Skip to content

Privacy

Privacy policy.

This policy covers the kanjin.io website, the Kanjin web workspace, the Kanjin Mac application and the Kanjin server behind them. It says what Kanjin collects, why, who else receives it, how long Kanjin keeps it, and what you can do about it.

Last updated: 10 October 2026. Questions: vladimir@kanjin.io.

In short

  • Kanjin keeps your account, your workspaces and the results of its analyses. It keeps no source code after an analysis, with one exception that is stated below.
  • To classify code, Kanjin sends source to an external service, the classifier. You accept this when you create an account.
  • Kanjin reads repositories, tickets and pages with your own provider account, and stores none of their content.
  • The Kanjin server keeps no personal data of an Atlassian account for more than 24 hours.
  • Kanjin does not sell personal data, and does not use it for advertising.
  • Everything Kanjin keeps about an analysis is deleted after one year. You can delete your account at any time.

Your account

When you create an account, Kanjin stores:

  • Your name and email address.
  • Your password, if you choose email sign-in. Kanjin stores only a hash of it, never the password itself.
  • The sign-in methods you link: Google, Apple or GitHub. Kanjin receives your profile and your email address from that provider, and nothing else. Signing in never gives Kanjin access to a repository.
  • The time you accepted the analysis consent.
  • Your workspaces, your role in each, and the invitations you send or receive. An invitation holds the email address it was sent to.
  • Your personal settings, the repositories you track and your reading progress.

For each signed-in session, Kanjin stores the IP address, the browser or device it came from, and the approximate city and country of the connection. You see these sessions in your settings, and you can end them there. A session ends 30 days after its last use.

Kanjin sends you the email that an account needs: an address check, a password reset and workspace invitations. It sends no marketing email.

Provider connections

An administrator connects GitHub, GitLab, Bitbucket, Jira, Linear, Confluence or Notion to a workspace. Each member then links their own account at that provider, through the provider's own authorization page. For each link, Kanjin stores:

  • The access token and the refresh token that the provider gives, encrypted with AES-256-GCM. They never leave the Kanjin server.
  • The account name at the provider, so that you and your administrators see which account is linked. Jira is the exception: see "Atlassian data" below.
  • For GitHub, GitLab and Bitbucket: the names of the repositories that each member's account can read, checked every 30 minutes. Kanjin uses this to show each member only what their own account can read at the provider.

Kanjin reads repositories, pull requests, tickets, comments and pages with the member's own token, when the member asks for them and for the access check. It stores none of that content. The only writes Kanjin makes are the ones a member asks for: a ticket status change in Jira or Linear, and a comment on a Jira ticket.

When you unlink an account, Kanjin deletes its tokens. You can also withdraw Kanjin's access in the provider's own settings at any time.

Atlassian data

For a Jira link, the Kanjin database keeps only the encrypted tokens, the Jira site and the state of the link. It does not keep the Atlassian account ID, the email address or the display name. To show "Your account", the Kanjin server reads your email address or name from Atlassian with your token, and keeps it in memory for one hour at most. While you connect a site, the server holds the account ID for ten minutes at most, to finish the authorization. Tickets, comments, boards and people are read from Jira for each request and are not stored.

Code and analysis

To classify a changed block, Kanjin sends the enclosing function in its old and its new version, the imports it uses, and the type and constant declarations it references. That is wider than the changed lines. For a ticket, Kanjin can also send the ticket text, file paths, commands and the messages of a coding agent, when a feature needs a classification. All of this goes to the Kanjin server and to an external service, the classifier. You accept this when you create your account.

  • While an analysis runs, the Kanjin server holds its input, so the job survives a restart. It deletes the input when the analysis completes or is canceled, and one hour after an analysis fails or ends partial.
  • After that, Kanjin keeps the results: block ranges, categories, probabilities and the versions that produced them. It keeps no source code, except the source of a block whose classification a reviewer corrects, because a second request must quote it.
  • Kanjin deletes the results and the corrected source one year after it stores them.
  • A request about a ticket is not stored by Kanjin.

The results belong to the workspace, and its members can see its reviews.

The Mac application

The Mac application keeps its settings, your pinned tickets and the state of your agent sessions on your Mac. A pinned ticket keeps its key, its title, its status and the name of its assignee, so the sidebar can show it. These stay on your Mac.

A ticket session runs your own coding agent, such as Codex or Claude Code, with your own account at that agent's provider. The brief that starts the session, and the pages the agent reads, go to that provider under your own agreement with it. Kanjin does not store that conversation. When a feature needs a classification, Kanjin sends parts of it to the classifier, as "Code and analysis" describes.

This website

kanjin.io is a static website. It sets no cookies and runs no analytics. Cloudflare serves it, and receives the request data of each visit, such as your IP address, to deliver and protect the site. The pages load their fonts from Google Fonts, so your browser also sends a request to Google.

Who else receives data

  • The classifier, an external service, receives the source and the ticket context described above, to classify it.
  • Hosting providers run the Kanjin server and its database, and Cloudflare sits in front of them. The location of the production server is to be confirmed.
  • The sign-in provider you choose (Google, Apple or GitHub) confirms who you are.
  • The providers you connect (GitHub, GitLab, Bitbucket, Atlassian, Linear, Notion) receive the requests that Kanjin makes with your token.
  • Google Workspace carries the email you send to a kanjin.io address.

Kanjin does not sell personal data, and does not share it for advertising.

How long Kanjin keeps it

DataKept
Your account, workspaces and settingsUntil you delete them
A signed-in session30 days after its last use
An address check link24 hours
A password reset link1 hour
A workspace invitation7 days
Provider tokensUntil you unlink the account or delete your account
Atlassian account ID, email and name1 hour at most, in memory only
The input of an analysisUntil it ends, or 1 hour after a failure
Analysis results and corrected source1 year

Your choices

  • Delete your account in Settings, Account. Kanjin removes your sign-in methods, every session, your linked provider accounts and their tokens, your tracked repositories and your reading progress. Workspace data stays with the workspace: its reviews, its stored analyses, and the corrections you made in it.
  • Unlink a provider account in Connections. An administrator can disconnect a provider from the workspace.
  • Withdraw access at the provider. GitHub, GitLab, Bitbucket, Atlassian, Linear and Notion each let you remove an authorized app.
  • Ask us for a copy of your personal data, for a correction, or for its deletion, at vladimir@kanjin.io.

Security

Kanjin encrypts provider tokens with AES-256-GCM, stores passwords only as hashes, and uses HTTPS between your browser or Mac and the Kanjin server. A provider decides what each member can read; Kanjin mirrors that and never grants access to a repository.

Changes to this policy

When Kanjin changes what it collects or how it uses it, this page changes first, with a new date at the top.

Contact

Write to vladimir@kanjin.io with any question about this policy or your data.

Back to the homepage