Privacy policy
What the Krodium browser, krodium.com and the Krodium developer platform collect, why, and the rights you have. The short version: the browser sends us nothing about you.
Last updated 8 October 2026This document is under legal review.
Who we are
This policy explains how Svayam Incarnation Limited, a company registered in England and Wales ("we", "us"), handles personal data in connection with the Krodium browser, the krodium.com website, the Krodium Store and the Krodium developer platform. We are the controller of the personal data described here, for the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where it applies to you, the EU General Data Protection Regulation (EU GDPR).
Questions about this policy or your personal data: [email protected]. Everything else: [email protected].
The short version
- The Krodium browser sends no telemetry, usage data or crash reports, to us or to anyone else.
- Your history, bookmarks, passwords, settings and downloads stay on your device. We cannot see them.
- No account is needed to use Krodium.
- The website sets no advertising or analytics cookies and loads no third-party trackers.
- If you sign in, apply for a job or become a developer, we keep only what we need, for as long as we need it, as set out below.
1. The Krodium browser
Krodium does not collect personal data for us. There is no telemetry, no usage reporting, no crash reporting, no studies or experiments, and no sponsored content. We do not know who uses Krodium, which sites you visit or how often you open it.
Your browsing data (history, bookmarks, saved passwords, form entries, cookies, site permissions, settings, profiles and downloads) is stored only on your device, in your Krodium profile folder. It is not sent to us. You can delete it at any time from Settings or by removing the profile folder.
Network services the browser contacts
A web browser has to talk to the internet. Apart from the websites you choose to visit, these are the only services Krodium contacts on its own, and why. None of these requests includes an identifier for you, your account or your browsing history.
| Service | When and why | What it receives |
|---|---|---|
| Kraken filter-list updates | Only while Kraken is switched on. Kraken keeps its lists of ads, trackers and annoyances up to date by downloading them from the public servers that publish them. | An ordinary download request, which shows your IP address and Krodium's user agent to that server. No browsing data. |
| Krodium phishing and malware lists (krodium.com) | Krodium regularly downloads lists of known dangerous and deceptive sites and downloads from krodium.com, so it can warn you. Pages you visit are checked against the lists on your device. | An ordinary download request, with your IP address and user agent. The addresses you visit are not sent. |
| Encrypted DNS (Quad9) | Only while Kraken is switched on. DNS lookups, which turn a site name into an address, are encrypted and sent to Quad9 using DNS over HTTPS, instead of your network's resolver. | The names of the sites you look up, and your IP address, as with any DNS resolver. Quad9 acts under its own privacy policy. |
| Search engines you choose | When you search from the home screen or the address bar, and, if search suggestions are on, as you type in the address bar. | Your search terms, or what you type, and your IP address, under that search engine's own privacy policy. |
| Protected-media component | Only when a site you visit needs protected playback (for example some music and video services), Krodium downloads the component that provides it, from the provider of that component. | An ordinary download request, with your IP address. |
| Certificate checks | When you connect to a secure site, the engine may check that the site's security certificate has not been revoked, with the authority that issued it. | Information about the certificate, and your IP address. |
The home screen works out your country on your device, from your time zone and language settings, to suggest popular sites. Nothing is sent anywhere to do this. The sites, extensions and apps you choose to use have their own privacy practices, which this policy does not cover.
If you install an extension or app, including from the Krodium Store, it is provided by its developer, who is responsible for the data it handles. Each Store listing links to the developer's privacy policy.
2. The krodium.com website
You can read krodium.com and download Krodium without telling us who you are.
- Server logs. Our servers and our network provider record the date and time of each request, the page or file requested, the response, your IP address, the referring page and your browser's user agent. We use these to deliver the site, keep it secure, prevent abuse and fix faults.
- Downloads. When you download Krodium we see the same log information. We do not link downloads to a person.
- Cookies and storage. The website uses only what is strictly necessary. See the Cookie policy (krodium.com/cookies).
- Contact. If you write to us, we use your message, name and email address to reply and to keep a record of the conversation.
3. Signing in with Viremail
You can sign in to krodium.com with a Viremail account to use the developer console and your account page. Viremail is a service of the same company. Sign-in uses OpenID Connect: you sign in on viremail.com, and Viremail tells us your Viremail account identifier, your name and your email address. We never see your Viremail password.
We store that account identifier, name and email address, when you first and last signed in, and a session record. The session cookie holds a random value; we store only a one-way hash of it. Sessions end after 14 days at most, or when you sign out.
4. The Krodium developer platform
If you apply to publish in the Krodium Store, we collect what we need to verify you, keep the Store safe and, later, pay you:
- Account details: the type of account, your legal name or organisation name, the public name shown in the Store, country, contact email address, phone number and address. For organisations, also the registration number, website and domain, contact person and, if you give it, a D-U-N-S number.
- Verification documents: an identity document and a photo of yourself (individuals), or a company registration document (organisations). These are encrypted before they are stored, can be opened only by Krodium reviewers, and are deleted 90 days after we decide on your application.
- Domain verification: the token we issue and the result of checking it, by DNS or by a file on your website.
- Your listings: names, descriptions, icons, screenshots, links, prices, packages and installers, release notes, review decisions and the reasons for them, and download counts.
- Records of review decisions and administrative actions, with the reviewer who took them.
The information you publish in a listing, including your public developer name, is shown to everyone who visits the Store.
