 13, the operator stops unnecessary processing, disables access and revokes sessions, then reviews deletion and any required parental or legal steps. Report an under-13 account through Contact. We do not offer a parental-consent system. This age floor does not establish that every teenager can consent independently to every kind of processing in every country.
This notice may change as the product and its providers develop. The effective date above identifies the published version once configured. Questions about changes can be sent through Contact.