Privacy Policy
Last updated 10 August 2026
Kaidoro is built and run by one person, as a personal project. This page is written in plain English on purpose — there's no legal team behind it, and that's better handled by explaining honestly what happens to your data than by hiding behind boilerplate neither of us would read. It isn't a substitute for legal advice.
What Kaidoro does
Kaidoro turns a goal you type in into an AI-generated roadmap you can track. This page explains what that involves, data-wise.
Account and sign-in
Kaidoro never sees your password. Sign-in runs through Supabase Auth, either by email and password or by "Continue with Google". Choosing Google shares your email, name and avatar from the account you pick on Google's own screen — nothing else, and nothing beyond what that screen already shows you.
Kaidoro stores your email address, display name and avatar (if set), and the account details needed to run the product: your subscription tier and Stripe identifiers (see Payment, below), usage counters, and a referral code. If you fill in a learner profile — optional, from Settings — that's stored too; see "What gets sent to the AI" below for what it contains and why.
What you create
Every goal you type in, every roadmap generated from it, and every task you complete is stored against your account so it can be shown back to you — and, only if you choose to make a roadmap public, shared at the link you get for doing that. A public profile (Settings → make my profile public, off by default) is separate and works the same way: turning it on publishes your display name, when you joined, your streak and an overview of your progress at a link others can see.
What gets sent to the AI
Generating, refining or expanding a roadmap — and the study guide, resource suggestion and "opportunities" features — all send text to whichever AI provider is configured, currently Google's Gemini or Anthropic's Claude. What's included depends on the feature: your goal, the roadmap's current content, your clarifying answers, and, if you've filled in your learner profile, what it says — your education level, institution, course, what you've already studied and what you're finding hard — so the roadmap can be tailored to you instead of generic. The "opportunities" feature additionally runs a live Google Search on your behalf to find real opportunities, so your goal and background reach Google Search for that one feature specifically. A study guide that includes a figure sends a short search query to Wikimedia Commons to find a suitable image.
That data reaches those providers under their own API terms, not Kaidoro's — Kaidoro doesn't control how they handle it once they receive it, only what it sends and why.
Documents you add
Uploading a CV stores the file so you can view it and replace it later. Kaidoro does not read what is inside it — the file is kept as you sent it, shown back to you unchanged, and deleted along with your account.
Payment
Subscribing to Kaidoro Pro is handled entirely by Stripe. Kaidoro never sees or stores your card number. What Kaidoro keeps is a Stripe customer id and subscription id, so it knows your account is paid and can manage renewals and cancellations.
Confirmation and sign-in emails are sent by Supabase, as part of its own authentication service — Kaidoro's own code never touches them. Kaidoro sends exactly one kind of email itself: a weekly progress digest, on by default, which you can turn off any time in Settings. When you get one, it's sent through Resend.
Optional connections
Connecting GitHub stores an access token for that connection, encrypted, so Kaidoro can suggest tasks as done for you to confirm. Kaidoro never marks a task complete on your behalf without you confirming it. Disconnecting removes the stored token.
Device sessions
Kaidoro limits how many devices can be signed into your account at once, to stop a single login being shared indefinitely. This is keyed to Supabase's own session id, not your IP address or a device fingerprint.
Browser storage
Kaidoro doesn't use cookies, and runs no advertising trackers. It does count visits — see "Measuring visits", below. What it keeps in your browser:
- Your sign-in token, so you stay signed in between visits. This is sent with every request you make to Kaidoro, because that's what proves who you are — that's Supabase's own session handling, not tracking.
- Your theme preference (light, dark, or matching your system) — stays on your device.
- An invite code, if you've entered one, sent with your requests until your account no longer needs one. If you start typing a goal before signing in, that text is held briefly too, so it survives the trip through sign-up.
None of this is shared with anyone Kaidoro doesn't already name in "Who else touches your data", below.
Measuring visits
Kaidoro counts page views and visitors, using Vercel Web Analytics. It's the only way to know whether anyone is finding the site, and it's the least invasive option that answers that question. What it does and doesn't do is worth being precise about:
- No cookies, and nothing stored on your device. Visitors are counted using a value derived from the request itself, which is discarded after 24 hours. Nothing follows you between visits, and nothing identifies you across other websites.
- Recorded per view: which page, where you arrived from, your country and region, and your browser and device type. Not your IP address, not your name, and not your account.
- Private addresses are removed before they're sent. A share link's slug and a roadmap's id are stripped out and replaced with a placeholder, so the count records that a roadmap page was opened without recording which one. Sign-in tokens are never included.
Who else touches your data
Kaidoro is a small project and doesn't sell data or share it for advertising. Data passes through the services that make the app work, each for its own purpose only:
- Supabase — authentication and the application database
- Stripe — payment processing, if you subscribe
- Google (Gemini) and/or Anthropic (Claude) — generating and refining your roadmap, and, for the "opportunities" feature specifically, a live Google Search
- Wikimedia Commons — finding a suitable image for a study guide, when one includes a figure
- Resend — sending the weekly digest email, if you keep it on
- GitHub — only if you choose to connect it
- Vercel / Render — hosting the app itself, and, at Vercel, the anonymous visit counts described in "Measuring visits" above
Deleting your account
Deleting your account, from Settings, removes everything tied to it — roadmaps, tasks, uploaded documents, your learner profile, integrations, referral and cohort data — and cancels any active subscription, genuinely, not just hidden from view. Two things it can't reach: a one-time lifetime purchase isn't refunded by deleting the account, and anything already sent to Stripe, Resend, or an AI provider before deletion lives in those systems' own records, not Kaidoro's. Kaidoro itself keeps one small trace afterward — an id, not your name or email — for up to 24 hours, only so a sign-in already underway at the moment you delete can't recreate the account by accident.
The terms that govern your use of Kaidoro — including what happens to your account and content — are in the Terms of Service.
Children
Kaidoro isn't directed at children under 13, and data isn't knowingly collected from anyone that age.
Changes to this policy
If anything material changes, this page changes with it, and the date at the top will move.
Contact
Questions about this policy or your data: d.j.chigbu@gmail.com