Privacy
What Kagoj does with your data.
Last updated 24 July 2026
Kagoj (kagoj.app) turns pasted or uploaded content into a page on a short link. This policy explains what it collects, why, and the controls you have. It is written to be read, not to hide behind length.
What we collect
- Your account. When you sign in with Google — the only sign-in method — we receive your name, email address, Google account identifier and profile picture.
- Content you create. The documents you paste or upload. Text (Markdown, rich text, HTML, code, plain text) is stored in our database; files (PDFs, images, video) are stored on Cloudflare R2. We also keep the title and the rendered version.
- Activity. How many times a document has been opened, a log of actions taken by any AI agent keys you issue (what they did and when), the IP address of those requests for that audit trail, and timestamps.
- Keys. Agent and extension API keys are stored only as a hash. The plaintext is shown once, at creation, and never stored.
- Anonymous use. You can use Kagoj without an account. Anonymous content has no owner and is deleted automatically after 24 hours.
The browser extension
The Kagoj browser extension places a floating launcher on the pages you visit, and acts only when you ask it to— when you click a tool in it, click the toolbar icon, or use its right-click menu. It can then record your screen, capture a screenshot or a selected area of the current tab, or take the current page’s title, URL and any text you have selected, and send that to your Kagoj account. To do this it needs access to the current tab, which is why it requests broad site access.
It does not track your browsing, run in the background, or read pages you have not explicitly chosen to share. Signing in stores a scoped access token in your browser (via chrome.storage). That token can create and read your documents; it can never change who they are shared with, or delete them. Remove it with “Sign out” in the extension, or revoke it from Agent keys in Kagoj.
How we use it
To provide the service: store and render your documents, enforce who can see them, show you your shelf, and let AI agents you authorise act on your behalf. We do not sell your data, and we do not use it for advertising or cross-site tracking.
Who it's shared with
We rely on a small number of processors to run the service:
- Google. Sign-in.
- Cloudflare R2. Storage for uploaded PDFs, images and video.
- Hetzner. Server and database hosting, in the EU.
Beyond these, your content is shared with other people only as you direct, through the visibility and access settings on each document (public, unlisted, your team, or specific people).
Where it's kept, and for how long
- Anonymous content. 24 hours, then deleted from the database and file storage.
- Trashed content. Kept 30 days, then permanently purged.
- Signed-in content. Kept until you delete it, or delete your account.
Our database and servers are hosted in the EU (Hetzner). Files are stored on Cloudflare R2.
Your controls
- Export. Download your account and every document you own as one JSON file, from Account settings.
- Delete. Delete your account, which permanently removes every document you own, including files.
- Per link. Set each link’s visibility, add a passphrase, an expiry, or make it one-time.
- Revoke. Revoke any agent or extension key at any time.
Security
User-submitted HTML is sanitised before it is stored and served from an isolated origin, so it cannot reach your session. Private files are served only through short-lived signed links, after an access check. Keys are hashed, and the session cookie is host-only.
Cookies
A single cookie keeps you signed in; your light/dark preference is stored locally in your browser. There are no advertising or cross-site tracking cookies.
Children
Kagoj is not directed at children under 13, and we do not knowingly collect their data.
Changes
We may update this policy. The date at the top reflects the current version; material changes will be noted there.
Contact
Questions about this policy or your data? Email [email protected], or reach Shadman Taqi.