Legal / KPWorkSpace
Privacy Policy
Last updated: July 5, 2026
This Privacy Policy explains how Karel Pelcak("we", "us"), the operator of KPWorkSpace, collects, uses, and protects personal data when you use the KPWorkSpace desktop application and website. We are the data controller for the processing described here. We are committed to data minimization: the Service is designed so that most of your work never leaves your device.
1. Data we collect
Account data
When you sign in with Google, we receive and store your name, email address, profile picture, and a Google account identifier. We use this to create and manage your account and to authenticate you.
Subscription and billing data
Payments are processed by Stripe. We do not receive or store your full payment card details. We store your subscription status, plan, and billing period, and a Stripe customer identifier, so we can provide the paid Service and manage renewals.
Technical and session data
To keep you signed in and to operate and secure the Service, we process session tokens and limited technical information such as IP address and request metadata processed by our hosting provider. We use a session cookie strictly necessary for authentication.
2. Data that stays on your device
The following are stored and processed locally on your device and are not transmitted to or stored by us:
- your workspaces, settings, and application data;
- files you open, edit, or create, and terminal input and output;
- screenshots you capture, which are saved in your local app folder;
- speech-to-text audio: dictation is transcribed entirely on your device using local, open-source models — your audio is never uploaded to us or any third party.
3. How we use your data
- to provide, maintain, and improve the Service;
- to authenticate you and secure your account;
- to process subscriptions, renewals, and support requests;
- to comply with legal obligations and prevent abuse.
4. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service and process your subscription;
- Legitimate interests — to secure and improve the Service and prevent fraud, balanced against your rights;
- Legal obligation — to comply with tax, accounting, and other legal requirements;
- Consent — where we specifically ask for it; you may withdraw consent at any time.
5. Service providers and sharing
We do not sell your personal data. We share data only with providers that help us operate the Service, acting as our processors or as independent controllers:
- Google — sign-in and authentication;
- Stripe — payment processing and subscription management;
- Cloudflare — hosting of our API and database, and network security;
- GitHub — hosting and delivery of application installers.
We may also disclose data if required by law or to protect our rights, users, or the public.
6. International transfers
Some providers may process data outside your country, including outside the European Economic Area. Where they do, appropriate safeguards (such as the European Commission's Standard Contractual Clauses) are relied upon to protect your data.
7. Data retention
We keep account and subscription data for as long as your account is active and as needed to provide the Service, then for the period required to meet legal, tax, and accounting obligations. When you close your account, we delete or anonymize your personal data unless we are required to retain it.
8. Your rights
Depending on your location, you have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. To exercise these rights, contact us at gryvdycz@gmail.com. If you are in the EEA and believe we have not handled your data properly, you also have the right to lodge a complaint with your local data protection authority.
9. Cookies
Our website uses a strictly necessary session cookie to keep you signed in. We do not use advertising or third-party tracking cookies.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
11. Security
We use reasonable technical and organizational measures to protect personal data, including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
12. Changes to this Policy
We may update this Policy from time to time. We will update the "Last updated" date and, for material changes, provide additional notice where appropriate.
13. Contact
For any privacy question or request, contact Karel Pelcak at gryvdycz@gmail.com.