Security, data and status
What a scan leaves behind, how long it stays, where it lives, who else touches it, what you can delete yourself, and whether the redirects are up right now. Everything on this page describes what the running system does; nothing here is a promise we cannot show.
Status
A probe fetches a sample code on kaay.link every fifteen minutes, once the way a phone does and once the way a script does, then the QR image and the API. The last result is below.
Region: Google Cloud us-central1. Hosting and the redirect function run on Firebase.
What a scan stores
| Kept | What it is | For how long |
|---|---|---|
| Scan record | Time, device type, operating system and browser family, country, whether it came from a QR or a tap, which destination was chosen, and a keyed hash that tells repeat visitors from new ones. Never the address, never the raw user agent, never the full referrer. | 30 days, deleted by a database-level expiry on every record. |
| Daily totals | Counts per day per code: scans, delivered, lost, QR versus tap, device and country totals. No visitor keys. | The life of the link. |
| Answers | If a code asks a question: the choice, the party size, the time, a hash of the client so a second answer replaces the first. No name, no address. | 400 days. |
| Access code | A salted hash. We cannot read it back or re-send it. | While the workspace exists. |
| Only if you attach one: a salted hash plus the address, for delivery. Delivery is not switched on yet, so nothing is sent. | While the workspace exists. | |
| Audit trail | Who changed a link and when: old destination, new destination, actor. | While the workspace exists. |
Who else processes it
| Processor | What for | Where |
|---|---|---|
| Google Cloud (Firebase) | Hosting, the redirect and API functions, the database, secrets. | us-central1, United States |
| Stripe | Card payments for paid plans. We never see the card number. | United States and the European Union |
| Zoho Mail | Outbound email (access-code delivery, receipts), once delivery is switched on. | United States and India |
| Google Fonts | The two typefaces on these pages. | Global |
No advertising pixels, no third-party analytics on kaay.link or kaayko.com/kortex. We do not sell data. A data processing agreement for organisations is available on request; write to the address at the foot of this page.
What you can do yourself
- Export a link or the whole workspace as CSV from the page.
- Delete a link, or the whole workspace with every scan and answer, from the page. Deletion is immediate and cannot be undone; printed codes stop resolving.
- Rotate the access code, or revoke a shared read-only report, at any time.
- Pause a code so scans see a paused page instead of the destination.
How the redirect is protected
- Every destination is screened on save: private and internal addresses are refused, known-bad hosts are refused, and an unknown domain on a brand-new workspace is held for a person to look at before it goes live. Screening is a check, not a guarantee.
- Anyone can report a link. A held or blocked link shows a review page with an appeal route, never the destination.
- Automated clients (uptime monitors, link checkers, privacy scanners) are sent on to the destination without being counted; headless browsers are refused.
- Access codes are checked with a fail-closed per-address limit, and every write is recorded in the audit trail.
- Paid webhooks are signed with HMAC-SHA256 so a receiver can verify the sender.
Reporting a security problem
Write to security@kaayko.com with the subject Kortex security. You will get a human reply, and we will not pursue anyone who reports in good faith and does not access other people's data. Please do not run automated scanners against live redirects; they are counted as abuse.
Accessibility
The pages are built to WCAG 2.1 AA: keyboard reachable with visible focus, form controls with labels, colour never the only signal, text that scales. Functional text on the dashboard is upright and at least 16 pixels. If something is not usable for you, tell us at the address above and we will fix it.
Cookies and local storage
No cookies. The page keeps your session token, your view preferences and an unsent draft in your browser's local storage; nothing there is read by a third party. Clearing site data signs you out on that device; your access code still opens the workspace.
Kortex is operated by Kaayko. Terms: kaayko.com/legal/kortex-terms. Support: kaayko.com/kortex/support. Contact: help@kaayko.com. Security: security@kaayko.com.