Privacy Policy
Effective 5 October 2026
The short version
- We keep the links you save and what you add to them: tags, notes, collections and your own texts. Photos and videos are never copied.
- We never ask for your password to Instagram or any other platform, and we can't see your accounts there.
- No ads, no selling of data, no visitor statistics, no cookies of our own.
- You can download everything, or delete your account and all of it, at any time in Settings.
1. Who we are
ClaspKart ("we", "us") is a web app at kerdostack.com for keeping the posts, links and texts you save in one library. It is run by an independent developer based in India. For anything about your data, write to kerdostack@gmail.com.
2. What we store
Your account. Your email address. If you sign in with Google, Google also tells us the name and picture address on your Google account; we get no access to anything else there. If you sign in with a password, it is kept by Google's sign-in service in scrambled form; we never see it.
What you save.
- The link of each post or page, as you shared it and in a cleaned-up form without tracking codes.
- What the link itself says: the platform, the kind of post and, when the link names it, the author's handle.
- For some platforms, the post's public title and author, which our helper service looks up once.
- Texts you save yourself (up to 10,000 characters each).
- What you add: tags, notes, collections, categories and favorites.
- When and how each save was made (shared, pasted, imported), and whether its preview could be shown.
Your settings, such as the theme and how previews load, and a short record of each import (its kind and how many posts it held). A file you import is read on your device; only the links in it are saved, the file itself is never uploaded.
On your device. Your browser keeps a copy of your library so that it opens without a connection, together with your sign-in, your preferences and anything still waiting to be sent. This is kept in the browser's own storage for this site. We set no cookies of our own.
Technical data. Like every website, the companies that deliver ours (section 5) see your IP address, your browser's type and the time of each request, and keep short technical logs to run the service and protect it from abuse. We build no profiles from this.
What we don't store: the photos or videos of the posts you save, your passwords or sign-ins for other platforms, your contacts, your location, or anything about what you do on other sites.
3. What we use it for
- To keep your library and show it on each device you sign in on.
- To look up a saved post's title and to open shortened links, so a save shows what it is.
- To keep the service safe and working: preventing abuse, fixing faults and keeping backups.
- To send the emails your account needs: confirming your address and resetting a password. We send no marketing emails.
We do this to provide the service you asked for when you created your account, and, for security and backups, because keeping the service safe is in everyone's interest. Where the law asks for your consent, you give it by creating your account, and you can withdraw it by deleting the account.
4. Previews come from the platforms
When your library shows a post, the post is loaded from its own platform (Instagram, TikTok, YouTube, X, Reddit, Facebook, LinkedIn, Threads, Pinterest or Bluesky) through that platform's official embed. It runs on a separate, closed-off page of ours at embed.kerdostack.com, which cannot reach your library or your sign-in.
The platform then receives what any visit to a website gives it: your IP address, your browser's details and which post is being shown. It may set its own cookies and, if you are signed in to it in the same browser, recognise you. What it does with that is covered by its own privacy policy, not this one.
You decide when this happens. In Settings, "Previews" can be set to load a post only when you tap it. In Europe that is how the app starts; elsewhere it asks you the first time.
5. Who else handles your data
We use three companies to run the service. Each handles data only to do its job for us:
- Google (Firebase): sign-in and the database that holds your library, in Google's data centres in the United States. Google also sends the account emails on our behalf.
- Cloudflare: delivers the website, and runs our small helper service. When you save a link, the helper may be given that link to look up its public title or to open a shortened link. It asks the platform from Cloudflare's network, so the platform does not see you, and it keeps nothing.
- GitHub: delivers the closed-off preview page, and stores our weekly backups. The backups are encrypted before they are stored; GitHub cannot read them.
One more case: when you save a Bluesky post, your browser asks Bluesky's public service for the account's permanent id, so the save still works if the account is renamed.
We do not sell your data, and we share it with no one else, unless a law or a court order requires us to.
6. Where it is kept
Your library is stored in the United States, and the website is delivered through networks that operate worldwide. If you live elsewhere, your data is therefore handled outside your country.
7. How long we keep it
- Your library: for as long as you keep your account.
- Saves you delete: they stay in your Trash for 30 days, where you can restore them. After that the save's contents are erased. A marker that holds only the save's id remains for up to about three months, so that your other devices learn the save is gone, and is then removed.
- Your account: "Delete account" in Settings removes your saves, collections, categories, import records, profile and sign-in straight away, and clears the copy on that device. Copies on your other devices are cleared when you sign out there.
- Backups: an encrypted backup is made every week and kept for 12 weeks, then deleted. Something you deleted can therefore remain inside encrypted backups for up to 12 weeks.
8. Your choices and rights
- See and change: everything we hold about you is what you see in your library and Settings, and you can edit it there.
- Take it with you: Settings → Export downloads your whole library as a file.
- Delete it: Settings → Delete account.
Depending on where you live, the law may give you further rights, such as asking for a copy of your data, having it corrected or erased, objecting to how it is used, or withdrawing consent. To use any of them, or to raise a complaint with us, write to kerdostack@gmail.com; we answer within 30 days. You may also complain to the data protection authority where you live.
9. Security
The site is served only over an encrypted connection. The database's rules let only your signed-in account read or change your library. The platforms' code runs on a separate address, away from your sign-in. Backups are encrypted.
As the operator we have administrative access to the database. We use it only to run the service, for example to make backups and fix faults, never to look through what people saved. No system is perfectly secure; if you think something is wrong, tell us at kerdostack@gmail.com.
10. Children
ClaspKart is for people aged 18 or over. We do not knowingly keep data about anyone younger. If you believe a younger person has made an account, write to us and we will delete it.
11. Changes to this policy
When we change this policy we change the date at the top. If a change matters to how your data is used, we will say so in the app or by email before it takes effect.
12. Contact
Questions about your data: kerdostack@gmail.com. See also our Terms of Service.