5. Careers
If you apply for a job, we collect your name, email address, phone number, the team you are interested in, your location, an optional link, an optional note and your CV. The CV is encrypted when stored. Only the people who handle hiring can see your application. We keep applications for 12 months, then delete them, unless you ask us to delete yours sooner or you join us.
6. Why we use your data, and our lawful bases
| Purpose | Data | Lawful basis |
|---|---|---|
| Running and securing the website and downloads, preventing abuse | Server logs | Legitimate interests: keeping our services available and secure. |
| Signing you in and keeping you signed in | Viremail account identifier, name, email address, session records | Contract: providing the service you asked for. |
| Verifying developers and reviewing listings | Developer account details, verification documents, domain checks, listings | Contract, and legitimate interests in keeping the Store free of fraud and malware. |
| Publishing listings in the Store | Listing details and your public developer name | Contract. |
| Payments to developers and keeping financial records, when paid sales open | Payout and tax details | Contract and legal obligation. |
| Considering job applications | Application details and CV | Steps taken at your request before entering a contract, and your consent to keeping your application for 12 months. |
| Answering messages and security reports | Your message and contact details | Legitimate interests in helping you and keeping Krodium safe. |
| Complying with the law and defending legal claims | Any of the above, where needed | Legal obligation, and legitimate interests. |
Where we rely on legitimate interests, we have weighed them against your rights, and you may object (see Your rights). Where we rely on consent, you may withdraw it at any time, without affecting what we did before.
7. How long we keep it
| Data | How long |
|---|---|
| Server logs | Up to 30 days, longer only where needed to investigate a specific security incident or abuse. |
| Sessions | 14 days at most, or until you sign out. |
| Sign-in attempts and rate-limit records | Up to 24 hours. |
| Account details from Viremail sign-in | While you have an account with us. Deleted within 30 days of a request to delete it, unless we must keep something for a legal reason. |
| Developer verification documents | Encrypted, and deleted 90 days after we decide on the application. |
| Developer account details and listings | While your developer account is open, then up to 6 years where we need them for legal, tax or dispute reasons. |
| Review and administrative records | Up to 6 years, to show how decisions were made. |
| Job applications and CVs | 12 months, then deleted. |
| Messages to support, privacy and security | Up to 3 years after the conversation ends. |
| Financial records, when paid sales open | 6 years after the end of the financial year they relate to, as UK law requires. |
8. Who we share it with
We do not sell personal data, and we do not share it for advertising. We use a small number of service providers (processors), who act only on our instructions, under contracts that protect your data:
- Our hosting provider, which runs the servers for krodium.com and the developer platform.
- Cloudflare, Inc., which provides our network, protection against attacks, caching of downloads and, where we use it, file storage (Cloudflare R2).
- Viremail, our own sign-in service, when you choose to sign in with it.
- When paid sales open, a payment provider for payments and developer payouts. We will update this policy before then.
We may also share data where the law requires it, to protect people from harm, to protect our rights, or with professional advisers under a duty of confidence. If our business is reorganised or sold, data may pass to the new owner, who must keep to this policy.
9. International transfers
We are based in the United Kingdom. Some of our providers, including Cloudflare, process data in other countries, including the United States. Where personal data leaves the UK or the European Economic Area, we make sure it is protected: by adequacy regulations or decisions (such as the UK Extension to the EU-US Data Privacy Framework), or by the International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, together with other measures where needed. Ask [email protected] for details.
10. Security
We protect personal data with encryption in transit (HTTPS) on every page, encryption at rest for identity documents and CVs (AES-256-GCM, with keys held separately from the data), strict access controls, logging of administrative actions, and regular review of our code and systems. No system is perfectly secure; if a breach affects you, we will tell you and the regulator as the law requires.
11. Your rights
Under UK and EU data protection law you have the right to:
- be told how your data is used (this policy);
- have a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted, in some circumstances;
- restrict how we use your data, in some circumstances;
- object to our use of your data based on legitimate interests;
- have data you gave us transferred to you or another organisation, where we rely on contract or consent;
- withdraw consent at any time, where we rely on it;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects. We do not make such decisions; every developer and listing decision is taken by a person.
To use any of these rights, email [email protected]. We may need to confirm who you are. We reply within one month, which the law lets us extend by two further months for complex requests, and we will tell you if we do. Using your rights is free.
Because the browser sends us nothing, we hold no browsing data about you. You control that data yourself on your device.
12. Complaints
If you are unhappy with how we have handled your data, please tell us first at [email protected] and we will try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK regulator, at ico.org.uk or on 0303 123 1113. If you live in the European Economic Area, you may complain to the data protection authority where you live or work.
13. Children
Krodium is a general-purpose browser and can be used by people of any age with the guidance of a parent or carer. Our online services (signing in, the developer platform and job applications) are not intended for children: developers must be 18 or over, and we do not knowingly collect personal data from anyone under 13 for those services. If you believe a child has given us personal data, write to [email protected] and we will delete it.
14. Changes to this policy
We will update this policy when what we do changes, for example before sign-in and sync arrive in the browser or before paid sales open. The date at the top always shows the latest version. If a change is significant, we will say so on this page and, where it affects the browser, in the release notes (krodium.com/release-notes), before it takes effect.
Contact
Svayam Incarnation Limited, registered in England and Wales. Data protection: [email protected]. Support: [email protected].