Legal
Privacy Policy
Last updated June 14, 2026
This policy explains what RenderKit collects, why, and the choices you have. It is written to be read — not to hide behind legalese. Questions: [email protected].
What we collect
Account data — when you sign in with GitHub or Google we store your email, name, avatar URL, and provider id to create your account.
Usage data — per-day, per-endpoint render counts, credit consumption, cache hits, and errors, used to power your dashboard and bill your plan.
Render inputs — the URL or HTML you submit and the parameters of each render, retained on the job record for 30 days for history and debugging.
What we do not collect
We never store your plaintext API keys — only a SHA-256 hash and a short display prefix.
We do not sell personal data, and we do not run third-party advertising trackers on the API.
Rendered artifacts
Screenshots and PDFs you generate are hosted on our CDN at content-addressed URLs and retained for 365 days. Anyone with the URL can access the artifact, so do not render private content you intend to keep secret without your own access controls.
Sub-processors
We use infrastructure providers for compute, object storage (CDN), database, and payments (Paddle, our merchant of record). Each processes data only to provide their service to us.
Your rights
You can export or delete your account data at any time from the dashboard, or by emailing [email protected]. Deleting your account purges your profile, keys, and job history.
Retention
Job records: 30 days. Rendered artifacts: 365 days. Usage aggregates: for the life of the account. Webhook delivery logs: 90 days.