Hosted Kiln privacy
This notice covers the Kiln hosted service operated by Instrukt Labs. It does not cover your local Kiln workspace or the assistant you connect. Contact support@instruktlabs.com about privacy or access to your data.
Sign-in and account data
Introductory access requires a single-use invitation. Kiln stores a hash of each code, its expiration, revocation and redemption state, and its account association until account deletion. It does not store the original code. After sign-in, an encrypted, browser-bound enrollment continuation may temporarily retain your verified identity and any email you explicitly consented to share with a client. It expires after ten minutes and is removed by background cleanup or successful enrollment. Kiln does not collect a separate contact email for invitations; access requests use Discord or support.
Google or GitHub confirms your identity. Kiln receives provider identity and profile information during sign-in, and keeps the provider name and stable account identifier to associate you with a Kiln account. It does not retain your provider profile name or photo. Provider access and ID tokens are discarded after verification.
Ordinary Google sign-in requests basic identity and profile access; ordinary GitHub sign-in uses your public identity. When a connected client requests email access, Kiln first asks you to consent to sharing your verified email address with that client for account identification and workspace restrictions. Only then does Kiln request Google's email permission or GitHub's private-email permission. Kiln does not request Google Drive, Gmail or GitHub repository access.
The consented email is verified by your sign-in provider when you connect and stored encrypted with that connection's authorization records for up to 30 days. The client can retrieve it only using that connection's valid credentials and email scope. It is not stored as your Kiln account identity or in operational logs. Disconnecting the client stops further access; copies already shared are subject to the client's own policies. Reconnect to share a changed address. This does not enable email sign-in, marketing or security emails.
Kiln stores its own account, session, connected-app, usage and security-activity records. Essential cookies keep sign-in, account confirmations and your browser session bound to you. Browser sessions expire after 30 minutes without activity or 24 hours in total; connected apps can stay authorized for up to 30 days.
Adding another sign-in method requires confirmation of both identities. Accounts are never automatically joined by matching email addresses. Security notices are in-app only: Kiln does not collect a separate security contact email or send alerts about sign-in method changes or deletion.
Your source and assets
Kiln processes the source, geometry, material files, previews, names and metadata you or your connected app send. It stores these privately for your account and returns requested results to the apps you authorize. The hosted service does not call a model provider. Your assistant handles its own conversations and copies under its provider's policies.
Unsaved work expires seven days after upload; background cleanup removes expired files. Saved source, assets and material dependencies remain until deleted, within your storage quota. Removing a saved revision removes that entry; files shared with another revision can remain, and unsaved copies follow the seven-day policy. Download links require your signed-in account and expire after ten minutes.
Kiln does not keep automatic backups of source files or GLBs. Once those files are deleted, they cannot be recovered. Download your work if you need a separate copy.
Service providers and operations
Cloudflare processes network requests, runs Kiln and stores hosted data. Google and GitHub process the sign-in you choose. Kiln's operational metrics record request categories, status codes, timing and aggregate service health, without source, file contents, account identifiers, IP addresses or credentials. These metrics are retained for three months. Cloudflare also processes its own infrastructure and security data under its policies.
Kiln pages do not load advertising or tracking scripts. If you contact support, your email and the details you choose to send are processed in the support inbox to handle your request. Do not include passwords, tokens or recovery codes.
Your controls and deletion
Use Your account to review sign-in methods, security activity and connected apps. Browser sign-out leaves app connections working. Disconnecting an app blocks its new requests but does not erase copies already returned to it or cancel work already admitted.
You can download your work and request account deletion after confirming a linked sign-in method. Access is revoked while cleanup stops outstanding work and removes active files and identity records. If cleanup is interrupted, the request stays pending while it retries. The private deletion receipt is available for seven days after completion.
Minimal pseudonymous retirement records remain to prevent old credentials or delayed jobs from restoring deleted data. Expiring authorization records and provider backups are separate from active-service deletion: Cloudflare's database recovery history can retain prior account data for up to 30 days. Deletion does not remove copies you downloaded or sent to another app.
For access, correction or deletion questions, contact support@instruktlabs.com. Use the identity provider's own account controls for your Google or GitHub data.