KarttaOpen app

Privacy Policy

Effective October 5, 2026

The short version
  • Your code never reaches our servers. Kartta analyzes your project in your browser or on your own computer.
  • If you join the waitlist, we keep your email (and the optional answers you give) only to tell you about Kartta.
  • We use cookie-free, aggregated visit statistics. No ads, no trackers, and we never sell your data.

This policy explains what information Kartta (“Kartta”, “we”, “us”) collects when you use the website kartta.dev, the web app at kartta.dev/app and the command-line helper @karttadev/cli (together, the “Service”), and what we do with it. Questions: hello@kartta.dev.

1. Your code stays with you

When you open a project folder in the web app, the files are read and analyzed inside your browser. When you run npx @karttadev/cli, the analysis runs on your computer, and the map is served only to your own browser (for example on localhost). If you pair the kartta.dev page with the helper, the data goes directly between your browser and your computer, using a pairing code.

We do not receive, upload or store your source code, file contents, environment variable values or secrets. The security check shows where a secret is, never its value, and nothing from it is sent to us.

Your browser may keep small settings on your device (for example the last pairing code or the AI-context format you chose). They stay in your browser and you can clear them at any time.

2. Information we collect

WhatWhyWhere it is stored
Waitlist: your email, plus optional answers (plan you’re interested in, what you build with, team size, how you found us)To tell you when paid plans or new features are ready, and to understand who Kartta is forSupabase (database). If signup alerts are on, a notification is sent through Resend.
Emails you send to hello@kartta.devTo answer youForwarded by ImprovMX to our email inbox
Visit statistics: pages viewed, referrer, country, browser and device typeTo know which pages are usefulVercel Web Analytics — no cookies, aggregated, not used to identify you or track you across sites
Standard server logs: IP address, browser, time of requestTo run the website and keep it secureVercel (hosting), kept for a short time under Vercel’s policies

When you install the CLI with npm, npm (GitHub, Inc.) handles that download under its own privacy policy. The CLI itself does not send us telemetry.

3. How we use it

Only to run and improve the Service and to communicate with you about it: answering emails, sending waitlist updates and launch news (you can unsubscribe or ask us to remove you at any time), and protecting the Service from abuse. We do not sell or rent your personal information, we do not share it for advertising, and we do not use your code or data to train AI models.

4. Service providers

We use a few providers to run Kartta: Vercel (hosting, analytics), Supabase (waitlist database), Resend (email notifications), ImprovMX (email forwarding) and npm (CLI distribution). They process data on our behalf, only as needed to provide their service. Some of them may store data in the United States or other countries.

5. How long we keep it

Waitlist entries are kept until you ask us to delete them or until we no longer need them for the purpose above. Emails are kept as long as needed to help you. Analytics are aggregated. Server logs are kept briefly by our hosting provider.

6. Your choices and rights

You can ask us at any time to see, correct or delete the information we have about you, or to stop emailing you — just write to hello@kartta.dev from the address in question. We’ll reply within 30 days.

California residents: you have the right to know what personal information we collect, to delete it, to correct it, and not to be discriminated against for using these rights. We do not sell or “share” personal information as those terms are defined in California law.

Visitors from the EU, UK or Switzerland: we process your waitlist data based on your consent (you can withdraw it at any time) and other data based on our legitimate interest in running a secure, useful website. You may also have the right to data portability, to object to processing and to complain to your local data protection authority.

Do Not Track: we don’t track you across websites, so there’s nothing for a Do Not Track signal to switch off.

7. Security

We use reputable providers, encrypted connections (HTTPS) and database rules that let the website add waitlist entries but not read them. No system is perfectly secure, but we keep the data we hold to a minimum.

8. Children

Kartta is a tool for developers and is not directed to children under 13. We don’t knowingly collect information from children under 13; if you believe we have, contact us and we’ll delete it.

9. Changes

If we change this policy, we’ll update the date at the top. If the change is significant — for example when accounts or paid plans launch — we’ll say so on the website and, if you’re on the waitlist, by email.

10. Contact

Kartta · hello@kartta.dev