KORTEXby KAAYKO

Security, data and status

What a scan leaves behind, how long it stays, where it lives, who else touches it, what you can delete yourself, and whether the redirects are up right now. Everything on this page describes what the running system does; nothing here is a promise we cannot show.

Status

A probe fetches a sample code on kaay.link every fifteen minutes, once the way a phone does and once the way a script does, then the QR image and the API. The last result is below.

Loading the last probe

Region: Google Cloud us-central1. Hosting and the redirect function run on Firebase.

What a scan stores

KeptWhat it isFor how long
Scan recordTime, device type, operating system and browser family, country, whether it came from a QR or a tap, which destination was chosen, and a keyed hash that tells repeat visitors from new ones. Never the address, never the raw user agent, never the full referrer.30 days, deleted by a database-level expiry on every record.
Daily totalsCounts per day per code: scans, delivered, lost, QR versus tap, device and country totals. No visitor keys.The life of the link.
AnswersIf a code asks a question: the choice, the party size, the time, a hash of the client so a second answer replaces the first. No name, no address.400 days.
Access codeA salted hash. We cannot read it back or re-send it.While the workspace exists.
EmailOnly if you attach one: a salted hash plus the address, for delivery. Delivery is not switched on yet, so nothing is sent.While the workspace exists.
Audit trailWho changed a link and when: old destination, new destination, actor.While the workspace exists.

Who else processes it

ProcessorWhat forWhere
Google Cloud (Firebase)Hosting, the redirect and API functions, the database, secrets.us-central1, United States
StripeCard payments for paid plans. We never see the card number.United States and the European Union
Zoho MailOutbound email (access-code delivery, receipts), once delivery is switched on.United States and India
Google FontsThe two typefaces on these pages.Global

No advertising pixels, no third-party analytics on kaay.link or kaayko.com/kortex. We do not sell data. A data processing agreement for organisations is available on request; write to the address at the foot of this page.

What you can do yourself

How the redirect is protected

Reporting a security problem

Write to security@kaayko.com with the subject Kortex security. You will get a human reply, and we will not pursue anyone who reports in good faith and does not access other people's data. Please do not run automated scanners against live redirects; they are counted as abuse.

Accessibility

The pages are built to WCAG 2.1 AA: keyboard reachable with visible focus, form controls with labels, colour never the only signal, text that scales. Functional text on the dashboard is upright and at least 16 pixels. If something is not usable for you, tell us at the address above and we will fix it.

Cookies and local storage

No cookies. The page keeps your session token, your view preferences and an unsent draft in your browser's local storage; nothing there is read by a third party. Clearing site data signs you out on that device; your access code still opens the workspace.

Kortex is operated by Kaayko. Terms: kaayko.com/legal/kortex-terms. Support: kaayko.com/kortex/support. Contact: help@kaayko.com. Security: security@kaayko.com.