Privacy Policy

Last updated: August 6, 2026

What Kindling Is

Kindling (kindlingmagic.com) is an AI marketing tool that helps startup teams run their marketing: it audits where your marketing stands, builds a strategy and 90-day plan, sends a weekly briefing, and creates campaign and founder content using AI. Kindling is operated by Kindling LLC, a Georgia (United States) limited liability company ("we," "us").

This policy explains what data we collect, what we don't, and how we handle what passes through our system.

What We Collect

Account information (stored on our servers):

  • Email address
  • Hashed password (if you sign up with email)
  • Subscription status (free or Pro)
  • Aggregate usage metrics -- campaign count, feature usage counts
  • Campaigns you save to your account, including the brief, brand context, and generated content. These are stored in Firestore, encrypted at rest, scoped to your user account by database security rules, and deletable by you at any time.
  • Your marketing profile (sometimes called your "company brain" in the product): the answers you give during the marketing audit (company stage, sales motion, revenue range, deal size, budget, and hours available), your audit results, your strategy and 90-day plan, your Monday briefings, the plays you run, the decisions and calls recorded in your decision log, and the pipeline numbers you report in check-ins. Stored in Firestore under the same encryption and user-scoping as campaigns, and deletable by you at any time.

Your saved campaigns are visible only to you. Firestore security rules enforce user-level isolation at the database layer -- no other user can read or list your campaigns, and staff access is limited to the few people who operate Kindling, under confidentiality obligations.

If you don't want a campaign saved to your account, just don't hit Save. Campaigns you don't save are never persisted server-side.

What We Store Locally

Campaign history, brand profiles, and user preferences are stored in your browser's local storage (IndexedDB). This data lives on your device, not our servers. You can clear it anytime from your Account page.

What We Share with Third Parties

We share limited data with three services to make Kindling work:

  • Anthropic (Claude API) -- When you run an audit, build a plan, receive a briefing, or generate content, the relevant inputs (your answers, brand context, briefs, pipeline check-ins, and snapshots of the public web pages being analyzed) are sent to Anthropic's API for processing. Anthropic processes this data under their API terms and does not use it to train models.
  • Google Cloud (Firebase / Firestore) -- Hosts our user accounts and any campaigns you choose to save. Data is encrypted at rest (AES-256) and in transit, and access is enforced at the database layer by per-user security rules.
  • Loops -- Your email address is shared with Loops for transactional emails (account notifications, schedule reminders, and your Monday briefing, which includes its content). Nothing else.
  • Vercel -- Kindling is hosted on Vercel. Standard server logs (IP addresses, request metadata) are processed by Vercel's infrastructure.

No analytics platforms receive your campaign content. We don't sell or share your data with advertisers.

The Marketing Audit, Plan & Monday Briefing

Kindling's core loop — the audit, the strategy and 90-day plan, and the Monday briefing — works by reading public web pages and the answers you provide, then storing the results to your account so the loop can build on them week over week. Specifically:

  • Reading your site and your competitors' sites. When you run the audit (and when the briefing checks what moved in your market), our servers fetch publicly available pages from the website you provide and from competitor websites, and may run web searches to find them. Snapshots and summaries of those public pages are processed through Anthropic's API and the relevant findings are saved with your audit and briefings. We only read pages any visitor could see — we never log into anything on your behalf.
  • Your answers and your numbers. The audit interview asks about your company's stage, sales motion, revenue range, deal size, marketing budget, and available hours. Pipeline check-ins ask what conversations, deals, and revenue moved. These answers are business information about your company; they are stored to your account to keep the plan's math honest, and are visible only to your team.
  • Plans, briefings, and decisions. Your strategy, 90-day plan, plays, Monday briefings, and the calls recorded in your decision log are stored to your account so you can see why a decision was made and what happened after.
  • Briefing emails. If Monday briefings are delivered by email, the briefing content is sent through Loops, our email provider, to your address.

All of this is generated with AI and provided as recommendations, not guarantees. You can delete your audits, plans, briefings, check-ins, and decision log at any time by deleting the brand they belong to or your account.

Unsaved Generations

When you generate a campaign and choose not to save it, the brief is sent to our API, forwarded to Anthropic for generation, and the result is returned to your browser. Unsaved generations are not persisted on our servers. The brief goes in, content comes out, and the server forgets.

Cookies

We use essential cookies for authentication and session management. If we add analytics in the future, we'll implement a cookie consent banner and update this policy.

Cross-Border Data

Kindling is operated by Kindling LLC, based in the United States. Your data is processed in the United States by the services listed above (Anthropic, Google Cloud, Vercel, Loops). If you use Kindling from outside the United States, you acknowledge that your data may be transferred to and processed in the United States.

Your Rights

You can:

  • Delete your account -- From the Account page or by emailing us. This removes all server-side data permanently.
  • Clear local data -- Use the "Clear all data" button on the Account page to wipe campaign history and brand context from your browser.
  • Request your data -- Email us and we'll provide everything we have (which is just your account info and usage counts).
  • Withdraw consent -- Stop using the service anytime. Delete your account to remove your data.

GDPR (EU/UK Users)

If you're in the EU or UK, you have additional rights under GDPR including the right to access, rectification, erasure, data portability, and the right to object to processing. Our legal basis for processing is contract performance (providing the service you signed up for) and legitimate interest (improving the product).

We maintain Data Processing Agreements with Anthropic, Vercel, and Loops.

Data Retention

Account data is retained while your account is active. When you delete your account, all server-side data is permanently removed. Browser-stored data persists until you clear it or clear your browser data.

Security

Passwords are hashed. API keys are stored as environment variables, never in source code. All traffic is encrypted via TLS. API routes run in isolated serverless functions with rate limiting and input validation.

Children

Kindling is not intended for anyone under 18. We don't knowingly collect data from minors.

Founder Voice & Speech

Founder voice capture happens in your browser. When you use “Start talking,” speech is transcribed by your browser’s built-in speech service — Kindling never receives, records, or stores audio. The transcript appears on your screen for you to review and edit before anything is submitted.

When you submit a transcript, we process it — together with any voice samples and brand context you provide — through Anthropic’s API to create your drafts. Anthropic does not use this data to train models. Transcripts are processed, never stored on our servers. The finished drafts and their check results are saved to your account’s story bank so your past content is available on any device, and your founder-voice setup (voice samples, brand context, industry) is saved to your account for the same reason. A copy of your setup is also kept in your browser’s local storage. You can edit or clear your setup at any time, and you can ask us to delete your story bank and account data entirely.

Connected Publishing Accounts

If you connect a LinkedIn or X account, we store the access tokens those platforms issue so we can publish the specific drafts you approve — and only on your instruction. Kindling never posts without your action. You can disconnect an account at any time, which removes our access.

Changes to This Policy

We'll update this page if anything changes. If it's significant, we'll email you.

Contact

Questions about your data? Email hello@kindlingmagic.com