DRKNYT - Policies
Privacy Policy
How we handle data across drknyt.com, studio engagements, the Lab, and related product surfaces.
Scope
This policy covers drknyt.com, DRKNYT studio intake, Lab properties, accounts, and related product surfaces, including experiments and private betas. Product-specific notices may add detail for a particular surface.
Updated: 2026-09-10
Data we collect
- Contact details you provide (name/handle, email, company) when you submit a signal, request access, or buy something.
- Content you share with us: messages, briefs, attachments, and any other context you send to the Lab.
- Operational telemetry: device/browser basics, timestamps, IP-derived region, and event logs used for abuse prevention and debugging.
- Payments flow through Stripe. We see receipts and the last 4/card brand; Stripe processes the sensitive card data.
How we use that data
- To run drknyt.com and .world products, ship updates, and respond to signals you send.
- To prevent fraud or abuse, keep uptime steady, and investigate bugs across the Lab stack.
- To improve the experience: measuring anonymized usage patterns to decide what to build next.
- To satisfy legal, tax, and accounting obligations when we charge for work or products.
Third parties & infrastructure
- Hosting and deployment: Vercel (and its CDNs) may log requests for reliability and security.
- Payments: Stripe processes the payment credentials and payment methods presented during checkout. Do not send raw card or bank details through a DRKNYT form or email.
- Accounts and data: Supabase may provide authentication and data infrastructure for account and product features.
- Communications: Mailgun or another disclosed email provider may deliver account, purchase, and support messages; files you send may be stored in managed cloud storage.
- We do not sell personal data. We share it with service providers only as needed to operate, secure, support, or comply with legal obligations.
Storage, retention, deletion
- We keep account and billing records while you have an active relationship with us and as required by law.
- Operational logs are retained for a limited window for security, then rotated or anonymized.
- You can ask us to delete or update your data. Some records (like invoices) must stay for compliance.
- Backups exist for disaster recovery; removal requests propagate to backups on their normal rotation.
Security & confidentiality
- DRKNYT uses access controls intended to limit production access to authorized operational and support needs.
- Data in transit uses HTTPS. Sensitive credentials are intended to remain in protected server-side configuration, not public browser bundles.
- Each service provider's own privacy and security terms also apply to the data it processes.
- Incidents are investigated promptly; if your data is involved, we will notify you when required.
Your choices
- Request access, correction, or deletion by emailing lab@drknyt.com. We respond as quickly as possible.
- Opt out of non-essential comms; we already avoid spam and only send operational or high-signal updates.
- Disable cookies in your browser if you prefer; certain features may degrade or stop working.
- If you represent someone else's data, ensure you have the right to share it before sending it to us.
Children & sensitive data
- Studio engagement and billing accounts are intended for adults and authorized organizational representatives.
- A product intended for families, schools, or children must provide its own age-appropriate notice and consent controls where required.
- Do not submit children's personal information, health information, financial account numbers, or other regulated sensitive data through the general project brief unless DRKNYT explicitly requests it through an approved project process.
Questions or data requests
If you want to access, correct, or delete your data - or you have concerns about how we handle privacy - reach out. The same applies if you think someone sent us data they shouldn't have.